Security Compass, a leading provider of cybersecurity solutions and advisory services, enables organizations to adopt balanced development automation for rapid and secure application development. With their flagship product, SD Elements, the company helps automate significant portions of proactive manual processes for security and compliance that improves time to market for new technology. In addition, they offer advisory services on how organizations can embrace emerging technologies like cloud to strengthen their security posture. Security Compass is the trusted solution provider to leading financial organizations, technology enablers, and renowned global brands.
Today we are joined by Altaz Valani from Security Compass and Shaun Mckeag, Principal Software Engineer at Gen Digital, to talk about her personal journey in software development and security. Many listeners are either trying to get into secure software development, or have graduated from a program that teaches security and software development, or perhaps recently transitioned from a different role. It’s nice to have someone with years of experience in the field to give some perspective, guidance, tips, and encouragement. Listen in as Shaun shares her personal journey that will inspire and help those of us who are newer to the secure software space.
Today we are joined by Altaz Valani from Security Compass and Pranshu Bajpai, Security Architect at Motorola Solutions, to talk about the use of application security training to influence developers toward embracing security. Many developers are eager to learn about security but they need help. Developers move very fast because their performance is often measured around release frequency. All of this is happening while developers have to keep up with continually evolving frameworks and tools. It is possible for security teams to influence developers without getting in their way.
Today we are joined by Altaz Valani from Security Compass and Simone Curzi, Principal Consultant at Microsoft, to talk about the role of developers within threat modeling. When we mention threat modeling, what often comes to mind are data flow diagrams created during a security design process. After these diagrams are created and eventually hit the developer backlog, we discover more insights that further evolve the security design. In this way, developers are crucial to an evolving threat model activity. Yet, many questions exist. We try to answer some of those developer questions related to threat modeling.
Useful links from this podcast:
Today we are joined by Altaz Valani from Security Compass and Jason Keirstead, Distinguished Engineer & Chief Technical Officer of Threat Management at IBM as well as Co-Chair of Open Cybersecurity Alliance. Security tool integrations are largely custom efforts today. That investment alone prevents loose coupling of our security tool architectures and timely delivery of security insights to key decision makers. Jason shares his insights on the work going on at Open Cybersecurity Alliance (OCA) to help solve this problem. The holy grail of an integrated security fabric that shares information across a toolchain can transform our ability to rapidly adapt to a changing threat landscape and allow for early detection of threat actor behavior. Jason shares his vision of how everyone can play a part in making this a reality, from customer procurement to vendor adoption of security standards.
Today we are joined by Vaibhav Garg, Executive Director, Cybersecurity & Privacy Research and Public Policy at Comcast, to talk about developer-centric threat modeling. We start by looking at ways to make threat modeling more appealing to developers. We discuss how a security team can help developers participate in threat modeling in the midst of continual change with both development and security teams. Ultimately, a threat modeling program is only as effective as the value it offers to a diverse group of stakeholders. We discuss how to measure and align the value of threat modeling across project, program, and executive levels. We conclude with Vaibhav’s thoughts about where he thinks developer-centric threat modeling is heading over the next 12 to 18 months.
Today we are joined by Altaz Valani from Security Compass and Krish Raja, Managing Director at Kroll Cyber Risk division, to talk about developer-centric threat modeling. We will start by discussing how threat modelers can help developers. We then discuss how to define the value of a threat modeling program and common pitfalls when creating such a program. We close off by discussing where threat modeling is headed in the future.
Today we are joined by Simone Curzi, Principal Consultant at Microsoft, to talk about some of the challenges we face today with conducting threat modeling. We will discuss how value creation in threat modeling is tied to the developer community and, ultimately, to the business. Our discussion will then look at how threat modeling must continue to evolve in light of our DevOps delivery cycles. We will conclude with a brief discussion on how organizations can operationalize a threat modeling practice.
Today we are joined by Spencer Koch, Offensive Security Professional at Reddit, to talk about building a threat modeling practice. We will examine when threat modeling should be done and the associated challenges. We will then turn our attention to the connection between threat modeling and secure coding in the developer space. In conclusion, we will explore some measures of success and where threat modeling is headed as the practice continues to add value and adapt to a changing software development paradigm that is more agile and cross-functional.
