Популярное

Музыка Кино и Анимация Автомобили Животные Спорт Путешествия Игры Юмор

Интересные видео

2025 Сериалы Трейлеры Новости Как сделать Видеоуроки Diy своими руками

Топ запросов

смотреть а4 schoolboy runaway турецкий сериал смотреть мультфильмы эдисон
dTub
Скачать

Modern AppSec: OWASP SAMM, AI Secure Coding, Threat Modeling & Champions - ASW

Автор: Security Weekly - A CRA Resource

Загружено: 2025-12-23

Просмотров: 231

Описание:

Using OWASP SAMM to assess and improve compliance with the Cyber Resilience Act (CRA) is an excellent strategy, as SAMM provides a framework for secure development practices such as secure by design principles and handling vulns.

Segment Resources:
https://owaspsamm.org/
https://cybersecuritycoalition.be/res...


As genAI becomes a more popular tool in software engineering, the definition of “secure coding” is changing. This session explores how artificial intelligence is reshaping the way developers learn, apply, and scale secure coding practices — and how new risks emerge when machines start generating the code themselves. We’ll dive into the dual challenge of securing both human-written and AI-assisted code, discuss how enterprises can validate AI outputs against existing security standards, and highlight practical steps teams can take to build resilience into the entire development pipeline. Join us as we look ahead to the convergence of secure software engineering and AI security — where trust, transparency, and tooling will define the future of code safety.

Segment Resources:
https://manicode.com/ai/



Understand the history of threat modeling with Adam Shostack. Learn how threat modeling has evolved with the Four Question Framework and can work in your organizations in the wake of the AI revolution.



Whether you're launching a formal Security Champions program or still figuring out where to start, there's one truth every security leader needs to hear: You already have allies in your org -- they're just waiting to be activated. In this session, we’ll explore how identifying and empowering your internal advocates is the fastest, most sustainable way to drive security culture change. These are your early adopters: the developers, engineers, and team leads who already “get it,” even if their title doesn’t say “security.”

We’ll unpack:
Why you need help from people outside the security org to actually be effective
Where to find your natural allies (hint: it starts with listening, not preaching)
How to support and energize those allies so they influence the majority
What behavioral science tells us about spreading change across an organization

Segment Resources:
Security Champion Success Guide: https://securitychampionsuccessguide....
Related interviews/podcasts:    • Dustin Lehr Speaking Appearances  
How to measure success and impact of culture change and champions:   / from-soft-skills-hard-data-measuring-succe...  
Global Community of Champions sign up: https://docs.google.com/forms/d/e/1FA...


This interview is sponsored by the OWASP GenAI Security Project. Visit https://securityweekly.com/owaspappsec to watch all of CyberRisk TV's interviews from the OWASP 2025 Global AppSec Conference!

Visit https://www.securityweekly.com/asw for all the latest episodes!

Show Notes: https://securityweekly.com/asw-362

Modern AppSec: OWASP SAMM, AI Secure Coding, Threat Modeling & Champions - ASW

Поделиться в:

Доступные форматы для скачивания:

Скачать видео mp4

  • Информация по загрузке:

Скачать аудио mp3

Похожие видео

AI-Era AppSec: Transparency, Trust, and Risk Beyond the Firewall - ASW #363

AI-Era AppSec: Transparency, Trust, and Risk Beyond the Firewall - ASW #363

Синьор 1С: 10 привычек, без которых ты не вырастешь

Синьор 1С: 10 привычек, без которых ты не вырастешь

The Upsides and Downsides of LLM-Generated Code - Chris Wysopal - ASW #364

The Upsides and Downsides of LLM-Generated Code - Chris Wysopal - ASW #364

Сисадмины больше не нужны? Gemini настраивает Linux сервер и устанавливает cтек N8N. ЭТО ЗАКОННО?

Сисадмины больше не нужны? Gemini настраивает Linux сервер и устанавливает cтек N8N. ЭТО ЗАКОННО?

Чем ОПАСЕН МАХ? Разбор приложения специалистом по кибер безопасности

Чем ОПАСЕН МАХ? Разбор приложения специалистом по кибер безопасности

The Future Of Proactive Security Before Building an AI Enabled Enterprise - Erik Nost - BSW #430

The Future Of Proactive Security Before Building an AI Enabled Enterprise - Erik Nost - BSW #430

Уязвимости в современных JavaScript-фреймворках на примере React, Vue и Angular / А. Важинская

Уязвимости в современных JavaScript-фреймворках на примере React, Vue и Angular / А. Важинская

Python for AI & Agents - Full Beginner Course

Python for AI & Agents - Full Beginner Course

Илон Маск (свежее интервью 2026): энергетика, ИИ, технологии, освоение космоса, андроиды, другое

Илон Маск (свежее интервью 2026): энергетика, ИИ, технологии, освоение космоса, андроиды, другое

Are you dead?, AI Hellscape, Copilot, Blue Delta, Quishing, Confer, Aaran Leyland - SWN #546

Are you dead?, AI Hellscape, Copilot, Blue Delta, Quishing, Confer, Aaran Leyland - SWN #546

Secure By Design Is Better Than Secure By Myth - Bob Lord - ASW #365

Secure By Design Is Better Than Secure By Myth - Bob Lord - ASW #365

Deep Dive into the OWASP Top 10 for Agentic AI Applications - John Sotiropoulos

Deep Dive into the OWASP Top 10 for Agentic AI Applications - John Sotiropoulos

OpenAI, Google, Apple: кто реально победит в гонке AI

OpenAI, Google, Apple: кто реально победит в гонке AI

Zettelkasten + AI: Как я связал ChatGPT и Obsidian в единую систему знаний

Zettelkasten + AI: Как я связал ChatGPT и Obsidian в единую систему знаний

OWASP Agentic AI Security Summit - Live-Stream from London

OWASP Agentic AI Security Summit - Live-Stream from London

Ralph Loop — x100 продуктивности Claude Code

Ralph Loop — x100 продуктивности Claude Code

Dark Web РАСКРЫТ (БЕСПЛАТНО + Инструмент с открытым исходным кодом)

Dark Web РАСКРЫТ (БЕСПЛАТНО + Инструмент с открытым исходным кодом)

The State of Cybersecurity Hiring, 2026 content plans, and the weekly news - ESW #441

The State of Cybersecurity Hiring, 2026 content plans, and the weekly news - ESW #441

How AI will change software engineering – with Martin Fowler

How AI will change software engineering – with Martin Fowler

Hacking AI is TOO EASY (this should be illegal)

Hacking AI is TOO EASY (this should be illegal)

© 2025 dtub. Все права защищены.



  • Контакты
  • О нас
  • Политика конфиденциальности



Контакты для правообладателей: infodtube@gmail.com