<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <atom:link href="https://feeds.megaphone.fm/IDG6781277066" rel="self" type="application/rss+xml"/>
    <title>A Hard Look at Software Security</title>
    <link>https://www.csoonline.com/podcast/ahardlook/</link>
    <language>en</language>
    <copyright>Copyright Foundry | Sponsored Content - All rights reserved.</copyright>
    <description>In Season 2 of our podcast series, we’ll discuss the implications and mandates generated by Veracode’s most recent State of Software Security report. Our industry experts will pick up from Season 1’s highlights to take a closer look at application security today. Listeners will learn more about:The impact security debt is having across industriesThe changing attitudes and priorities put around application securityHow the average number of days to fix software flaws has almost tripled since the last reportThe case for scanning early and oftenSponsored by Veracode</description>
    <image>
      <url>https://megaphone.imgix.net/podcasts/094c6952-e92e-11e9-8fae-3387dca27c0f/image/c0651ee7d25358055ee31b9f61d9315d.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress</url>
      <title>A Hard Look at Software Security</title>
      <link>https://www.csoonline.com/podcast/ahardlook/</link>
    </image>
    <itunes:explicit>no</itunes:explicit>
    <itunes:type>serial</itunes:type>
    <itunes:subtitle></itunes:subtitle>
    <itunes:author>Foundry</itunes:author>
    <itunes:summary>In Season 2 of our podcast series, we’ll discuss the implications and mandates generated by Veracode’s most recent State of Software Security report. Our industry experts will pick up from Season 1’s highlights to take a closer look at application security today. Listeners will learn more about:The impact security debt is having across industriesThe changing attitudes and priorities put around application securityHow the average number of days to fix software flaws has almost tripled since the last reportThe case for scanning early and oftenSponsored by Veracode</itunes:summary>
    <content:encoded>
      <![CDATA[<p>In Season 2 of our podcast series, we’ll discuss the implications and mandates generated by Veracode’s most recent State of Software Security report. Our industry experts will pick up from Season 1’s highlights to take a closer look at application security today. Listeners will learn more about:The impact security debt is having across industriesThe changing attitudes and priorities put around application securityHow the average number of days to fix software flaws has almost tripled since the last reportThe case for scanning early and oftenSponsored by Veracode</p>]]>
    </content:encoded>
    <itunes:owner>
      <itunes:name>Foundry</itunes:name>
      <itunes:email>podcasts@foundryco.com</itunes:email>
    </itunes:owner>
    <itunes:image href="https://megaphone.imgix.net/podcasts/094c6952-e92e-11e9-8fae-3387dca27c0f/image/c0651ee7d25358055ee31b9f61d9315d.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
    <itunes:category text="Technology">
    </itunes:category>
    <itunes:category text="News">
      <itunes:category text="Tech News"/>
    </itunes:category>
    <item>
      <title>Ep. 6, S2: Frequency matters: the case for scanning early and often, part 2</title>
      <link>https://www.csoonline.com/article/3516162/frequency-matters-the-case-for-scanning-early-and-often-part-2.html</link>
      <description>Security debt – which is defined as aging and accumulating flaws in software -- is a lot like credit card debt. You can throw money at the balance, but if you don’t stop spending, you’re never going to actually get out of debt. 

In this episode of A Hard Look at Software Security, Chris Wysopal, Chief Technology Officer with Veracode, will join us to continue our conversation on software scanning with focus on the accumulating security debt in applications caused by persistent flaws in long-term time frames.

Listeners will learn more about:


  Why there is less security debt in organizations that scan their code more than 300 times per year

  How to know if security debt is meaningful

  Best practices for incorporating scanning into the process 


Produced by FoundryCo, Inc., in association with Veracode.</description>
      <pubDate>Thu, 23 Jan 2020 16:41:00 -0000</pubDate>
      <itunes:title>Frequency matters: the case for scanning early and often, part 2</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>2</itunes:season>
      <itunes:episode>6</itunes:episode>
      <itunes:author>Foundry</itunes:author>
      <itunes:subtitle></itunes:subtitle>
      <itunes:summary>Security debt – which is defined as aging and accumulating flaws in software -- is a lot like credit card debt. You can throw money at the balance, but if you don’t stop spending, you’re never going to actually get out of debt. 

