
Advertise on podcast: The AppSec Management Podcast
This podcast has
56 episodes
Language
EnglishPublisher
Dag FlachetExplicit
No
Date created
2025/12/05
Latest episode
2026/09/01
Average duration
24 min.
Release period
11 days
Description
This podcast is about application security, OWASP and security first compliance. It is targeted at those involved with application security programmes and anyone interested in the frontier of cybersecurity in applications.
Unlock The AppSec Management Podcast podcast Email contact info,
Listeners & Audience details
Email contact information
Direct podcast contact details

Listeners
Audience numbers & engagement insights

Audience details
Podcast Insights

Podcast episodes
Check latest episodes from The AppSec Management Podcast podcast
CRA Sessions: Vulnerability Management
2026/09/01
Vulnerability management is at the core of the Cyber Resilience Act (CRA). But what are the minimal expectations? Annex I, Part 2 lists 8 expectations manufacturers shall implement, yet they remain very abstract.Chapters:00:00 Introduction and a motivating example02:39 CRA: a brief recap08:11 Vulnerability management basics10:00 Revisiting the running example of a smart fridge10:38 Incident management18:25 The definition of an incident24:30 Defect management27:26 Security testing28:35 Patching and updating29:51 Secure deploy33:11 Recap of all required security activities under the CRAAbout this video:Today, the topic of vulnerability management typically makes one think of a SAST, DAST, IAST, SCA scanner. It makes us think of a triaging process and fixing the critical and high severity findings in the attempts to try to keep the risk low. However under the CRA vulnerability management is much broader. Fortunately, at least based on the OWASP SAMM latest benchmark, the industry is doing so much better on vulnerability management than on any other security related activities.Incident detection and response is the first major subtopic under vulnerability management. Especially in larger organizations most of the aspects of incident management are well under control. Amongst the key outstanding issues we typically face is the lack of communication between the product teams and the incident management teams as these are always siloed. Without a clear understanding of the business context the incident management can only focus on generic risks.Under the CRA the definition of an incident is interesting to understand. It differs starkly from the organizational perspective where a minor incident affecting a single user may be overlooked. CRA is all about the sensitivity of the data rather than the volume of the data.Defect management is about making sure that all findings are reported to a centralized defect tracking system, triaged and tackled within pre-defined time frames.Security testing is all about the tooling organizations are so excited about. However just pulling in a scanner is likely to make things worse. Teams must have a full grip on their scanners by tweaking the rulesets and how they tie to the build and deploy process.Patching and updating focuses on regularly patching OS and infrastructure components.Finally, secure deploy is actually a very complex topic as it needs to ensure the authenticity and integrity of the code moving from development to production. Code signing is one of the key controls, yet getting that aspect right is not as straightforward as it seems.All in all, you need a systematic approach to product security. Codific's SAMMY tool can help you out there. SAMMY can enable your gap assessment, improvement planning and demonstrating those improvements. SAMMY has an instrumental integration with JIRA so that your developers don't have to jump into a new tool. SAMMY also features an MCP server that allows your AI tools to generate all sorts of board reports based on your data in SAMMY.Links:π Use the SAMMY tool to manage your security posture: https://sammy.codific.comπ Check the industry standard AppSec management model: https://owaspsamm.org
September 11 CRA reporting obligations. What and how to?
2026/08/26
On September 11, 2026 the CRA reporting obligations come into effect. What exactly are you supposed to repot, to whom and how do you do it.
Content from Complycra.eu full article here: https://complycra.eu/what-are-the-cra-obligations-starting-september-11-2026/
To use SAMMY Free go to https://sammy.codific.com
CRA Horizontal Standards Explained
2026/08/14
This chapter summarizes the horizontal standards of CRA and is based on resources from complycra.eu. Voices and narrative is AI generated based on in depth resources. For full factual accuracy refer to complycra.eu
CRA Sessions: Technical Security Requirements
2026/07/20
The Cyber Resilience Act makes it mandatory to take security into consideration from a productβs design until sunsetting. But what are these technical security requirements? Is this about yet another checkbox exercise we can "fake it until we make it" along with a bunch of documents we can now effortlessly generate?
PRC, Product Risk and Compliance
2026/06/16
Traditional GRC tools were built for corporate IT, not for modern software development. As regulations like the EU Cyber Resilience Act raise the bar for product-level security, a new discipline is emerging: Product Risk and Compliance (PRC).
