Securing Software Development: From SSDLC to Third-Party Risks

Securing Software Development: From SSDLC to Third-Party Risks

In this episode of 'The ITSM Practice' podcast, Luigi Ferri delves into the critical aspects of Secure Software Development Lifecycle (SSDLC), highlighting the shift from traditional SDLC to Security-by-Design. Through expert insights, the discussion covers the integration of security at every development phase, the role of third-party risk assessments, and the benefits of frameworks like NIST SSDF. The episode also emphasizes the necessity of cultural change within organizations to prioritize security in software development, offering practical advice for enhancing security postures against sophisticated threats.


In this episode, we answer to:

How critical is the importance of the Secure Software Development Lifecycle in today's tech-driven environment?

What steps can organizations take to evolve from Traditional SDLC to Security-by-Design?

How can organizations manage risks associated with third-party components in software development?


Resources Mentioned in this Episode:

Snyk, article "Secure Software Development Lifecycle (SSDLC)". link https://snyk.io/learn/secure-sdlc/


Hackerone, article "What Is the SSDLC (Secure Software Development Life Cycle)?", link https://www.hackerone.com/knowledge-center/what-ssdlc-secure-software-development-life-cycle


Synopsys, article "Secure SDLC", link https://www.synopsys.com/blogs/software-security/secure-sdlc.html


Vulcan, article "SDLC and secure coding practices: the ultimate guide for 2024", link https://vulcan.io/blog/secure-sdlc-best-practices/


Connect with me on:

LinkedIn: https://www.linkedin.com/in/theitsmpractice/

Website: http://www.theitsmpractice.com

And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security.


Credits:

Sound engineering by Alan Southgate - http://alsouthgate.co.uk/


Graphics by Yulia Kolodyazhnaya

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(165)

Should Your CMDB Know Your Business Risk?

Should Your CMDB Know Your Business Risk?

A critical vulnerability is not automatically a critical business risk. If your CMDB only tells you which server is affected but not the customer, service, contract, SLA, or revenue behind it, you are...

22 Sep 19min

Is Your Security Stack Too Big?

Is Your Security Stack Too Big?

Is your security stack actually protecting you, or are you just paying for too many tools? This episode looks at security tool sprawl, unused capabilities, overlapping products, skills gaps and vendor...

15 Sep 13min

24/7 IT Support: Why Coverage Is Not Capability

24/7 IT Support: Why Coverage Is Not Capability

24/7 support does not automatically mean 24/7 capability. In this episode of The ITSM Practice Podcast, Luigi Ferri explores how MSPs can design profitable 24/7 IT support using follow-the-sun models,...

8 Sep 11min

The Last Human-Only Leadership Generation: How AI Is Transforming the Workforce

The Last Human-Only Leadership Generation: How AI Is Transforming the Workforce

AI is no longer just a technology tool, it is becoming part of the workforce. In this episode, Luigi Ferri explores why AI represents a workforce transformation rather than a technology project, and h...

1 Sep 11min

ENISA Cyber Exercises: Why Testing Cybersecurity Isn't Enough

ENISA Cyber Exercises: Why Testing Cybersecurity Isn't Enough

Are cyber exercises actually improving your cybersecurity resilience, or just satisfying compliance requirements? In this episode, Luigi Ferri explores ENISA's cyber exercise methodology, the gap betw...

25 Aug 8min

Projects Deliver Outputs. Services Deliver Outcomes.

Projects Deliver Outputs. Services Deliver Outcomes.

Projects Deliver Outputs, Services Deliver Outcomes: The Ownership Crisis Nobody Discusses. Discover why the biggest risk in any IT project begins after go-live. In this episode, Luigi Ferri explores ...

18 Aug 11min

MSPs: Your AI Contracts Are Obsolete

MSPs: Your AI Contracts Are Obsolete

AI is transforming Managed Service Providers (MSPs) from managing technology to managing AI behavior. This episode explains why traditional service design, governance, contracts, and risk models are n...

11 Aug 16min

DARE25: Why Defense Isn't Enough

DARE25: Why Defense Isn't Enough

Discover why traditional cybersecurity defense is no longer enough in the AI era. Luigi Ferri explores the DARE25 framework, dynamic risk management, governance, Purple Teaming, accountability, and ad...

4 Aug 9min

Populärt inom Teknik

natets-morka-sida
uppgang-och-fall
elbilsveckan
bilar-med-sladd
market-makers
rss-laddstationen-med-elbilen-i-sverige
skogsforum-podcast
rss-en-ai-till-kaffet
rss-elektrikerpodden
rss-technokratin
rss-ai-med-jonas-benjamin
rss-uppgang-och-fall
rss-sakerhetspodcasten
rss-veckans-ai
rss-snacka-om-ai
bli-saker-podden
developers-mer-an-bara-kod
rss-powerboat-sverige-podcast
rss-it-sakerhetspodden
rss-fabriken-2