AppSec Master Class: Recent Episodes

AppSec MC

AppSec Master Class is a podcast that helps you help your developers build better software

View Details

This is a mini-episode originally recorded for the BSIMM community as part of an ongoing series of metrics. We’ve decided to release this audio interview for the benefit of anybody looking to use metrics to drive the transformation of their application security program. Sammy Migues has years of experience in coaching CISOs and AppSec Program […]

View Details

Security Gates are the final decision point before releasing software to the next phase of development or to production. If your security gates aren’t checking into the right risks, you may be releasing insecure software. When initially created, security gates were manual meetings where a bunch of humans would make a human decision, but as […]

View Details

One of the most common initiatives shared by successful AppSec programs is the Satellite or Security Champions program. Since most software issues are introduced by people, having a people driven solution pays huge dividends. A Security Champions program recruits, trains, and organizes a community of developers, testers, and designers to take the lead on security […]

View Details

Design flaws can lead to vulnerabilities present in the blue prints of your application. If you’re building a house with a blue-print that doesn’t call for locks on the windows, your house will be built with a huge vulnerability. If your software is missing needed controls or has gaps in logic, attackers will be able […]

View Details

Congratulations on your promotion/hiring to AppSec Director! You are now in charge of application security for a small/medium/large company called Sec Co. It is now your job to evaluate the business drivers, culture, and organization features that will shape an AppSec program whose goal is to help developers build software that is harder to hack. […]

View Details

Application Security is now more important than ever. If your company is writing software but doesn’t have a plan to write it securely, it’s not secure. Companies have been learning that the hard way and have been getting the headlines to prove it. The only way to write secure software is to do so intentionally, […]