
Pete Chestna -- SAST, DAST, and IAST. Oh My!
Om avsnittet
Buying more scanners does not automatically create a better application security program. Pete Chestna explains SAST, DAST, IAST, runtime protection, and composition analysis, then connects those technologies to the developers who must use their results. Starting from a listener’s question about false positives, he explores speed, accuracy, workflow integration, and the difference between a real flaw and an accepted risk. Pete offers a gradual approach for a new program: understand the application inventory, establish a baseline, train developers, and improve one weakness category at a time. For more mature teams, he discusses combining metrics, preventing new vulnerabilities, and retaining human testing where tools fall short. His central argument is that effective programs develop secure developers, with secure software following from that capability.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Pete Chestna:
→ Pete Chestna on LinkedIn
Mentioned in this episode:
→ Veracode
→ Brakeman
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Making sense of AppSec testing tools
00:47 Pete’s security origin story
03:01 SAST, DAST, IAST, RASP, and SCA explained
07:25 Tool maturity and deployment models
09:08 Developer concerns: speed, accuracy, and integration
12:51 Compensating controls and risk decisions
14:18 Security knowledge and developer motivation
16:37 Starting a new AppSec program
18:05 Baseline measurement before enforcement
20:34 Improving one weakness category at a time
23:46 Preventing new vulnerabilities
25:06 The goal is secure developers
26:43 Combining data in a mature program
28:43 Where penetration testing still adds value
31:18 Open-source testing tools and tradeoffs
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.