In this episode of A Hard Look at Software Security, Chris Wysopal, Chief Technology Officer with Veracode, will join us to continue our conversation on software scanning with focus on the accumulating security debt in applications caused by persistent flaws in long-term time frames.

Listeners will learn more about:


  Why there is less security debt in organizations that scan their code more than 300 times per year

  How to know if security debt is meaningful

  Best practices for incorporating scanning into the process 


Produced by FoundryCo, Inc., in association with Veracode.</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Security debt – which is defined as aging and accumulating flaws in software -- is a lot like credit card debt. You can throw money at the balance, but if you don’t stop spending, you’re never going to actually get out of debt. </p>
<p>In this episode of A Hard Look at Software Security, Chris Wysopal, Chief Technology Officer with Veracode, will join us to continue our conversation on software scanning with focus on the accumulating security debt in applications caused by persistent flaws in long-term time frames.</p>
<p>Listeners will learn more about:</p>
<ul>
  <li>Why there is less security debt in organizations that scan their code more than 300 times per year</li>
  <li>How to know if security debt is meaningful</li>
  <li>Best practices for incorporating scanning into the process </li>
</ul>
<p>Produced by FoundryCo, Inc., in association with Veracode.</p>]]>
      </content:encoded>
      <itunes:duration>896</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[37d1ff4a-3df6-11ea-97ff-2ba658834655]]></guid>
      <enclosure url="https://traffic.megaphone.fm/IDG3076108813.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Ep. 5, S2: Frequency matters: the case for scanning early and often, part 1</title>
      <link>https://www.csoonline.com/article/3516131/frequency-matters-the-case-for-scanning-early-and-often-part-1.html</link>
      <description>The latest Veracode State of Software Security report reveals that scanning early, often, and steadily helps you fix more flaws faster while not contributing to security debt. The report finds 56 percent of software flaws eventually get fixed. While 76 percent of high severity flaws are addressed by developers, half of the applications showed a net reduction in flaws over the sample time frame.

In this episode of a Hard Look at Software Security, Paul Farrington, chief technology officer for the Europe, Middle East, and Asia regions for Veracode, will dive deeper into those numbers and discuss when development teams should consider scanning and why.

Listeners will learn more about:


  The stage at which development teams should engage in software scanning

  DevSecOps culture and how to enable it

  Where DevSecOps is heading in the future 




Produced by FoundryCo, Inc., in association with Veracode.</description>
      <pubDate>Thu, 23 Jan 2020 16:35:00 -0000</pubDate>
      <itunes:title>Frequency matters: the case for scanning early and often, part 1</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>2</itunes:season>
      <itunes:episode>5</itunes:episode>
      <itunes:author>Foundry</itunes:author>
      <itunes:subtitle></itunes:subtitle>
      <itunes:summary>The latest Veracode State of Software Security report reveals that scanning early, often, and steadily helps you fix more flaws faster while not contributing to security debt. The report finds 56 percent of software flaws eventually get fixed. While 76 percent of high severity flaws are addressed by developers, half of the applications showed a net reduction in flaws over the sample time frame.

In this episode of a Hard Look at Software Security, Paul Farrington, chief technology officer for the Europe, Middle East, and Asia regions for Veracode, will dive deeper into those numbers and discuss when development teams should consider scanning and why.

