The Application Security Podcast

Steve Springett -- Software and System Transparency

Chris Romeo and Robert Hurlbut Season 11 Episode 21

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 48:13

Steve Springett, an expert in secure software development and a key figure in several OWASP projects is back. Steve unpacks CycloneDX and the value proposition of various BOMs. He gives us a rundown of the BOM landscape and unveils some new BOM projects that will continue to unify the security industry. Steve is a seasoned guest of the show so we learn a bit more about Steve's hobbies, providing a personal glimpse into his life outside of technology. Steve Springett educates teams on the strategy and specifics of developing secure software. He practices security at every development lifecycle stage by leading sessions on threat modeling, secure architecture and design, static dynamic component analysis, offensive research, and defensive programming techniques.

Today's episode is brought to you by Security Journey.

About Security Journey
Our education platform teaches valuable secure coding skills based on real-world vulnerabilities and threats, including OWASP Top 10.
Learn more about Security Journey

Connect with Steve Springett:
CycloneDX
Software Transparency: Supply Chain Security in an Era of a Software-Driven Society

Mentioned in this episode:
CycloneDX
Software Transparency: Supply Chain Security in an Era of a Software-Driven Society
JC Herz and Steve Springett -- SBOMs and software supply chain assurance
OWASP Dependency-Track
CycloneDX
OWASP Foundation
Log4j
Apache Struts
Open Threat Model (OTM)
OWASP Threat Dragon Project
LINDDUN
PCI Security Standards Council
Software Transparency: Supply Chain Security in an Era of a Software-Driven Society by Chris Hughes, Tony Turner
OWASP Dependency-Check

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Meet Steve Springett: Software and System Transparency
02:04 It's, uh, well, the City of Brotherly Love, isn't that what
06:05 That's just, it's just another reminder that we all gotta find
07:44 Um, Robert, where are we, where are we going with Steve
11:00 And I think a lot of people in AppSec are going
12:21 Right
14:26 I'd love to get you kind of on the record giving
19:08 Based on the Log4j, Log4Shell example, let's have it, let's, let's
23:03 We've talked about some of the use cases, but are there
24:52 We think about All of these different capabilities and different, I
30:18 Let's say in relation to that transparency, but also, uh, commonalities
33:19 I know you've been doing some work, Steve, on this idea
36:32 I mean, it, it, I think if I, if I kind
42:47 Okay. Yeah. So we have 3 questions. Do we, have we
45:19 Last question, uh, what's your top book recommendation and why do

Follow the Application Security Podcast:

➜ Home: appsecpodcast.com
➜ X: @AppSecPodcast
➜ LinkedIn: The Application Security Podcast
➜ YouTube: @ApplicationSecurityPodcast
➜ Instagram: @appsecpodcast
➜ Facebook: Application Security Podcast

People on this episode

Podcasts we love

Check out these other fine podcasts recommended by us, not an algorithm.

The Security Table Artwork

The Security Table

Izar Tarandach, Matt Coles, and Chris Romeo