Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Jon Mccoy and Jonathan Marcil -- Agile #AppSec

45 min29 augusti 2017

Om avsnittet

Agile delivery promises fast feedback, but where does application security fit when teams are already moving continuously? Jon McCoy and Jonathan Marcil join Chris and Robert to separate Agile principles from inconsistent enterprise interpretations and identify practical starting points. They discuss dedicated AppSec leadership, security-minded developers, continuous integration, static analysis, shared knowledge, and reusable components. The guests challenge the idea of a late security sprint and examine the real cost of building defenses early. They also explain how responsibility can be distributed without asking every developer to become a cryptography specialist. The episode closes with learning recommendations, community participation, and the principle that a mature AppSec program should help teams avoid repeating the same security mistakes.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Jon McCoy and Jonathan Marcil:
Jon McCoy on X
Jonathan Marcil on X

Mentioned in this episode:
Agile Manifesto
OWASP Top 10
OWASP Montreal

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Agile application security
01:54 Security origin stories
05:41 Development experience and security work
08:52 The advantages of fast feedback
10:11 What organizations mean by Agile
13:24 Where security fits
16:44 Starting an Agile AppSec program
20:02 Continuous integration and static analysis
23:02 Building a security knowledge base
27:54 Why a late security sprint fails
28:05 The real cost of building security early
32:44 Reusable controls and specialized responsibility
35:33 Additional first-year priorities
37:34 Learning through local communities
43:18 Avoiding the same mistakes over time

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.