Listeners will learn more about:


  The stage at which development teams should engage in software scanning

  DevSecOps culture and how to enable it

  Where DevSecOps is heading in the future 




Produced by FoundryCo, Inc., in association with Veracode.</itunes:summary>
      <content:encoded>
        <![CDATA[<p>The latest Veracode State of Software Security report reveals that scanning early, often, and steadily helps you fix more flaws faster while not contributing to security debt. The report finds 56 percent of software flaws eventually get fixed. While 76 percent of high severity flaws are addressed by developers, half of the applications showed a net reduction in flaws over the sample time frame.</p>
<p>In this episode of a Hard Look at Software Security, Paul Farrington, chief technology officer for the Europe, Middle East, and Asia regions for Veracode, will dive deeper into those numbers and discuss when development teams should consider scanning and why.</p>
<p>Listeners will learn more about:</p>
<ul>
  <li>The stage at which development teams should engage in software scanning</li>
  <li>DevSecOps culture and how to enable it</li>
  <li>Where DevSecOps is heading in the future </li>
</ul>
<p><br></p>
<p>Produced by FoundryCo, Inc., in association with Veracode.</p>]]>
      </content:encoded>
      <itunes:duration>1037</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[e31b9038-3df5-11ea-b061-37d1eb014461]]></guid>
      <enclosure url="https://traffic.megaphone.fm/IDG2363131894.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Ep. 4, S2: AppSec grows up</title>
      <link>https://www.csoonline.com/article/3516091/appsec-grows-up.html</link>
      <description>AppSec awareness has grown in a decade. In Veracode’s State of Software Security report, Volume one, most of the conversation was around trying to explain and advocate for application security. Today, far less of that is necessary and more emphasis is put on talking about how to build an effective, mature application security program.

In this episode of a Hard Look at Software Security, Chris Wysopal, Chief Technology Officer with Veracode, will discuss positive AppSec signs – and what they mean for security best practices.

Listeners will learn more about:


  Factors influencing the change in application security programs

  What the State of Software Security report uncovers when it comes to current AppSec efforts

  Why awareness about AppSec risk has grown, but actual risk reduction still has room for improvement


Produced by FoundryCo, Inc., in association with Veracode.</description>
      <pubDate>Thu, 23 Jan 2020 16:30:00 -0000</pubDate>
      <itunes:title>AppSec grows up</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>2</itunes:season>
      <itunes:episode>4</itunes:episode>
      <itunes:author>Foundry</itunes:author>
      <itunes:subtitle></itunes:subtitle>
      <itunes:summary>AppSec awareness has grown in a decade. In Veracode’s State of Software Security report, Volume one, most of the conversation was around trying to explain and advocate for application security. Today, far less of that is necessary and more emphasis is put on talking about how to build an effective, mature application security program.

In this episode of a Hard Look at Software Security, Chris Wysopal, Chief Technology Officer with Veracode, will discuss positive AppSec signs – and what they mean for security best practices.

Listeners will learn more about:


  Factors influencing the change in application security programs

  What the State of Software Security report uncovers when it comes to current AppSec efforts

  Why awareness about AppSec risk has grown, but actual risk reduction still has room for improvement


Produced by FoundryCo, Inc., in association with Veracode.</itunes:summary>
      <content:encoded>
        <![CDATA[<p>AppSec awareness has grown in a decade. In Veracode’s State of Software Security report, Volume one, most of the conversation was around trying to explain and advocate for application security. Today, far less of that is necessary and more emphasis is put on talking about how to build an effective, mature application security program.</p>
<p>In this episode of a Hard Look at Software Security, Chris Wysopal, Chief Technology Officer with Veracode, will discuss positive AppSec signs – and what they mean for security best practices.</p>
<p>Listeners will learn more about:</p>
<ul>
  <li>Factors influencing the change in application security programs</li>
  <li>What the State of Software Security report uncovers when it comes to current AppSec efforts</li>
  <li>Why awareness about AppSec risk has grown, but actual risk reduction still has room for improvement</li>
</ul>
<p>Produced by FoundryCo, Inc., in association with Veracode.</p>]]>
      </content:encoded>
      <itunes:duration>874</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[ff5ba54a-3df4-11ea-80c1-c786a31f191c]]></guid>
      <enclosure url="https://traffic.megaphone.fm/IDG8620589915.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Ep.3, S2: Unresolved flaws: security debt grows deeper</title>
      <link>https://www.csoonline.com/article/3516159/unresolved-flaws-security-debt-grows-deeper.html</link>
      <description>The average number of days to fix software flaws was at 59 days in the first Veracode State of Software report from ten years ago. Today, it’s jumped to 171 days in the latest 2019 report.

