
Matt Clapham -- Development Security Maturity
Om avsnittet
Can you learn enough about a development team’s security practices in an hour to give it useful direction? Matt Clapham joins Chris and Robert to explain his lightweight approach to estimating development security maturity through five key behaviors. They discuss preparing for the assessment, learning from defect records and existing artifacts, and holding a conversation that encourages honest answers rather than anxiety about being graded. Matt walks through scoring practices such as threat modeling and vulnerability response, then explains how the results can guide improvement. The discussion also examines the experience an assessor needs, the model’s limitations, and its relationship to broader approaches such as BSIMM and SAMM. The goal is an actionable view of how a team actually works.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Matt Clapham:
→ Matt Clapham on LinkedIn
Mentioned in this episode:
→ RSA slides: Estimating Development Security Maturity in About an Hour
→ BSIMM
→ OWASP SAMM
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Estimating development security maturity with Matt Clapham
01:32 Matt’s product security background
03:15 What development security maturity means
05:15 Why measurement can make developers anxious
08:20 Why a maturity assessment is useful
11:03 Preparing for the assessment
16:33 Understanding the application before the meeting
19:49 What defect records reveal about a team
21:10 Running the development-team conversation
22:30 Communication that encourages useful answers
26:38 Scoring security behaviors
29:54 Evaluating threat modeling practices
34:39 Vulnerability response as a maturity signal
37:52 Can a team outgrow the model?
42:12 Limitations and advantages of the approach
45:30 How the model relates to BSIMM and SAMM
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.