Tech Lead Journal

#138 - Building Application Security Program - Derek Fisher


Listen Later

“Building an application security program is about ensuring security is built into the software development lifecycle and how to respond to vulnerabilities."

Derek Fisher is the author of “Application Security Program Handbook”. In this episode, Derek shared about building an application security program and how to implement it in our organization. First, we discussed some security fundamental concepts, such as shift-left, CIA triad, and threat modeling. Derek then outlined how to start an application security program and measure the program’s success. Derek also touched on the security program maturity model and gave his tips on how to build and hire application security teams. Towards the end, Derek also gave his insights on how to address zero-day vulnerabilities when it becomes prominent.  

Listen out for:

  • Career Journey - [00:03:51]
  • Building Application Security Program - [00:06:56]
  • Shifting Left - [00:11:58]
  • CIA Triad - [00:16:30]
  • Threat Modeling - [00:19:04]
  • Threat Classification - [00:22:49]
  • Starting Application Security Program - [00:27:04]
  • Security Program Maturity Model - [00:32:45]
  • Building Security Teams - [00:35:27]
  • Measuring the Program’s Success - [00:40:19]
  • Zero Day Vulnerabilities - [00:42:48]
  • 3 Tech Lead Wisdom - [00:44:59]
  • _____

    Derek Fisher’s Bio
    Derek is an award winning author of a children’s book series in cybersecurity as well as the author of “The Application Security Handbook.” He is a university instructor at Temple University where he teaches software development security to undergraduate and graduate students. He is a speaker on topics in the cybersecurity space and has led teams, large and small, at organizations in the healthcare and financial industries. He has built and matured information security teams as well as implemented organizational information security strategies to reduce the organizations risk. His focus has been to raise the security awareness of the engineering organization while maintaining a practice of secure code development, delivery, and operations.

    Follow Derek Fisher:

    • LinkedIn – linkedin.com/in/derek-fisher-sec-arch
    • YouTube – @securelybuilt5967
    • Website – securelybuilt.com
    • _____

      Our Sponsors

      Are you looking for a new cool swag? Tech Lead Journal now offers you some swags that you can purchase online. These swags are printed on-demand based on your preference, and will be delivered safely to you all over the world where shipping is available. Check out all the cool swags available by visiting techleadjournal.dev/shop. And don't forget to brag yourself once you receive any of those swags.


      Like this episode?

      Show notes & transcript: techleadjournal.dev/episodes/138

      Follow @techleadjournal on LinkedIn, Twitter, and Instagram.
      Buy me a coffee or become a patron.

      ...more
      View all episodesView all episodes
      Download on the App Store

      Tech Lead JournalBy Henry Suryawirawan

      • 4.7
      • 4.7
      • 4.7
      • 4.7
      • 4.7

      4.7

      12 ratings


      More shows like Tech Lead Journal

      View all
      Hanselminutes with Scott Hanselman by Scott Hanselman

      Hanselminutes with Scott Hanselman

      377 Listeners

      Software Engineering Radio - the podcast for professional software developers by se-radio@computer.org

      Software Engineering Radio - the podcast for professional software developers

      273 Listeners

      .NET Rocks! by Carl Franklin and Richard Campbell

      .NET Rocks!

      246 Listeners

      The Changelog: Software Development, Open Source by Changelog Media

      The Changelog: Software Development, Open Source

      282 Listeners

      The Cloudcast by Massive Studios

      The Cloudcast

      152 Listeners

      Thoughtworks Technology Podcast by Thoughtworks

      Thoughtworks Technology Podcast

      42 Listeners

      Software Engineering Daily by Software Engineering Daily

      Software Engineering Daily

      625 Listeners

      Soft Skills Engineering by Jamison Dance and Dave Smith

      Soft Skills Engineering

      270 Listeners

      AWS Podcast by Amazon Web Services

      AWS Podcast

      203 Listeners

      Syntax - Tasty Web Development Treats by Wes Bos & Scott Tolinski - Full Stack JavaScript Web Developers

      Syntax - Tasty Web Development Treats

      984 Listeners

      CoRecursive: Coding Stories by Adam Gordon Bell - Software Developer

      CoRecursive: Coding Stories

      189 Listeners

      Kubernetes Podcast from Google by Abdel Sghiouar, Kaslin Fields

      Kubernetes Podcast from Google

      181 Listeners

      Practical AI by Practical AI LLC

      Practical AI

      191 Listeners

      The Stack Overflow Podcast by The Stack Overflow Podcast

      The Stack Overflow Podcast

      64 Listeners

      The Pragmatic Engineer by Gergely Orosz

      The Pragmatic Engineer

      52 Listeners