Today we are once again joined by Kyle Lai, Founder and CISO of KLC Consulting, to talk about CMMC. We will start by discussing the differences between CMMC 1.0 and CMMC 2.0 and discuss the timeline for CMMC 2.0 rulemaking. Our discussion will also look at CMMC 2.0 both from an assessor’s perspective and a Defense contractor’s perspective. Specifically, how an assessor should manage the change if they are already invested in CMMC 1.0 and next steps for a Defense contractor to do before CMMC 2.0 rulemaking is complete. CMMC impacts a broad ecosystem and being aware of the changes can help organizations prepare for the transition.
Today we are joined by Kim Wuyts from KU Leuven, to talk about privacy threat modeling. We will start by discussing what LINDDUN is and the difference between privacy threat modeling and security threat modeling. We will then discuss how a framework like LINDDUN can be used in DevSecOps pipelines as part of an evolving knowledge base. For those who wish to provide feedback to the LINDDUN team, Kim will share some ways that you can reach out to her team. Privacy is a critical part of our software that is often neglected. With new regulations and standards emphasizing both privacy and security, we need a consistent approach to help guide policy creation and software development activities.
Today we are joined by Nick Deshpande to talk about data governance and security. We will start by introducing the concept of data governance and the business importance of data governance. We will dig deeper and discuss who is responsible for creating and managing a data governance program. When looking at data governance as an enabler, we will turn our attention to three use cases: DevSecOps, Threat Modeling, and Zero Trust. In concluding, Nick will share his thoughts on where he sees data governance evolving over the next 12-18 months.
Today we are joined by Kyle Lai, Founder and CISO of KLC Consulting, to talk about CMMC. We will start by discussing the governance and ownership aspects of CMMC. Once a CMMC program has kicked off, teams usually have to overcome some challenges. We will discuss the top challenges with achieving CMMC compliance. In an era of DevSecOps, we will turn our attention to the importance of automation and conclude by discussing the impact of CMMC in the near future.
Today we are joined by K Royal, Associate General Counsel & DPO of TrustArc, to talk about Software Development and Privacy. We will start by discussing what the intersection of privacy and software development looks like. We will examine the essential competencies required to produce privacy compliant software and touch on automated privacy checking in the context of DevSecOps pipelines. We will conclude by discussing where privacy is headed in the next 12-18 months. Producing privacy compliant software is becoming increasingly important in light of government regulations.
Today we are joined by Mark Simos, Lead Cybersecurity Architect at Microsoft, to talk about leveraging security reference architectures to operationalize security. We will talk about our current context and the democratization of security and DevOps across the enterprise. Since security touches so many parts of the organization, this is where the role of security reference architectures becomes critical in creating an onramp for cross-functional teams. They help coordinate activities and programs against measurable business outcomes. We will conclude by looking forward to the next 18-24 months and what to expect.
Today we are joined by Michael Isbitski, Technical Evangelist at Salt Security, to talk about API Security. Our systems and platforms today are largely driven by API integrations. We will start by discussing ownership of API security in an organization. This will lead into a discussion about convincing a business stakeholder to invest in API security. Given how complex our applications are today, we will talk about some of the biggest challenges with securing our APIs. As security paradigms continue to evolve, we have gone from perimeter based security to Zero Trust. We will conclude by discussing how API security fits into Zero Trust.
Today we are joined by Carmichael Patton, Senior Security Architect at Microsoft, to talk about Zero Trust. We will talk about the value proposition along with ownership and accountability for a Zero Trust program. It is important that Zero Trust aligns with business priorities. We will also discuss the rollout of Zero Trust and some important lessons learned from previous implementations.
Today we are joined by Rob Akershoek from DXC, to talk about security reference architectures. We will start by discussing why we need a security reference architecture. This will lead us into governance and who is responsible for creating a security reference architecture. Since we don’t have a standard security reference architecture in the industry, we will explain how to start creating a security reference architecture. In conclusion, we will share some of the work being done by The Open Group around security reference architectures.
Today we are joined by Mark Timms, Senior Manager, Cybersecurity Education & Awareness Behavioural Science at RBC, to talk about the human side of cyber security. We will talk about what motivates people to embrace a security program and what triggers drive the intended behavior. Building a security culture takes intentionality and a coordinated set of activities that focuses on the person. We will conclude with a consideration on how we should think about measuring the outcome. Cyber security is top of mind for many organizations and understanding the human side will help to drive meaningful programs that align with personal and organizational motivations.
