Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Jay Bobo & Darylynn Ross -- App Sec Is Dead. Product Security Is the Future.

52 min9 januari 2024

Om avsnittet

Is application security dead, or does it need to grow into something larger? CoverMyMeds security leaders Jay Bobo and Darylynn Ross challenge the traditional AppSec model and argue for product security that follows business risk across the whole product. They compare centralized security teams with security specialists embedded in engineering, explain where threat modeling and automated testing belong, and discuss how to give developers useful SAST findings without drowning them in tool output. The conversation then turns to communication: executives need risk, impact, and business context rather than raw vulnerability details. Jay and Darylynn also question the industry’s reflexive reliance on penetration testing and share practical advice for aligning security work with product outcomes, engineering workflows, and the people responsible for shipping software.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Darylynn Ross and Jay Bobo:
Darylynn Ross on LinkedIn
Jay Bobo on LinkedIn
CoverMyMeds

Mentioned in this episode:
How to Measure Anything in Cybersecurity Risk, 2nd Edition
Kristin Hannah
CoverMyMeds
GitHub Dependabot

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Is AppSec dead? Meet Darylynn Ross and Jay Bobo
03:11 Jay’s path from development into security
04:23 Why traditional AppSec needs to become product security
09:21 Embedding security expertise inside development teams
20:24 Product security compared with application security
23:46 Threat modeling and risk at the product level
26:49 Giving developers useful SAST results
34:46 Aligning security work with business value
36:44 Communicating vulnerabilities across the organization
40:18 Turning technical findings into executive risk
43:07 Controversial opinions about AppSec
44:53 Questioning the industry’s reliance on penetration tests
47:07 Book recommendations
49:27 Key takeaways from Darylynn and Jay

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.