Thoughts on Security in the Modern Software Supply Chain

Thoughts on Security in the Modern Software Supply Chain

Caroline Wong, Paula Thrasher and I were having lunch at DevOps Enterprise Summit when the conversation took an interesting turn. Paula and Caroline had been on a panel the previous day and didn't get a chance to do a deep dive into any of the topics. As we were talking at lunch, I realized is was a good opportunity to give them a chance to talk with each other on government vs public software security, about how the OWASP Top 10 might best be used and to they have discovered as common security patterns in their large scale projects. About Caroline Wong I am a strategic leader with strong communications skills, cybersecurity knowledge, and experience delivering global programs. My close and practical information security knowledge stems from broad experience as a Cigital consultant, a Symantec product manager, and day-to-day leadership roles at eBay and Zynga. I have been featured as an Influencer in the Women in IT Security issue of SC Magazine, named as one of the Top 10 Women in Cloud by CloudNOW, and received a Women of Influence Award in the One to Watch category from the Executive Women's Forum. I authored the popular textbook Security Metrics: A Beginner's Guide. About Paula Thrasher Paula Thrasher has 20+ years experience in IT and has spent the last 15 years trying to implement Agile culture in the federal government. Paula’s first Agile project was in 2001, since then she has led over 15 programs and projects as an Agile developer, technical lead, Scrum master, or Agile coach. Her teams have helped two separate federal agencies migrate applications to Amazon AWS GovCloud, and done some other amazing DevOps ninja work along the way. Paula is a proud Carnegie Mellon University alumna with a B.S. in Statistics, is a Certified Scrum Master (CSM) and a Project Management Professional (PMP), but prefers learning new things through experience and working with smart people.

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(191)

ep2024-12 Tanya Janca: Happy Holidays are Secure Code

ep2024-12 Tanya Janca: Happy Holidays are Secure Code

Some production issues caused this one to slip to December so the intro is a bit off but this is still a great episode. So, learn some lessons on creating secure code from one of my favorite guests: T...

23 Joulu 20241h

ep2024-10 Don't be Scared, It's just a Pen Test with Brad Causey

ep2024-10 Don't be Scared, It's just a Pen Test with Brad Causey

There's no reason to be scared about a pen test - especially when it's run by a professional like Brad Causey. I catch up with Brad in this episode to discuss what's recently changed in pen testing in...

31 Loka 202437min

ep2024-09 Threat Modeling with Takaharu

ep2024-09 Threat Modeling with Takaharu

What happens when you get interested in Threat Modeling and you want to share. For some, that means you do one work shop, then another, then another. What happens when you start down this path. Takaha...

25 Syys 202436min

ep2024-08 OWASP Projects Roundup

ep2024-08 OWASP Projects Roundup

The August episode is a review of projects from a recent OWASP project showcase. We talk to the leaders of the OWASP pytm, OWASP Developer Guide, OWASP State of AppSec Survey Project. Get up on the la...

30 Elo 202436min

ep2024-07 Safety belts for AppSec with Lisa Plaggemier

ep2024-07 Safety belts for AppSec with Lisa Plaggemier

After a long and unplanned pause, the OWASP podast is back with a home run of an episode. We have Lisa Plaggemier as our guest who reprises her eloquent keynote topic from AppSec DC. All hope isn't lo...

12 Heinä 202432min

ep2023-09  Vulnerable Data Gathering for AI with Arturo Buanzo Busleiman

ep2023-09 Vulnerable Data Gathering for AI with Arturo Buanzo Busleiman

After getting a ping from an old friend about a potential new OWASP project, I had to bring him on as a guest. He's got an interesting idea around potential vulnerabilities in web crawlers which just ...

2 Loka 202332min

ep2023-08 Finding Next Gen Cybersecurity Professionals with Brad Causey

ep2023-08 Finding Next Gen Cybersecurity Professionals with Brad Causey

For years we've heard talk about a shortage of cybersecurity professionals so what can be done about that? In this episode, I speak to Brad Causey who has taken one approach he's found successful. We ...

31 Elo 202332min

ep2023-07 What's Audit got to do with IT

ep2023-07 What's Audit got to do with IT

In this episode we talk with Zain Haq and take a leap and bound over the first and second line to discover more about the third line - internal audit. We discover answers to a number of questions: Wha...

31 Heinä 202333min