In this episode, Clay Carter talks about product security in our critical infrastructure- specifically, water! Clay discusses the unique challenges and opportunities of product security in the water industry, the intersection with business partners like safety, importance of domain expertise, and the effect of seeing the products you help secure impact your day to day life.
Today we are joined by Malu Septien Milan, President of Cryptopon, to talk about tying security to business value. We will start by explaining the gap between security and business expectations. This has an impact on how security teams scale as they become increasingly relevant in business operational risk where DevOps is driving “continuous everything”. We will then round off the discussion by turning to the business side to consider what they can do to help close the gap. In an era where going digital is a top priority, closing the security-business gap is crucial to balancing security with operational risk.
Today we are joined by Jack Freund, Head of Cyber Risk Methodology at VisibleRisk, to talk about cyber security risk and business value. We will start by discussing the gap between cyber security and business value. In bridging these two domains, we eventually need to consider different risk models. We will discuss cyber security risk modeling approaches and challenges. We will then conclude by looking at where cyber security risk modeling is going over the next 18 to 24 months. This discussion will serve both security and risk practitioners who focus on threat modeling or risk assessments and want to understand how their efforts can align with the broader trend around risk modeling.
Leaders in Product Security: In the eleventh episode of this series, we are joined by John Deskurakis, Chief Product Security Officer, Carrier Global Corporation, to talk about how Carrier tackles some of the unique challenges they face with product security, as well as the critical role of cold storage for COVID-19 vaccinations. During this discussion, he also highlights how "shift left" is often used to mean scanners in the industry, when in fact there should be more focus on security by design. John will also throw some light on product security in general, and the role of a Chief Product Security Officer more broadly.
Leaders in Product Security: In the eleventh episode of this series, we are joined by Sean Poris, Director, Product Security at Verizon Media, to talk about the role of engineering in a service organization. We will discuss the evolving pace of software development, the critical contributions of security champions, and balancing security by design with security assurance.
Today we are joined by Paul Breitbarth, Director, Global Policy & EU Strategy at TrustArc, to talk about integrating privacy into software development. We will start by educating you about the process of privacy impact assessment which will help us understand how to bridge the gap between privacy and DevOps. The inherent cross-functional nature of balancing speed and privacy necessitates early intervention of privacy teams. To conclude, Paul will share thoughts on the future of privacy regulations and software development.
Today we are joined by Ayhan Tek, VP of Information Security at Cyber Electra, to talk about how a security practitioner can help support compliance related security activities in software development. In order to make threat modeling scalable, the cross-functional nature of software development needs to extend beyond data flow diagrams into the business realm. Once in the business domain, the discussion turns toward risk. The long-term value of threat modeling, therefore, is in its ability to contribute toward risk assessments that will enable non-technical stakeholders to make informed decisions about security investments.
Today we are joined by Spencer Koch, Offensive Security Professional at Reddit, to talk about threat modeling and the issues with scaling the traditional processes. These days, we don’t have enough security practitioners to perform threat modeling on every system. In many cases, there is also an emphasis on trying to achieve perfection instead of doing what’s “good enough.” In this episode, we delve into how shifting toward a more democratized and decentralized approach that allows more people to get involved.
Leaders in Product Security: In the tenth episode of this series, we are joined by Timo Skytta, Managing Director, Head of Advisory (Security) at Goldman Sachs, to talk about his experience with workload, priority management, and automation. We will delve into what problem their company was trying to solve, the challenges they ran into, unexpected pushback from the stakeholders, and how they aligned goals to overcome these challenges.
Leaders in Product Security: In the ninth episode of this series, we are joined by David Lenoe, Director, Secure Software Engineering at Adobe, to talk about product security and its evolution at Adobe. David will also share his insights on working with engineering teams, the importance of security champions, and why compliance is not necessarily a barrier to security.
