Application Security Weekly (Audio)

The Application Security Weekly podcast delivers interviews and news from the worlds of AppSec, DevOps, DevSecOps, and all the other ways people find and fix software flaws. Join hosts Mike Shema, John Kinsella, and Akira Brand on a journey through modern security practices for apps, clouds, containers, and more.

https://securityweekly.com/asw

subscribe
share






Starting an OWASP Project (That's Not a List!) - Grant Ongers - ASW #272


We can't talk about OWASP without talking about lists, but we go beyond the lists to talk about a product security framework. Grant shares his insights on what makes lists work (and not work). More importantly, he shares the work he's doing to spearhead a new OWASP project to help scale the creation of appsec programs, whether you're on your own or part of a global org.

Segment Resources:

  • https://owasp.org/www-project-product-security-capabilities-framework/
  • https://github.com/OWASP/pscf
  • https://prods.ec/
  • https://owaspsamm.org
  • https://iso25000.com/index.php/en/iso-25000-standards/iso-25010
  • https://www.scmagazine.com/podcast-episode/application-security-weekly-242

Qualys discloses syslog and qsort vulns in glibc, Apple's jailbroken iPhone for security researchers, moving away from OpenSSL, what an ancient vuln in image parsing can teach us today, and more!

Visit https://www.securityweekly.com/asw for all the latest episodes!

Show Notes: https://securityweekly.com/asw-272


fyyd: Podcast Search Engine
share








 February 6, 2024  1h14m