The Application Security Podcast

Matin Mavaddat - Understanding Security as a Systemic Concern: The Role of Anti-Requirements

Chris Romeo and Robert Hurlbut Season 11 Episode 28

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 50:20

Matin Mavaddat discusses his perspective on security as a systemic concern, developed from his background in requirements engineering and systems architecture. He introduces the concept of "anti-requirements" - defining what a system should not do - and distinguishes between "syntactic security" (addressing technical vulnerabilities that are always incorrect) and "semantic security" (context-dependent security emerging from system interactions). Mavaddat shares his perspective that security itself doesn't have independent existence but rather emerges from preventing undesirable states. The discussion concludes with practical implementation strategies, suggesting that while automated tools can handle syntactic security issues, organizations should focus more energy on semantic security by understanding business context and defining anti-requirements early in the development process.

Today's episode is brought to you by Security Journey.

About Security Journey
Our education platform teaches valuable secure coding skills based on real-world vulnerabilities and threats, including OWASP Top 10.
Learn more about Security Journey

Connect with Matin Mavaddat:
Matin's article: Reframing Security: Unveiling Power Anti-Requirements
Systems Thinking for Curious Managers by Russell Ackoff

Mentioned in this episode:
Matin's article: Reframing Security: Unveiling Power Anti-Requirements
Systems Thinking for Curious Managers by Russell Ackoff
Antifragile by Nassim Nicholas Taleb
The Black Swan by Nassim Nicholas Taleb
Nassim Taleb books

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Meet Matin Mavaddat: Understanding Security as a Systemic Concern: The Role of Anti-Requirements
01:48 So I'm excited to have Mateen join us here. And Mateen
04:17 One, one follow-up question. I read the, the article that is
10:38 Mateen, can I give you a quick example
11:42 There like, what would you say
14:20 I like that example. I'm just imagining a pile of parts
20:59 There's independent choices that drive it, right
25:33 I'm going to ask you what I think of as the
29:48 I see the challenge here, Mateen, is people that aren't going
33:29 Happens, here's another million-dollar question. I often think about, in the
41:26 All right. Well, I think we gotta, we gotta move on
47:41 Yeah. Yeah, I agree. I, I've read some of, uh, Taleb's

Follow the Application Security Podcast:

➜ Home: appsecpodcast.com
➜ X: @AppSecPodcast
➜ LinkedIn: The Application Security Podcast
➜ YouTube: @ApplicationSecurityPodcast
➜ Instagram: @appsecpodcast
➜ Facebook: Application Security Podcast

People on this episode

Podcasts we love

Check out these other fine podcasts recommended by us, not an algorithm.

The Security Table Artwork

The Security Table

Izar Tarandach, Matt Coles, and Chris Romeo