Leaders in Product Security: In the eighth episode of this series, we are joined by Matthew Bohne, Vice President and Chief Product Security Officer for Honeywell Corporation, to talk about the unique challenges of running a security program at a global scale. Drawing on his experience in leading one of the largest product security teams globally, he shares his thoughts on emerging regulatory standards that can impact product security. We will also talk about the value of the ISA/IEC 62443 standard for IOT & IIOT devices, and how other industries are taking product security more seriously now.
Leaders in Product Security: In the seventh episode of this series, we are joined by Sudharma Thikkavarapu to talk about product, application, and cloud security. He shares his perspectives on software-defined infrastructures and how it impacts the way we think about security. He also throws light on what it takes to make product security successful, including how to evolve security thinking to keep engineering engaged.
Leaders in Product Security: In the sixth episode of this series, we are joined by Khaja Ahmed, Sr. VP, Product and Application Security at SAP, who shares his unique insights from working in the cloud security space with companies like Amazon, Microsoft, and Google. We will talk about the impact of reporting structure on product security, differences between start-ups and enterprises, and how product security will evolve in the future.
Leaders in Product Security: In the fifth episode of this series, we are joined by Janne Uusilehto, Lead Privacy PgM at Google, to gain insights into product security as he shares his experiences from the early days of mobile device security. We will also discuss how product security has evolved over the years and the progress being made by organizations with the changes in this space.
Today we are joined by John Weigelt, Lead for Microsoft Canada’s Strategic Policy and Technology Efforts, to talk about IoT and Hardware Security from a security executive’s perspective. We will start by looking at the context of IoT and hardware products and the importance of not getting biased toward an exclusively desktop computing frame of reference. We will then discuss how security teams can help with creating awareness. We will conclude by talking about emerging trends around zero trust and security enclaves to address hardware security concerns.
Leaders in Product Security: In the fourth episode of this series, we are joined by Jason Christman, VP, Chief Product Security Officer at Johnson Controls. Jason is a recognized champion of the Chief Product Security Officer (CPSO) role. In this podcast we discuss the role and its core responsibilities, top priorities, and compare the role with the Chief Information Security Officer (CISO). We also talk about product security as it relates to competitiveness, unique considerations for industrial controls, and future changes to product security.
Leaders in Product Security: In the third episode of this series, we are joined by Laksh Raghavan, Head of Product, Platform and Enterprise Security at LinkedIn,he explains how cross-disciplinary thinking — specifically behavioral science and systems thinking are critical to driving success in product security. Laksh also shares how he has successfully driven developer buy-in for security, and how we must focus on dissolution and dis-continuous improvements to completely eliminate many of the complex and chronic problems in Information Security.
You can connect with Laksh on Twitter @laraghavan.
Show Notes:
How Wolves Change Rivers : https://www.youtube.com/watch?v=ysa5OBhXz-Q
Heartwarming Video: https://www.linkedin.com/posts/ugcPost-6759141809772863488-HtKs and the quote from Anil Dash.
Today we are joined by Altaz Valani from Security Compass and Tony Carrato, an Independent Architecture Consultant, to talk about IoT and Hardware Security from a security executive’s perspective. We will start the discussion by talking about the top security challenges with IoT and hardware products, such as emerging standards, data movement, and default passwords. We will then turn our attention toward trying to de-risk these security challenges through standards influence, architecture, and assurance. To conclude, we will discuss security trends around IoT and hardware products, including device capabilities, edge computing, and the importance of IoT at the executive level.
Leaders in Product Security: In the second episode of this series, we are joined by Brad Arkin, Senior Vice President, Chief Security and Trust Officer, Cisco, who shares his unique insights from his extensive experience in product, and more holistically, information security. In this podcast, we are going over the major shifts in product security, how we might solve the talent gap, and what role standards may play in the future. Brad will also talk about influencing leadership and driving organizational change, which he has successfully achieved throughout his career.
Leaders in Product Security: In the first episode of this series, we are joined by Steve Lipner, Executive Director of SAFECode, who is inarguably one of the most experienced and prolific specialists in product security. We will talk about how Steve got into software security, the impact of Bill Gates' famous Trustworth Computing Memo, how consumers and businesses can assess a vendor's product security, and the important role that SAFECode plays.
