Your Next Steps if Your AppSec Program Is in the Reactive Stage

sciccone's picture
By Suzanne Ciccone February 23, 2017  | Managing AppSec
Reactive application security programs should follow these steps.

This is the first blog in a series that will look at each stage of an application security program’s maturity and outline what the next steps are to move toward an advanced program. We typically see organizations fall within one of these four stages of application security: Reactive (you're here!) Baseline Expanded Advanced If you are in the first stage and taking a reactive approach... READ MORE

A Veracode Program Manager’s Perspective: Our Programmatic Approach to Application Security

gjames's picture
By Griff James February 21, 2017  | Customer News

Undeniably, the best way to get secure software is to develop secure software. And the emerging DevSecOps trend – the integration of development, security and operations – facilitates this process. The ideal application security program today would involve a DevOps process with security integrated automatically from development to production. However, most companies aren... READ MORE

Live From RSA: Topics of Leadership and Teamwork With Dame Stella Rimington

jlavery's picture
By Jessica Lavery February 17, 2017  | Security News
RSA talk Dame Stella Rimington

In perhaps my favorite talk at RSA this year, Dame Stella Rimington, former Director of MI5, told the story of her career in the intelligence organization. And her story has parallels to the IT security industry today. When Rimington joined MI5, there were separate and unequal career paths for men and women. It was just taken for granted that women could not do the same jobs as men. She explained... READ MORE

Live From RSA: Your Chance to Get It Right – 5 Keys to Building AppSec into DevOps

jlavery's picture
By Jessica Lavery February 17, 2017  | Security News
AppSec and DevOps

The session I’ve been waiting for all week at RSA – Chris Wysopal and Tim Jarrett of Veracode gave an informative talk about the need for security to adapt to the developer-led world and the opportunity DevOps presents for security to become part of the team. Chris likened cyberthreats to Cholera, the disease is always there, but only when you have poor sanitation do you get sick or... READ MORE

Live From RSA: The Most Dangerous New Attack Techniques and What's Coming Next

jlavery's picture
By Jessica Lavery February 17, 2017  | Security News

SANS took the main stage at RSA Wednesday morning to talk about the seven most dangerous cyberattacks and what they expect to see in the coming years. The panel, moderated by Alan Paller, consisted of SANS researchers Ed Skoudis, Johannes Ullrich and Michael Assante. The four issues that stood out: 1. The rise of ransomware and crypto-ransomware Cryptography, Skoudis explained, was invented to... READ MORE

Live From RSA: Final Boarding Call for DevOps – You Don’t Have to Go Home, But …

jlavery's picture
By Jessica Lavery February 15, 2017  | Security News
RSAC Corman Keynote: DevOps

Josh Corman gave another engaging and informative talk at RSA about DevOps and how it is changing the way we think about security. As he says, DevOps is here, and is the future of development. Companies that don’t start shifting this way won’t be able to keep up in terms of innovation. But he also points out the need for governance, using the analogy of an earthquake. The earthquake... READ MORE

Live From RSA: States Confront Cybersecurity Challenge

jlavery's picture
By Jessica Lavery February 15, 2017  | Security News
RSAC McAuliffe Keynote

Before Terry McAuliffe made his plea for audience members to move to Virginia, the Virginia Governor and the Chairman of the National Governors Association spoke about the need for states to take cybersecurity into their own hands and work with the federal government to improve it. He pointed out that, collectively, the 50 U.S. states possess more data than the federal government. Health... READ MORE

Live From RSA: Michael McCaul Keynote – Fight for Our Digital Lives

jlavery's picture
By Jessica Lavery February 15, 2017  | Security News
RSAC Michael McCaul keynote

The RSA 2017 theme of cyberwar and the need for improved national security continued with a presentation by Michael McCaul, Chairman of the House Committee on Homeland Security. Like many of the other speakers I heard today, McCaul danced a political line. But if others were dancing a ballet, he was more of a tap dancer, clearly stomping on the line while others glided around it. He began his... READ MORE

Live From RSA: Brad Smith Keynote – We Need a Cyber Geneva Convention

jlavery's picture
By Jessica Lavery February 15, 2017  | Security News
RSAC Brad Smith

When RSA’s Zulfikar Ramzan finished his keynote discussing technology’s “ripple effect,” Brad Smith, President of Microsoft, took the stage to talk about cyberspace as the new battlefield. He started by pointing out that – unlike when war shifted from land, to the sea, to the air – cyberspace is not physical. Yet the battle can still have... READ MORE

Live From RSA: Zulfikar Ramzan Keynote – Ripples and Technology

jlavery's picture
By Jessica Lavery February 15, 2017  | Security News
RSA 2017: Zulfikar Ramzan

Once John Lithgow left the stage, Zulfikar Ramzan, RSA’s CTO, took the stage to talk about business-driven security. He implored the security professionals in the room to not draw lines between departments, but instead create connections for better collaboration and enhanced security. Sounds a lot like DevOps. Ramzan then spoke a lot about how small events can create larger ripples that... READ MORE

Love to learn about Application Security?

Get all the latest news, tips and articles delivered right to your inbox.