Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Ochaun Marshall -- IaC and SAST

36 min29 november 2021

Om avsnittet

Infrastructure as code gives security teams something they have wanted for years: a readable description of the systems surrounding an application. Ochaun Marshall, a developer and application security consultant, explains how that visibility complements static analysis and penetration testing. He discusses where SAST belongs in development, what configuration files can reveal about cloud resources, and why deployed infrastructure still needs monitoring. The conversation covers Terraform, AWS development tools, open-source scanners, and using source access to make a penetration test more productive. Ochaun and Chris then connect those technical practices to developer empathy, explaining why overwhelming engineers with findings undermines trust and how a smaller, carefully tuned set of checks can make security genuinely useful.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Ochaun Marshall:
Ochaun Marshall on LinkedIn

Mentioned in this episode:
Semgrep
Bandit
Terraform

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Infrastructure as code and SAST with Ochaun Marshall
02:35 Returning to cloud application security
06:32 Where SAST fits in development
07:15 Scanning applications and their infrastructure
09:53 Configuration files versus deployed assets
12:19 Rebuilding infrastructure instead of changing it manually
14:23 Infrastructure programming with the AWS CDK
17:19 Using SAST during a penetration test
20:26 Open-source tools in the testing toolkit
25:06 The security benefits of infrastructure visibility
26:55 Tagging resources and monitoring changes
29:06 Developer empathy under delivery pressure
32:14 Introducing security checks without overwhelming developers

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.