The Application Security Podcast

Farshad Abasi -- Three Models for Deploying AppSec Resources


Listen Later

Farshad Abasi shares three models for deploying resources within application security teams:

  1. The Dedicated AppSec Person Model involves assigning an AppSec person to work with each team. Farshad shares his experience of working with developers and the challenges faced in getting them to understand and implement threat modeling. He also discusses the transition from waterfall to Agile and how it affected threat modeling.
  2. The Federated Model: A security consultant attends weekly standups and sprint planning sessions in this model. They work with a checklist to quickly determine if any user stories could be security sensitive. This model reduces the allocation required to 10 to 20% of an AppSec consultant.
  3. The Champion or Deputy Model: The AppSec team deputizes developers to do the bulk of the application security work, and the AppSec team becomes a resource and escalation point for more complex problems. Each DevOps team appoints a security champion, and these champions form a working group supported by an AppSec person. The champions handle day-to-day issues and threat modeling, with the AppSec team providing mentorship and support.

Over several years, Farshad's journey progressed from the expert-led model to a fully-deputized, champion-driven approach to AppSec. 

After careful consideration, we conclude that the fully deputized model is the only path to scalability.

FOLLOW OUR SOCIAL MEDIA:

➜Twitter: @AppSecPodcast
➜LinkedIn: The Application Security Podcast
➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast

Thanks for Listening!

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

...more
View all episodesView all episodes
Download on the App Store

The Application Security PodcastBy Chris Romeo and Robert Hurlbut

  • 5
  • 5
  • 5
  • 5
  • 5

5

36 ratings


More shows like The Application Security Podcast

View all
Risky Business by Patrick Gray

Risky Business

371 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

651 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,020 Listeners

Thoughtworks Technology Podcast by Thoughtworks

Thoughtworks Technology Podcast

43 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,064 Listeners

Application Security Weekly (Audio) by Security Weekly Productions

Application Security Weekly (Audio)

13 Listeners

Application Security Weekly (Video) by Security Weekly Productions

Application Security Weekly (Video)

4 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

179 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

189 Listeners

The Peter Attia Drive by Peter Attia, MD

The Peter Attia Drive

8,506 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

74 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

139 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

44 Listeners

The Rundown by Public.com

The Rundown

413 Listeners

The Security Table by Izar Tarandach, Matt Coles, and Chris Romeo

The Security Table

2 Listeners