While typical median fix times haven't gotten worse in 10 years – they have remained about the same - security debt is getting much deeper.

In this episode of a Hard Look at Software Security, Chris Eng, Vice President of Research with Veracode, will discuss relevance of the findings on median time to remediate flaws - and where organizations may stand when it comes to their own security debt.

Listeners will learn about:


  Why security debt is getting much deeper

  If fixes are based on flaw severity or exploitablilty

  Why the source of an application affects fix speed of remediation




Produced by FoundryCo, Inc., in association with Veracode.</description>
      <pubDate>Thu, 23 Jan 2020 16:23:00 -0000</pubDate>
      <itunes:title>Unresolved flaws: security debt grows deeper</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>2</itunes:season>
      <itunes:episode>3</itunes:episode>
      <itunes:author>Foundry</itunes:author>
      <itunes:subtitle></itunes:subtitle>
      <itunes:summary>The average number of days to fix software flaws was at 59 days in the first Veracode State of Software report from ten years ago. Today, it’s jumped to 171 days in the latest 2019 report.

While typical median fix times haven't gotten worse in 10 years – they have remained about the same - security debt is getting much deeper.

In this episode of a Hard Look at Software Security, Chris Eng, Vice President of Research with Veracode, will discuss relevance of the findings on median time to remediate flaws - and where organizations may stand when it comes to their own security debt.

Listeners will learn about:


  Why security debt is getting much deeper

  If fixes are based on flaw severity or exploitablilty

  Why the source of an application affects fix speed of remediation




Produced by FoundryCo, Inc., in association with Veracode.</itunes:summary>
      <content:encoded>
        <![CDATA[<p>The average number of days to fix software flaws was at 59 days in the first Veracode State of Software report from ten years ago. Today, it’s jumped to 171 days in the latest 2019 report.</p>
<p>While typical median fix times haven't gotten worse in 10 years – they have remained about the same - security debt is getting much deeper.</p>
<p>In this episode of a Hard Look at Software Security, Chris Eng, Vice President of Research with Veracode, will discuss relevance of the findings on median time to remediate flaws - and where organizations may stand when it comes to their own security debt.</p>
<p>Listeners will learn about:</p>
<ul>
  <li>Why security debt is getting much deeper</li>
  <li>If fixes are based on flaw severity or exploitablilty</li>
  <li>Why the source of an application affects fix speed of remediation</li>
</ul>
<p><br></p>
<p>Produced by FoundryCo, Inc., in association with Veracode.</p>]]>
      </content:encoded>
      <itunes:duration>669</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[3c959d68-3df4-11ea-b061-5f803ea90b84]]></guid>
      <enclosure url="https://traffic.megaphone.fm/IDG8022635052.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Ep. 2 S2: Security debt across sectors: behind the numbers</title>
      <link>https://www.csoonline.com/article/3516158/security-debt-across-sectors-behind-the-numbers.html</link>
      <description>According to the latest State of Security Software report from Veracode, the retail industry has the lowest average number of unaddressed security flaws. Government and education have the largest “iceberg“ of security debt lurking below the surface. Financial services firms have the best fix rate among all industries.

In this episode of a Hard Look at Software Security, Tim Jarrett, Senior Director of Product Management with Veracode, will discuss security debt across industries, and what is influencing their flaw fix rates.