Today we are joined by Spencer Koch, Offensive Security Professional at Reddit, to talk about cloud enablement from a security practitioner’s perspective. We will start by looking at how security teams can help with creating a culture around cloud enablement. We will then look deeper into the guardrails and metrics, and whether current security metrics still apply to the cloud. And, finally, we will conclude with a brief discussion on pitfalls to avoid while trying to enable cloud adoption in the context of speed to market while managing security risk.
Today we are joined by Ayhan Tek, VP of Information Security at Cyber Electra, to talk about how a security practitioner can help enable cloud adoption for their organization. From a cultural standpoint, we will discuss the role of security practitioners in enabling cloud adoption as well as some common pitfalls around cloud security. And, finally, given our rapid delivery CI/CD pipelines, we will talk about the types of metrics we should be considering in order to balance both speed and security.
Today we are joined by David Wheeler, Director of Open Source Supply Chain Security at the Linux Foundation, to talk about securing open source software. We will start with a brief discussion on the “2020 FOSS Contributor Survey” report, co-authored by David. We will then delve deeper into some surprising insights from that report as it relates to the dynamic nature of fast-moving open source development. Finally, we will conclude with David’s thoughts on where he thinks open source software security is headed.
Today we are joined by Altaz Valani from Security Compass and Wayne Howell Jr., Cyber Security Process & Governance Leader at Honeywell, to talk about product security governance and bridging the gap between product and software security. We will talk about the similarities and differences between product and software security, particularly around the end — i.e. the post-deployment product support. We will then explore areas of process convergence for these teams around requirements and hardware virtualization. To conclude, we will share insights about metrics.
Today we are joined by Katie Stewart, co-author of CMMC and Senior Member of the Technical Staff within the CERT® Division at the Software Engineering Institute, to talk about the creation and ongoing evolution of CMMC. We will start by talking about the history of CMMC and the response received so far. We will then turn our discussion to the ongoing evolution of CMMC and ways that people can get involved. CMMC is a significant step in the direction of securing the DoD supply chain and being aware of the ongoing evolution in this space will help leaders proactively plan ahead.
Today we are joined by Altaz Valani from Security Compass, Sesh Vaidyula, Partner at Templar shield, and Harvey Nusz, Principal at 4IT Security, Governance & Compliance, to talk about CMMC in a commercial context, given its overlap with NIST 800-53, NISC CSF, and ISO 27001. We will also discuss its similarities with other non-maturity standards and regulations such as PCI, HIPAA, GDPR. To conclude, we will talk about how CMMC might help the broader commercial industry.
Today we are joined by Altaz Valani from Security Compass, Sesh Vaidyula, Partner at Templar shield, and Harvey Nusz, Principal at 4IT Security, Governance & Compliance, in our second podcast about CMMC we will talk about what it means for DoD vendors. We will discuss the transformational leadership role that the DoD has as they work toward a more secure supply chain. We will conclude by discussing challenges that, in particular, smaller organizations face with CMMC compliance.
Today we are joined by Altaz Valani from Security Compass, Sesh Vaidyula, Partner at Templar shield, and Harvey Nusz, Principal at 4IT Security, Governance & Compliance, in our second podcast to talk about CMMC. We will talk about what CMMC means to DoD suppliers around building maturity. We will then discuss the transformational leadership role that the DoD has as they work toward a more secure supply chain. We will conclude by discussing challenges that, in particular, smaller organizations face with CMMC compliance.
Today we are joined by Altaz Valani from Security Compass and Wendy Murphy, Chair - Events & Outreach Working Group for CMMC Center of Excellence, to talk about their mission and then dive deeper into the common challenges organizations face with CMMC. We will conclude by talking about where the CMMC CoE is headed in the future. Given the importance of CMMC and its implications for ensuring security in the DoD supply chain, having insights and guidance from a Center of Excellence can help organizations leverage best practices and learn from the experience of others.
Today we are joined by Altaz Valani from Security Compass and Ayhan Tek, VP of Information Security at Cyber Electra, to talk about how a security executive can enable speed to market in software development. Competition adds a lot of pressure to deliver software products faster which is why we will explore how a senior security executive can enable the business to keep moving fast instead of being perceived as a blocker. In today’s world, security is an imperative component of software development and can enable speed to market.
