
Kevin Greene -- Shifting left
Om avsnittet
Moving a security scanner earlier in the pipeline is not the same as building security into development. Kevin Greene explains what shifting left should mean and why rapid delivery exposes weaknesses in both security strategy and testing tools. Drawing on his work across industry, government research, and MITRE, he argues for capturing practitioners’ experience so teams can apply it repeatedly rather than depend on individual intuition. Chris and Robert explore that idea through threat modeling, architectural decisions, and adversary knowledge. Kevin discusses the Common Architectural Weakness Enumeration, CAPEC, and ATT&CK as ways to connect design choices with realistic failure and attack scenarios. The conversation challenges teams to improve the thinking behind their automation and bring developers usable security knowledge before problems become expensive defects.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Kevin Greene:
→ Kevin E. Greene’s website
Mentioned in this episode:
→ MITRE CAPEC
→ MITRE ATT&CK
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Shifting left with Kevin Greene
02:05 Kevin’s security origin story
05:43 Security across government and industry
07:39 What shifting left should mean
11:42 Why DevOps security efforts struggle
12:40 Strategy and the limits of testing tools
17:04 What it means to codify intuition
22:02 Turning experience into threat modeling knowledge
24:24 Architectural decisions and CAWE
26:55 Using CAPEC and ATT&CK
29:00 Bringing adversary knowledge into development
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.