Listeners will learn more about:


  The differences in software security across sectors

  Why the government and education sectors have a so-called iceberg of security debt

  The details on why finance has the best fix rate




Produced by FoundryCo, Inc., in association with Veracode.</description>
      <pubDate>Thu, 23 Jan 2020 15:57:00 -0000</pubDate>
      <itunes:title>Security debt across sectors: behind the numbers</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>2</itunes:season>
      <itunes:episode>2</itunes:episode>
      <itunes:author>Foundry</itunes:author>
      <itunes:subtitle></itunes:subtitle>
      <itunes:summary>According to the latest State of Security Software report from Veracode, the retail industry has the lowest average number of unaddressed security flaws. Government and education have the largest “iceberg“ of security debt lurking below the surface. Financial services firms have the best fix rate among all industries.

In this episode of a Hard Look at Software Security, Tim Jarrett, Senior Director of Product Management with Veracode, will discuss security debt across industries, and what is influencing their flaw fix rates.

Listeners will learn more about:


  The differences in software security across sectors

  Why the government and education sectors have a so-called iceberg of security debt

  The details on why finance has the best fix rate




Produced by FoundryCo, Inc., in association with Veracode.</itunes:summary>
      <content:encoded>
        <![CDATA[<p>According to the latest State of Security Software report from Veracode, the retail industry has the lowest average number of unaddressed security flaws. Government and education have the largest “iceberg“ of security debt lurking below the surface. Financial services firms have the best fix rate among all industries.</p>
<p>In this episode of a Hard Look at Software Security, Tim Jarrett, Senior Director of Product Management with Veracode, will discuss security debt across industries, and what is influencing their flaw fix rates.</p>
<p>Listeners will learn more about:</p>
<ul>
  <li>The differences in software security across sectors</li>
  <li>Why the government and education sectors have a so-called iceberg of security debt</li>
  <li>The details on why finance has the best fix rate</li>
</ul>
<p><br></p>
<p>Produced by FoundryCo, Inc., in association with Veracode.</p>]]>
      </content:encoded>
      <itunes:duration>837</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[e8529bf2-3df3-11ea-9166-bfff73168e1e]]></guid>
      <enclosure url="https://traffic.megaphone.fm/IDG1666374577.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Ep. 1, S2: What’s behind most security debt</title>
      <link>https://www.csoonline.com/article/3516035/what-s-behind-most-security-debt.html</link>
      <description>Security debt - defined as aging and accumulating flaws in software - is emerging as a significant pain point for organizations across industries.

In this first episode of our second season of a Hard Look at Software Security, Tim Jarrett, Senior Director of Product Management with Veracode, will discuss what factors are behind security debt and how security managers can arm themselves with this knowledge to tackle the problem.

Listeners will learn about:


  How cross-site scripting is contributing to security debt and why it’s noteworthy

  Findings on how organizations are prioritizing fixes

  Why security debt is not being discussed enough among security professionals




Produced by FoundryCo, Inc., in association with Veracode.</description>
      <pubDate>Thu, 23 Jan 2020 15:44:00 -0000</pubDate>
      <itunes:title>What’s behind most security debt</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>2</itunes:season>
      <itunes:episode>1</itunes:episode>
      <itunes:author>Foundry</itunes:author>
      <itunes:subtitle></itunes:subtitle>
      <itunes:summary>Security debt - defined as aging and accumulating flaws in software - is emerging as a significant pain point for organizations across industries.

In this first episode of our second season of a Hard Look at Software Security, Tim Jarrett, Senior Director of Product Management with Veracode, will discuss what factors are behind security debt and how security managers can arm themselves with this knowledge to tackle the problem.

