CyberSecurity Awareness Month with Troy Vinson - Episode 161

CyberSecurity Awareness Month with Troy Vinson - Episode 161

This week, Jeffrey is joined by Troy Vinson; a Principal Software Architect at Clear Measure as a CISSP (Certified Information System Security Professional.) He is an experienced leader, architect, and problem-solver in Information Systems Security and Software Development technologies and has spent the majority of his career integrating computer science, information science, and cognitive science to assist in software development and the management of information.

With October being CyberSecurity Awareness Month, Troy gives a rundown on everything that developers and development teams need to know regarding security, how to become more cyber security aware, the top ten web application security risks you need to look out for, how to keep your environment secure regardless or where you're working from, and what you can putting in place today to improve your cyber security.

Topics of Discussion:

[:39] About The Azure DevOps Podcast, Clear Measure; the new video podcast Architect Tips; and Jeffrey's offer to speak at virtual user groups.

[1:11] About today's episode with Troy Vinson!

[1:23] Jeffrey welcomes Troy to the podcast.

[1:30] What is CISSP?

[2:53] Troy shares his career highlights and the path that led him to his current role in cyber security.

[4:39] Why is October Cybersecurity Awareness Month?

[6:18] What developers should be aware of when setting up a connected environment for themselves at home.

[8:47] Troy's favorite VPN services.

[10:08] Best practice: Always work from a VPN, especially as a developer working from a public place.

[10:25] What developers should keep in mind about source code when it comes to cyber security.

[12:32] How to keep documents (that don't quite fit in a source control repository) secure.

[14:31] Troy highlights important security architecture models of practice.

[15:56] How is the STRIDE model applicable?

[17:59] A word from The Azure DevOps Podcast's sponsor: Clear Measure.

[18:30] What is repudiation in the STRIDE model referring to? What is it in code changes? When is it necessary?

[20:22] Are there test suites that developers can use to augment their functional tests that check for security measures?

[23:16] Should development teams hire third parties to do audits versus doing it in-house?

[24:36] What OWASP Top Ten is and why all of your engineers should be trained on it.

[26:15] Is there a comprehensive list of web application security risks?

[27:28] Troy highlights the importance of #6 on the OWASP Top Ten list: vulnerable and outdated components.

[29:15] Rules of thumb regarding security for development teams when it comes to deployment and configuring environments

[30:56] Free online courses for cyber security awareness that you can share with family members and friends.

[33:52] Jeffrey thanks Troy Vinson for joining the podcast!

Mentioned in this Episode:

Architect Tips — New video podcast!

Azure DevOps

Clear Measure (Sponsor)

.NET DevOps for Azure: A Developer's Guide to DevOps Architecture the Right Way, by Jeffrey Palermo — Available on Amazon!

bit.ly/dotnetdevopsebook — Click here to download the .NET DevOps for Azure ebook!

Jeffrey Palermo's YouTube

Jeffrey Palermo's Twitter Follow to stay informed about future events!

DEVintersection Conference — Dec. 7th‒9th in Las Vegas, Nevada

Cybersecurity Awareness Month | CISA

Cybersecurity Awareness Month | National Cybersecurity Alliance (NCSA)

NordVPN

ExpressVPN

STRIDE Model

GitHub

DevSecOps

SharePoint

One Drive

Azure Front Door

Azure Application Gateway

FxCop

Roslyn

Sonarqube

OWASP Top Ten

Top 25 Most Dangerous Software Errors CWE/SANS

2021 CWE Top 25 Most Dangerous Software Weaknesses

Want to Learn More?

Visit AzureDevOps.Show for show notes and additional episodes.

Jaksot(397)

Jeff Hollan on Azure Functions and Serverless - Episode 61

Jeff Hollan on Azure Functions and Serverless - Episode 61

This week, Jeff Hollan is joining the podcast! Jeff is a Principal Program Manager on the Azure Functions team. He is always developing and shipping solutions on the latest and greatest tech, and is p...

4 Marras 201937min

Shayne Boyer on the Landscape of Containers and Cloud-Native - Episode 60

Shayne Boyer on the Landscape of Containers and Cloud-Native - Episode 60

Today's guest on the podcast is Shayne Boyer, a Principal Cloud Advocate and .NET Lead at Microsoft! For the last 15 years, he has been developing Microsoft-based technology, mixing in a little Oracle...

28 Loka 201942min

Daniel Jacobson on DevOps for Desktop Applications - Episode 59

Daniel Jacobson on DevOps for Desktop Applications - Episode 59

Today's guest is Daniel Jacobson, a Program Management Lead on the Visual Studio team focused on empowering Windows Developers. Daniel was one of the speakers at the .NET Conf 2019 and will also be at...

21 Loka 201937min

Glenn Condron on New Capabilities in .NET - Episode 58

Glenn Condron on New Capabilities in .NET - Episode 58

This week on the podcast, Jeffrey is speaking with Glenn Condron! Glenn is the Program Management Lead of the App Platform team within the Developer Division at Microsoft, focusing on .NET. With .NE...

14 Loka 201942min

Craig Loewen on the Windows Subsystem for Linux DevOps Story - Episode 57

Craig Loewen on the Windows Subsystem for Linux DevOps Story - Episode 57

On this week's episode, Jeffrey is joined by Craig Loewen to discuss the Windows Subsystem for Linux! Craig is a Program Manager on the Windows Subsystem for Linux team. He started his journey in Univ...

7 Loka 201932min

Oren Eini on DevOps Success at RavenDB (Part 2) - Episode 56

Oren Eini on DevOps Success at RavenDB (Part 2) - Episode 56

This is the second part to the two-episode series with Oren Eini! If you haven't listened to the first part already be sure to tune into that one first! Oren Eini, pseudonym Ayende Rahien, is a freq...

30 Syys 201941min

Oren Eini on DevOps Success at RavenDB (Part 1) - Episode 55

Oren Eini on DevOps Success at RavenDB (Part 1) - Episode 55

Today's guest is Oren Eini, pseudonym Ayende Rahien. Oren is a frequent blogger at Ayende.com and has over 20 years of experience in the development world, with strong focuses on the Microsoft and .NE...

23 Syys 201936min

Kayla Cinnamon and Rich Turner on DevOps on the Windows Terminal Team - Episode 54

Kayla Cinnamon and Rich Turner on DevOps on the Windows Terminal Team - Episode 54

On this week's podcast, Kayla Cinnamon and Rich Turner are joining the show! Kayla is a Program Manager on the Windows Terminal Team and has been working for Microsoft for the last 8 years, and Rich i...

16 Syys 201956min

Suosittua kategoriassa Politiikka ja uutiset

uutiscast
aikalisa
politiikan-puskaradio
ootsa-kuullut-tasta-2
rss-ootsa-kuullut-tasta
rss-pinnalla
tervo-halme
rss-vaalirankkurit-podcast
rss-podme-livebox
aihe
rss-asiastudio
the-ulkopolitist
rss-tasta-on-kyse-ivan-puopolo-verkkouutiset
rss-girls-finish-f1rst
otetaan-yhdet
et-sa-noin-voi-sanoo-esittaa
rss-50100-podcast
rss-polikulaari-pitka-kiekko-ja-muut-ts-podcastit
rss-ulkopoditiikkaa
rss-kaikki-uusiksi