
Jim Routh -- Selling #AppSec Up The Chain
Om avsnittet
What if the strongest argument for funding application security is better software delivery rather than fear of a breach? Jim Routh draws on building five software security programs to explain how he makes the case to executives. He connects security with quality, productivity, and the cost of fixing defects, then distinguishes the language that works with business leaders from the conversations practitioners have about risk. Chris and Robert ask how to put that case into practice, build developer participation, and use security champions to extend a program’s reach. Jim also explores board attention, industry crises, and the choices that determine whether a program scales. The conversation offers a leader’s perspective on earning investment by making secure development part of how the business succeeds.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Jim Routh:
→ Jim Routh on LinkedIn
Mentioned in this episode:
→ BSIMM
→ Meltdown and Spectre
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Making the executive case for AppSec
01:41 Jim’s route into security leadership
03:54 The state of enterprise software security
07:46 Connecting security with quality and productivity
08:27 How Jim wins funding for security programs
16:39 When to talk about risk
21:37 Turning the business case into a program
25:31 Software security and executive attention
29:40 Using industry crises to drive improvement
35:23 Why security champions help programs scale
36:17 The next challenges for software security
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.