25 Years of Appsec - Appsec Global
Adam is delivering the opening keynote for OWASP Global Appsec 2021 with a 25 year restrospective on the history of appsec and a look into its future.
Adam is delivering the opening keynote for OWASP Global Appsec 2021 with a 25 year restrospective on the history of appsec and a look into its future.
New at Darkreading, a post on NIST and threat modeling
Earlier this week, NIST released a Recommended Minimum Standard for Vendor or Developer Verification of Code. I want to talk about the technical standard overall, the threat modeling component, and the what the standard means now and in the future.
Apple has released ‘Device and Data Access when Personal Safety is At Risk’ and I wanted to explore it a bit.
If everyone agrees on what we should do, why do we seem incapable of doing it?
Expanding on the UK Government's ‘The Uk Code of Practice for Consumer IoT Security’ and how it aligns with Threat Modeling.
As the expression goes, no one cares about backups, they care about restores. Do yours work?
A few tidbits in recent news.
Earlier this year, I helped to organize a workshop at Schloss Dagstuhl on Empirical Evaluation of Secure Development Processes. I think the workshop was a tremendous success.
My talks from AppSecCali 2019
A new game from SANS for understanding pen test methodology, tactics, and tools.
The House Oversight Committee has released a scathing report on Equifax...
[no description provided]
Near misses are an important source of information for avoiding accidents, and it's a shame we don't use them in cybersecurity.
[no description provided]
[no description provided]
[no description provided]