Today we are joined by Altaz Valani from Security Compass and Rohini Narasipur, Product Security Engineer at Bosch, to talk about what makes product security different from software security. With the convergence of software and hardware, it has become important to understand how software and hardware security processes can integrate with each other. To conclude, we get some forward-looking insights from Rohini about where product security is headed. In today’s world, we need to consider the security aspect of both software and hardware as well as the challenges that arise due to the cross-functional narrative.
Today we are joined by Rohit Sethi from Security Compass and David Fairman, Chief Security Officer at Netskope, to understand the concept of cyber-physical systems and how these are transforming the way we interact with engineered objects and infrastructure. We will also delve into the security concerns for cyber-physical systems as these play an increasingly vital role in critical infrastructure and can cause massive damage in the event of a cyberattack. In addition, David will talk about the use of these systems in the financial services sector drawing from his experience.
Today we are joined by Altaz Valani from Security Compass and Arun Prabhakar, Security Consultant at Security Compass, to talk about product security. We start by talking about both product and software security, where there are similarities and differences. We then turn the conversation to look at quality and the categories of metrics that help make secure products. At the end of our discussion, we discuss where hardware security is headed in the future. This area of product security is an important topic in light of the growing convergence between hardware and software layers.
Today we are joined by Pranoy De and Michael Bolger from Security Compass and DJ Schleen, Senior Manager of Software Security at Rally Health, to talk about how we can leverage technology to enhance DevSecOps practices. In this podcast, we delve into the details of technology and automation tools that are essential for setting up a robust DevSecOps program, with specific emphasis on the Healthcare industry.
Today we are joined by Pranoy De, Eleonor Lee, and Altaz Valani from Security Compass, to talk about three DevSecOps challenges from a technical leader’s perspective: integrating security into DevOps pipelines; building a knowledge retention and training model that balances speed and security; and the convergence of business and IT. In all cases, security has a key role to play in enabling the business to manage risk, in a way that doesn’t slow down the business.
Today we are joined by Altaz Valani from Security Compass and Spencer Koch, Offensive Security Professional at Reddit, to talk about Agile Security in technology companies from an Executive’s perspective. We would start with the question — Why does the business think security gets in the way of being agile — and discuss how a security executive can start to change this perception. As with any change, there needs to be an ongoing effort from security teams to provide assurance and business value for agility. Agile is at the forefront of technology companies today, and security can be an enabler by reducing risk without getting in the way.
Today we are joined by Altaz Valani from Security Compass and Purnima Bihari, Product Owner at Security Compass, to talk about how managing a fast moving product delivery lifecycle while ensuring security is a challenging task. Purnima will share insights from her experience about the role a product owner plays in injecting security early into the product lifecycle and the impact being a security champion can make on ensuring product security. We will also discuss the skills required to adopt a balanced approach to speed and security.
Today we are joined by Rohit Sethi from Security Compass and Nicolas Chaillan, Chief Software Officer, U.S. Air Force, to gain insights into building a DevSecOps program for a large government organization. In this podcast, we will talk about the challenges, key considerations, and the need to balance security with fast delivery cycles in the defense world. We will also cover the program structures being established across the Department of Defense and understand more about the ATO process.
Today we are joined by Altaz Valani from Security Compass and Bob Aiello, DevOps architect and trainer with decades of experience leading enterprise software process improvement initiatives. We will start by asking the question, “Why do so many organizations struggle with integrating security into DevOps?” Since automation is a key part of DevOps, we will discuss security practices that are easily automatable in DevOps, and conclude with a discussion on where DevOps is headed.
Today we are joined by Altaz Valani from Security Compass and Spencer Koch, Security Wizard at Reddit, to discuss the role of security in Application Modernization. In today’s digital world, businesses have to modernize their applications routinely. In this podcast, we will discuss current trends and security challenges around application modernization; and how security can help minimize the risk. This is important as many organizations are currently transforming their applications against a backdrop of going digital.
Today we are joined by Altaz Valani from Security Compass and Jeff Sorrell, a Data Privacy and Information Security Consultant. We will discuss, at a high level, the importance of Cybersecurity Maturity Model Certification (CMMC) and its operational impact on companies that have contracts with the U.S. Department of Defense. We dive into some of the nuances of CMMC as it advocates moving away from self-attestation to third-party audit and certification. To conclude this discussion, Jeff will share thoughts on any trends based on his own experience.