CRA Sessions: Risk Assessment
2026/06/09
Risk assessments are the starting point of your application security program and as it turns out your Cyber Resilience Act compliance strategy. If you think about it, it makes absolute sense. If there is no risk, you don't really need security. Unfortunately, that's not the world we are living in and creating a crystal clear understanding of the risk profile for each of your products is essential.Risk has two components to it. It has a more "businessy" component that is related to loss magnitude or impact. This is the component that needs to be dictated by the business.The second risk component is more technical, namely threat event frequency.The combination of the two factors is what we typically think of risk. However it is critical to stress that the first "business"-side of risk is much easier to come up with. It is also relatively limited. It is also the first one in terms of a sequence. This is also precisely what CRA suggests, you need to start with clearly defining the context of your product, its risk and risk acceptance criteria.The second factor, i.e., the actual threats, is virtually unlimited. Once again you need the business side of the story to come up with meaningful threats.In this second episode of our CRA series podcast we dive deep into the risk assessment and threat modeling concepts in the context of the upcoming EU Cyber Resilience Act.
What is CRA and why do we care?
2026/06/02
Lara and I kick off our new series on the EU Cyber Resilience Act (CRA), where we'll go deep on what the regulation actually means for product security teams and how to translate it into concrete application security practice.In this first episode, we cover the foundations:What the CRA is and why it existsWhich products fall under its scope, and which don'tHow compliance requirements differ between product categories (default, important, and critical)The role of horizontal and vertical standards, and how they fit togetherWhat's at stake if you simply ignore the regulation β the penalties, market access consequences, and liability implicationsTo help you figure out where your product stands, we've also built a CRA screening tool that walks you through the key scoping questions and gives you a first read on your obligations.In the coming episodes, we'll move from the regulatory frame into the practical side: what "secure by design," vulnerability handling, SBOMs, and conformity assessments actually look like when you're shipping real products.π Try the CRA screening tool: https://sammy.codific.com/craπ Subscribe so you don't miss the next episodes.
Is security becoming prompt-driven? The future of AppSec in the age of AI
2026/05/26
AI is changing everything - including how attackers think. But is the security industry keeping up?This webinar, hosted jointly with Toreon, tackles one of the biggest questions in AppSec right now: as AI agents, LLMs, and prompt-driven development become the norm, what does application security even look like?π Follow us on LinkedIn: https://www.linkedin.com/company/9420309/π Or visit our website: https://codific.com/π Subscribe for more AppSec tutorials and security framework insights!
AppSec at SMEs, how are your peers doing?
2026/05/19
In this chapter we have the research team of PXL University of Applied Sciences that did an in depth analysis of the state of AppSec processes at SMEs. They report on their outcomes and findings.
Operational Security With SAMMY
2026/05/12
You can use SAMMY for free on sammy.codific.com
Appsec Management With SAMMY
2026/05/05
You can use sammy for free on sammy.codific.com
AI in AppSec, May 2026 Update
2026/04/28
This episode looks at the latest developments around AI tools in Application Security. Guidance and best practices in the new context.
Introduction to EU DORA
2026/04/21
This is deep dive into DORA the EU Digital Operational Resilience Act.
For more details refer to the Codific website: https://codific.com/summary-of-dora/
CRA Standards
2026/04/14
This episode covers the EN-40000 standards that serve as a provisional basis for CRA Horizontal Standards.
This is the summary of resources collected on complycra.eu for the full story and presentation please refer to the website:
https://complycra.eu/cra-standards/
Introduction to Secure Control Frameworks
2026/04/07
This content is a summary of a deep dive by the Codific team.
For the full coverage refer to the article on the Codific Website: https://codific.com/secure-controls-framework-a-comprehensive-overview/
Podcast reviews
Read The AppSec Management Podcast podcast reviews
Podcast sponsorship advertising
Start advertising on The AppSec Management Podcast relevant audience podcasts
You may also like to advertise on these Podcasts

4.5175169
Crystal's Nightcap
WiLD 94.9

510206
From John To Justin
Craig Baird

5174299
Championship Leadership
Nate Bailey

4.9205106
GAMECHANGER with Setema Gali
Setema Gali: NFL Superbowl Champion, Coach, Mentor, Best-Selling Author

4.9172314
Pool Chasers Podcast
Greg & Justin, Swimming Pool

54266
Mortgage Gumbo
Mortgage Gumbo

4.8181132
Rachel Watches Star Trek
Rachel Watches Star Trek

4.997100
Way of the Heart Podcast
Jake Khym and Brett Powell

4.321340
I Want My Podcast
I W M P

4.936104
Shoot Edit Chat Repeat
Vicki Knights & Eddie Judd