Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Thinking back, Looking forward - A Balanced Approach to Securing our Software Future

1 tim 12 min15 juli 2021

Om avsnittet

Software security has spent decades alternating between prevention, detection, and response. Kevin Greene joins Chris and Robert to ask what a balanced approach should look like now. Drawing on work at Parasoft and across government and industry, Kevin discusses secure development practices, standards, developer enablement, and the limits of relying on tools alone. The conversation connects supply-chain failures and the federal cybersecurity executive order to cyber resilience, penetration testing, red teams, and assurance. It closes by looking ahead to policy, software minimalism, and the changes organizations must make if they want secure software to become a repeatable engineering outcome rather than a late-stage scramble.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Kevin Greene:
Parasoft
Kevin Greene on API security testing

Mentioned in this episode:
Parasoft
OWASP Proactive Controls
MITRE ATT&CK
Threat Modeling Manifesto
Executive Order 14028
Apache Struts

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Looking back at software security
02:03 Kevin Greene’s path through AppSec
04:54 What a balanced security approach means
06:59 Prevention, detection, and response
09:52 Standards and repeatable engineering practices
12:38 Making secure development easier
15:42 Helping developers own security
18:40 The current state of software assurance
22:36 Guidance, governance, and accountability
24:46 Where security tools help—and where they do not
28:00 Supply-chain failures and SolarWinds
30:00 Why old software problems persist
33:00 The federal cybersecurity executive order
37:00 Adapting to rapid change
40:00 Building cyber resilience
42:00 The role of penetration testing
45:00 What red teams add
47:00 Standards, certification, and assurance
53:00 Looking toward the future
54:00 Goals for the next generation of software
56:00 Software minimalism and reducing attack surface
59:00 Policy as a driver for change
62:00 Closing thoughts

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.