Today we are joined by Ehsan Foroughi from Security Compass, and Andrew Wertkin, Chief Strategy Officer at BlueCat. In this podcast, we will discuss the intersection of network infrastructure and security, and how to bake security requirements from that perspective. Drawing from his experience in enterprise architecture and distributed computing networks, Andrew will also share valuable security and network health insights.
Today we are joined by Hasan Yasar, Technical Director of Continuous Deployment at the Software Engineering Institute, CMU, to talk about Continuous ATO. We will start with the need to automate architectural assurance across the application build and deployment pipeline. Further, we will discuss how risk management is embedded into the process through security controls. Finally, we will conclude with how DevOps unlocks the ability to achieve continuous ATO.
In this podcast, we are joined by Brian Pitts, Director, Product Security Governance at Johnson Controls (JCI) to discuss some of the unique security challenges faced by IOT device manufacturers and how advanced tooling has helped JCI bolster their product security practices.
Today we are joined by Glen Notman, Associate Partner at Citihub. In this podcast, we will talk about the gap that exists between the security and business teams. To communicate the value of security, it’s important for security teams to make their findings and recommendations relevant to the business. This involves empathizing with the real needs of a business stakeholder.
Today we are joined by Gopi Reddy who is an experienced Enterprise Architect. We will talk about digital transformation and how DevOps enables the business imperative. Security is often not considered a key part of this transformation because of the perception that it is a low-level technical activity. With the shift to digital product enablement in a high velocity environment, this is now changing as security becomes everyone’s responsibility.
Today we are joined by Ruth G. Lennon, Lecturer, Department of Computing at the Letterkenny Institute of Technology, to talk about initiating the journey of injecting security into development. Many teams feel enormous pressure from the start to quickly understand security. In this podcast, we delve into taking a more thoughtful and deliberate approach that focuses on building a strong foundation to align your cross functional teams.
Today we are joined by Altaz Valani from Security Compass and Nikhil Kumar, President, and Founder of ApTSi, to discuss the feasibility of Zero Trust. In this podcast, we will talk about the value of Zero Trust from a business enablement perspective. We will also dive into the feasibility of Zero Trust for technical leaders. While Zero Trust is not a silver bullet, for today’s rapidly evolving business and security scenarios, it offers a compelling evolution away from our network-centric approach towards a focus on the data.
Today we are joined by Altaz Valani from Security Compass and Stephen Whitlock, one of the first members of the Jericho Forum and a security expert with 16 years of experience at Boeing. In this podcast, we will discuss the evolution of Zero Trust and its roots in the Jericho Forum work. We will also talk about the business value of Zero Trust and the pitfalls of rolling out a Zero Trust program. Implementing Zero Trust is more effective if we understand the history and why today’s business needs are driving this evolutionary approach to security.
Today we are joined by Altaz Valani from Security Compass and Tony Carrato, an independent consultant with expertise in delivering enterprise architecture across varied industries. In this podcast, we will discuss the evolution of the Zero Trust security model and how it is different from existing models. We will also delve into the business value that Zero Trust can offer organizations in the midst of changing operating models. The agility of organizations depends, in large part, on the security assurance of data safety at all times.
Today we are joined by Ehsan Foroughi, Head of Products at Security Compass, to talk about the importance of a security culture in an organization. In this episode, he will explain how the effectiveness of any application security program is impacted by the security culture across teams. Citing examples from his personal experiences, he delves into the human factor in security and how strong organizational policies can fail if not implemented properly.
Today we are joined by Altaz Valani from Security Compass and Hasan Yasar, Technical Director of Continuous Deployment at the Software Engineering Institute, CMU. We will discuss shifting security to the left and being more proactive. Using Top 10 lists is a good starting point. In the long term, however, value is achieved when we use security scenarios to drive out important value propositions.
Today we are joined by Altaz Valani from Security Compass and Andy Woyzbun, Management Consultant at Woyzbun Advisory, to discuss how a CIO drives a cybersecurity strategy. In this podcast, we will talk about clearly defining and communicating security policies; guiding employees to execute these policies; and using guardrails to assess whether security policies are being enforced effectively. Ultimately, it’s about balancing a cybersecurity strategy against the needs of business enablement.
