Insight for
Security Leaders

Articles tagged with "Training"

Credit: Patrick Tomasso @ Unsplash
Credit: Daniel McCullough @ Unsplash
Credit: Barry Weatherall @ Unsplash
Credit: Joe Basirico

Phase One of Appsec Engineering: Awareness

This is part of a series

  • Introduction
  • Awareness (you are here)
  • Enablement (coming soon)
  • Enforcement (coming soon)

Last week I published a post introducing three important phases of AppSec Engineering: Awareness, Enablement, and Enforcement. Over the next three posts I will dive into each of these topics to share best practices and guidelines you can roll out to optimize your security engineering practice.

In my experience, the best AppSec programs start with AppSec awareness training. The goal is to provide your product team with enough information to know when they need security involvement. That’s a broad statement, so let’s break it down.


Read more >>

Credit: Joe Basirico

The Three Phases of Appsec Engineering

This is part of a series

In order for an AppSec team to collaborate effectively with development teams they should think in three phases: Awareness, Enablement, and Enforcement. This month I’ll be dedicating an article to each. The focus of these articles will be on the critically important area of application security, focused on the roles involved in building software: developers (DevOps), testers, and architects.


Read more >>

Credit: Joe Basirico & Rob Curran
Credit: Pexels

How to Scale an Application Security Program - Part Two

In my last blog post, I wrote about what an application security program is and why it matters. In this post, I’ll cover what it takes to build and scale an effective application security program. 

I’ve seen many different ways that a well-intentioned program can fail to meet its objectives. While there may be many ways to fail, there are just a few key characteristics that lead to success.

The program must be:


Read more >>

Credit: Pexels
Credit: Kroll Historical Maps
Credit: Jay Heike @ Unsplash
Credit: Dane Deaner on Unsplash