Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Tony Turner -- Threat Modeling and SBOM

44 min3 maj 2023

Om avsnittet

Have you ever considered using an SBOM to inform your threat modeling? Tony Turner has. Tony joins us to discuss SBOMs, threat modeling, and the importance of Cyber Informed Engineering. Tony Turner is the CEO and founder of Ops-Wright, a new type of cybersecurity company disrupting security engineering for critical infrastructure. I found Tony via a talk he did on threat modeling in SBOM. Topic caught my attention, so I reached out to have a conversation. We talk about threat modeling in SBOM, the value proposition of SBOM, security engineering in SBOM, and cyber-informed engineering. This is something you'll want to learn about. I'd never heard of it before, but it could also help us in building more secure applications and products both.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Tony Turner is the CEO and founder of Ops-Wright, a new type of cybersecurity company disrupting security engineering for critical infrastructure.
Learn more about Security Journey

Connect with Tony Turner:
Opswright
Cyber-Informed Engineering (INL)

Mentioned in this episode:
Opswright
Cyber-Informed Engineering (INL)
Consequence-driven Cyber-Informed Engineering (CCE)
Software Transparency
IriusRisk
Open Threat Model (OTM)
PyTM
Contrast Security
CycloneDX
VEX
National Vulnerability Database (NVD)
Software Transparency: Supply Chain Security in an Era of a Software-Driven Society by Chris Hughes, Tony Turner
OWASP pytm

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Meet Tony Turner: Threat Modeling and SBOM
01:49 Yeah, I mean, getting into a style of threat modeling or
05:21 And so when you, when you mentioned kind of in the
06:51 To jump into our topic today, Tony, what's an SBOM
09:38 Tony, when you think of the value proposition of SBOM, like
13:39 Right
19:51 Yeah, this is the first time that I've ever bumped into
21:59 Makes sense. And OT, you mean operational technology, right
28:59 You think about, like, when we think about the process that
31:25 You also mentioned there were some tools that you used as
34:47 I'm going to— we had another question about CycloneDX, but I'm—
37:34 Yeah. Okay, cool. So I guess, Tony, from a key takeaway
39:17 Okay. So how about a key takeaway then, or a call
43:10 Very good. Well, Tony, thank you for being with us today

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.