Skip to main content

Managing AppSec

Discover how to manage your application security program with expert guidance on measuring AppSec success and improving the security of your software.

Stay up to date on Application Security

  • Let’s face it; consumers’ attention spans are getting shorter by the day. Gone are the days of people willing to wait several minutes for a clunky website with a poor user experience to load. In fact, 47 percent of users expect the average page to load in less than 2 seconds before they leave, resulting in billions in missed potential revenue. With the increased competition for consumer attention READ MORE

  • If you’re a software engineer you’ve probably seen one or two of your colleagues graduate from Senior Developer to Developer Manager – some with the sobering realization that managing a team of developers requires significant cross-functional skillsets. Foundationally, to be a successful Developer Manager you must know your stuff when it comes to software development, be passionate about the READ MORE

  • The use of open source libraries to assemble applications is accelerating. Not only are more people using open source libraries, but more individual developers, and even companies, are also on a mission to contribute to more open source projects. For Veracode, we’re seeing more than 70 percent of our customer base leveraging one or more open source libraries in their applications. And that could READ MORE

  • In their book Agile Testing: A Practical Guide for Testers and Agile Teams (2008), Lisa Crispin and Janet Gregory wrote that one of the most important factors for success in software development is feedback. “Feedback is a core agile value. The short iterations of agile are designed to provide constant feedback to keep the team on track.” The message still rings true: constant feedback is READ MORE

  • Authored by Jacques Lopez and Tom Eston  As a result of the current COVID-19 pandemic, most companies are operating remotely. This “new normal” has led to an increased demand for digital transformations and cloud migrations. But Verizon’s 2020 Data Breach Investigations Report recently noted that cyberattackers are taking advantage of the digital transformations, finding new ways to attack web READ MORE

  • If you know the term “nightly build,” chances are you’ve been a part of that process before. A nightly build - or code compiled overnight from previously checked code - is a foundational way to find flaws or issues that arise from changes made during long build processes. But while a staple in DevOps, nightly builds also present a problem: if new bugs are discovered the following morning after READ MORE

  • Creating a remediation plan can be tricky. In fact, customers often tell us that it’s much easier to create a plan to help developers scan applications quickly and easily than it is to establish remediation goals. But if vulnerabilities aren’t remediated right away, there’s a higher chance that they will never be remediated. Our recent State of Software Security (SOSS) report found that there’s READ MORE

  • “Make it work, make it right, make it fast.” These words from renowned software engineer Kent Beck will always ring true for developers, especially with the pace of development picking up, not slowing down. A GitLab survey from last year showed nearly half (43 percent) of respondents deploy software on-demand or multiple times per day – that’s nonstop grinding to produce good code. But simply READ MORE

  • It’s a common conundrum for application security (AppSec) teams…how can developers and security professionals work together to release software faster? It takes a working relationship, good communication, and the right tools, which most teams don’t have. Even more discouraging, stigmas follow both teams around the office; developers often worry that security is there to slow down or halt their READ MORE

Love to learn about Application Security?

Get all the latest news, tips and articles delivered right to your inbox.