
Jim Manico and Katy Anton -- The Future of the OWASP Proactive Controls
Om avsnittet
Where should the OWASP Proactive Controls go after giving developers a concise defensive counterpart to the Top 10? Project leaders Jim Manico and Katy Anton discuss the document’s origins, intended audience, and plans for its next version. They explore how much implementation guidance belongs in a short list, whether data should shape future priorities, and how the controls relate to ASVS, cheat sheets, and other OWASP resources. The guests consider language-specific guidance and a future in which developers can move from a high-level control to concrete examples for their platform. Chris also asks how the community can review and contribute. The conversation captures an open-source project deciding how to remain approachable while becoming more useful to practicing software engineers.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Jim Manico and Katy Anton:
→ Jim Manico on LinkedIn
→ Katy Anton on LinkedIn
→ OWASP Proactive Controls
Mentioned in this episode:
→ OWASP Proactive Controls
→ OWASP ASVS
→ OWASP Cheat Sheet Series
→ NIST Digital Identity Guidelines
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 The future of OWASP Proactive Controls
02:43 A defensive counterpart to the Top 10
04:46 The project’s origin story
06:10 Priorities for the next version
09:11 Whether data should shape the controls
12:39 Mapping to ASVS and other projects
14:25 A five-year vision for the project
16:24 Language-specific developer guidance
17:24 How the community can contribute
18:50 Final thanks and next steps
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.