Today we are joined by Altaz Valani from Security Compass and Spencer Koch, Security Wizard at Reddit, to discuss the importance of a proactive security mindset across the software security life cycle. Proactive often means using tools, but these tools are useful only if they help reduce process overhead. Blindly shifting security responsibilities to tool results in more overhead through false positives. In this podcast, we will talk about a lean process mindset that shifts the discussion “to the left” (before SAST, DAST, and Pentesting) and helps to identify where waste can be eliminated — and that is what enables proactive security.
Spencer is an offensive security professional with extensive experience in both consulting and industry. He has also served as the North American CISO at a large energy company.
Today we are joined by Altaz Valani from Security Compass and Lynn Carter, Consultant and former Professor at Carnegie Mellon University, to talk about the importance of clearly identifying security training objectives. In this podcast, we will delve into why it is important to build long-term behavioral changes into your program vision for sustainable security training. A thoughtful approach to training can help bridge the gap between business and security teams.
Today we are joined by Altaz Valani from Security Compass and Malu Septien Milan, President of Cryptopon, to discuss how you can balance software development risk at all levels of an organization. In this podcast, we are exploring the tension between automation and controls with a focus on providing value to the end customer.
Today we are joined by Rohit Sethi from Security Compass and Dan Fritsche, Founder, and CEO at Alpine Security Consulting, to talk about balancing speed and risk in payments. In this podcast, Dan will share his experience with security and the continuous need for innovation fueled by customer demand in the payments space.
Today we are joined by Altaz Valani from Security Compass and Vicky Hailey, Certified Management Consultant at VHG, to discuss how you can tie your software development programs and processes to business value. In this podcast, we will talk about the importance of focusing on customer and stakeholder needs first — only then can we drive out the right software development programs and practices that contextually balance these needs.
Listen in on a brief discussion around Privacy and Contact Tracing. Our research team from Security Compass discusses several relevant issues from the need to gain public trust, developing secure apps, data accuracy, and managing the data lifecycle all while trying to balance public safety and utility.
Today we are joined by Kevin Delaney, Director of Solutions Engineering at Security Compass who will share a useful, bite-sized analogy on the importance of fostering meaningful collaboration between security and engineering teams.
Today we are joined by Altaz Valani from Security Compass and Glen Notman, Associate Partner at Citihub, to discuss how we can engage different stakeholders to adopt a balanced development approach. In this podcast, we will go into the details of how the “technical” automation-for-speed perspective is shifting to a “business-centric” perspective of automation-for-balance, which includes risk and security.
In this episode, Security Compass' Altaz Valani is joined by Ayhan Tek, VP of Information Security at Cyber Electra, to discuss how DevOps automation is shifting to include balanced development for software security. As we inject security, risk, and compliance into software development, we will explore how automation can improve product security and time to market.
Today we are joined by Altaz Valani, Director of Insights Research at Security Compass, and Hasan Yasar, Technical Director at the Software Engineering Institute, Carnegie Mellon University, to talk about adding intelligence to our DevOps pipelines. In this podcast, we will go into the details of how we can make smarter use of the data being collected through DevOps pipelines.
We sat down with Rohit Sethi, CEO of Security Compass, to talk about balanced development automation and how it can help organizations develop digital products faster while ensuring security. In this podcast, we will discuss why organizations should not choose between a “fast and risky” and “slow and safe” approach to development – because there’s a better way.
The future of business relies on being digital, but all software deployed needs to be secure and protect privacy. Yet, responsible cybersecurity gets in the way of what any company really wants to do: innovate fast, stay ahead of the competition, and wow customers! In this podcast recorded at RSA Conference 2020, Ehsan Foroughi from Security Compass talks about a way of building software that addresses cybersecurity issues from the start, letting companies focus on what they do best.
In this episode, we are in conversation with Ehsan Foroughi from Security Compass about the challenges organizations face with regulatory compliance. In the wake of new cyberattacks and increased device connectivity, organizations are finding it difficult to comply with new regulations. Ehsan will explore how businesses can tackle these challenges in an increasingly competitive world.
Rohit Sethi, CEO of Security Compass, joined The Last Watchdog to discuss the limitations of the current DevSecOps movements -- and how Security Compass can infuse security best practices into the current framework.