Artwork

Вміст надано Robert Wood and Sidekick Security. Весь вміст подкастів, включаючи епізоди, графіку та описи подкастів, завантажується та надається безпосередньо компанією Robert Wood and Sidekick Security або його партнером по платформі подкастів. Якщо ви вважаєте, що хтось використовує ваш захищений авторським правом твір без вашого дозволу, ви можете виконати процедуру, описану тут https://uk.player.fm/legal.
Player FM - додаток Podcast
Переходьте в офлайн за допомогою програми Player FM !

From DMZs to DevSecOps: Building Modern AppSec Programs with Gunnar Peterson

1:15:00
 
Поширити
 

Manage episode 461219658 series 3603368
Вміст надано Robert Wood and Sidekick Security. Весь вміст подкастів, включаючи епізоди, графіку та описи подкастів, завантажується та надається безпосередньо компанією Robert Wood and Sidekick Security або його партнером по платформі подкастів. Якщо ви вважаєте, що хтось використовує ваш захищений авторським правом твір без вашого дозволу, ви можете виконати процедуру, описану тут https://uk.player.fm/legal.
In this conversation, Robert Wood and Gunnar Peterson delve into the complexities of application security (AppSec), discussing its evolution, the importance of building effective AppSec programs, and the need for engaging developers in security practices. They explore the blurred lines between cloud security and application security, the role of posture management tools, and the significance of an asset-centric approach to security. Gunnar emphasizes the importance of understanding key use cases and platforms within an organization, as well as the need for security professionals to broaden their skill sets to navigate the changing landscape of cybersecurity effectively.
Takeaways
  • Application security is evolving, requiring a focus on both technology and human factors.
  • Understanding the organization's current state is crucial for building an effective AppSec program.
  • Coverage and efficacy are key metrics for assessing AppSec initiatives.
  • Engaging developers is essential for successful security practices.
  • In larger organizations, security efforts can become check-the-box activities.
  • The lines between cloud security and application security are increasingly blurred.
  • Posture management tools are emerging to address skill gaps in AppSec.
  • An asset-centric approach to security is gaining traction in the industry.
  • New security professionals should prioritize understanding key business use cases.
  • The future of security will require blending traditional practices with new technologies.
Sound Bites
  • "Good judgment comes from experience."
  • "You have to have the humility to recognize."
Chapters
00:00 Introduction to Application Security and Its Evolution
02:59. Building an Effective AppSec Program
05:51. Understanding Coverage and Efficacy in AppSec
08:58. Engaging Developers in Security Practices
11:52. Navigating Federated Environments in Security
14:55. The Blurred Lines Between Cloud and Application Security
17:46. The Role of Posture Management Tools in AppSec
21:10. The Importance of Asset-Centric Security
23:55. Advice for New Security Professionals
26:45. Final Thoughts and Future Trends in Security
  continue reading

4 епізоди

Artwork
iconПоширити
 
Manage episode 461219658 series 3603368
Вміст надано Robert Wood and Sidekick Security. Весь вміст подкастів, включаючи епізоди, графіку та описи подкастів, завантажується та надається безпосередньо компанією Robert Wood and Sidekick Security або його партнером по платформі подкастів. Якщо ви вважаєте, що хтось використовує ваш захищений авторським правом твір без вашого дозволу, ви можете виконати процедуру, описану тут https://uk.player.fm/legal.
In this conversation, Robert Wood and Gunnar Peterson delve into the complexities of application security (AppSec), discussing its evolution, the importance of building effective AppSec programs, and the need for engaging developers in security practices. They explore the blurred lines between cloud security and application security, the role of posture management tools, and the significance of an asset-centric approach to security. Gunnar emphasizes the importance of understanding key use cases and platforms within an organization, as well as the need for security professionals to broaden their skill sets to navigate the changing landscape of cybersecurity effectively.
Takeaways
  • Application security is evolving, requiring a focus on both technology and human factors.
  • Understanding the organization's current state is crucial for building an effective AppSec program.
  • Coverage and efficacy are key metrics for assessing AppSec initiatives.
  • Engaging developers is essential for successful security practices.
  • In larger organizations, security efforts can become check-the-box activities.
  • The lines between cloud security and application security are increasingly blurred.
  • Posture management tools are emerging to address skill gaps in AppSec.
  • An asset-centric approach to security is gaining traction in the industry.
  • New security professionals should prioritize understanding key business use cases.
  • The future of security will require blending traditional practices with new technologies.
Sound Bites
  • "Good judgment comes from experience."
  • "You have to have the humility to recognize."
Chapters
00:00 Introduction to Application Security and Its Evolution
02:59. Building an Effective AppSec Program
05:51. Understanding Coverage and Efficacy in AppSec
08:58. Engaging Developers in Security Practices
11:52. Navigating Federated Environments in Security
14:55. The Blurred Lines Between Cloud and Application Security
17:46. The Role of Posture Management Tools in AppSec
21:10. The Importance of Asset-Centric Security
23:55. Advice for New Security Professionals
26:45. Final Thoughts and Future Trends in Security
  continue reading

4 епізоди

Усі епізоди

×
 
Loading …

Ласкаво просимо до Player FM!

Player FM сканує Інтернет для отримання високоякісних подкастів, щоб ви могли насолоджуватися ними зараз. Це найкращий додаток для подкастів, який працює на Android, iPhone і веб-сторінці. Реєстрація для синхронізації підписок між пристроями.

 

Короткий довідник

Слухайте це шоу, досліджуючи
Відтворити