Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Dave Ferguson -- The OWASP Top 10 Proactive Controls

44 min25 juli 2017

Om avsnittet

Developers hear plenty about vulnerabilities, but what should they actually build into their applications to prevent them? Dave Ferguson joins the podcast to walk through the OWASP Top 10 Proactive Controls as they stood at the time of this recording. The discussion covers early security testing, parameterized queries, output encoding, input validation, authentication, access control, data protection, logging, security frameworks, and error handling. Dave connects the controls to familiar application risks and explains how OWASP cheat sheets provide the implementation detail behind the high-level guidance. Chris and Dave also debate where intrusion detection belongs and why security features should be reusable. The result is a developer-focused conversation about turning awareness of common failures into concrete engineering practices.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Dave Ferguson:
Dave Ferguson on LinkedIn

Mentioned in this episode:
OWASP Proactive Controls
OWASP Cheat Sheet Series
OWASP Top 10

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Proactive security controls with Dave Ferguson
07:40 A developer-focused security baseline
08:40 Verify security early and often
12:34 Parameterize queries
15:01 Encode data for its output context
18:14 Validate all inputs
23:07 Identity, authentication, and session management
25:25 Implement access controls
29:03 Protect data at rest and in transit
32:18 Logging and intrusion detection
36:32 Use security frameworks and libraries
38:33 Handle errors and exceptions securely
41:18 Turning vulnerability awareness into action

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.