Listeners will learn about:


  How cross-site scripting is contributing to security debt and why it’s noteworthy

  Findings on how organizations are prioritizing fixes

  Why security debt is not being discussed enough among security professionals




Produced by FoundryCo, Inc., in association with Veracode.</itunes:summary>
      <content:encoded>
        <![CDATA[<p>Security debt - defined as aging and accumulating flaws in software - is emerging as a significant pain point for organizations across industries.</p>
<p>In this first episode of our second season of a Hard Look at Software Security, Tim Jarrett, Senior Director of Product Management with Veracode, will discuss what factors are behind security debt and how security managers can arm themselves with this knowledge to tackle the problem.</p>
<p>Listeners will learn about:</p>
<ul>
  <li>How cross-site scripting is contributing to security debt and why it’s noteworthy</li>
  <li>Findings on how organizations are prioritizing fixes</li>
  <li>Why security debt is not being discussed enough among security professionals</li>
</ul>
<p><br></p>
<p>Produced by FoundryCo, Inc., in association with Veracode.</p>]]>
      </content:encoded>
      <itunes:duration>898</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[74260070-3df3-11ea-8ec3-af3aee3184f7]]></guid>
      <enclosure url="https://traffic.megaphone.fm/IDG9215178375.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>How Can A Security Champion Help Your Development Team?</title>
      <link>https://www.csoonline.com/article/3387147/how-can-a-security-champion-help-your-development-team.html</link>
      <description>A security champion serves as the voice of the developer while satisfying the needs of the business from a security perspective. In this episode we dig deeper into details on the role of the security champion and what effect having a champion can have on development and security. Listeners will learn about: • How to identify a security champion in your organization • What benefits can be expected from having a security champion • Suggestions for getting started with a security champion program</description>
      <pubDate>Fri, 05 Apr 2019 14:27:00 -0000</pubDate>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <itunes:episode>6</itunes:episode>
      <itunes:author>Foundry</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/098eca18-e92e-11e9-ac60-7b68d68134db/image/ed9bb3307722b9c8eae16a1a25628a72.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>A security champion serves as the voice of the de…</itunes:subtitle>
      <itunes:summary>A security champion serves as the voice of the developer while satisfying the needs of the business from a security perspective. In this episode we dig deeper into details on the role of the security champion and what effect having a champion can have on development and security. Listeners will learn about: • How to identify a security champion in your organization • What benefits can be expected from having a security champion • Suggestions for getting started with a security champion program</itunes:summary>
      <content:encoded>
        <![CDATA[<p>A security champion serves as the voice of the developer while satisfying the needs of the business from a security perspective. In this episode we dig deeper into details on the role of the security champion and what effect having a champion can have on development and security. Listeners will learn about: • How to identify a security champion in your organization • What benefits can be expected from having a security champion • Suggestions for getting started with a security champion program</p>]]>
      </content:encoded>
      <itunes:duration>979</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[tag:soundcloud,2010:tracks/601410699]]></guid>
      <enclosure url="https://traffic.megaphone.fm/IDG5858076267.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Flaw Fix Rates Are Low - How Can They Be Improved?</title>
      <link>https://www.csoonline.com/article/3363702/flaw-fix-rates-are-low-how-can-they-be-improved.html</link>
      <description>In this episode we discuss the latest findings on flaw fix rates in enterprises. Chris Eng, Vice President of Research, Veracode, offers perspective on what figures in the State of Software Security report reveal about the troubling amount of time it takes to address the majority of vulnerabilities. Listeners will learn about: • Average enterprise fix rates at one week and one month • Why enterprises still struggle with vulnerable open source components in software • What business can can do to mitigate risks associated with open source flaws</description>
      <pubDate>Tue, 12 Mar 2019 19:23:00 -0000</pubDate>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <itunes:episode>5</itunes:episode>
      <itunes:author>Foundry</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/09b16ee2-e92e-11e9-ac60-efe82383771a/image/ed9bb3307722b9c8eae16a1a25628a72.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode we discuss the latest findings on…</itunes:subtitle>
      <itunes:summary>In this episode we discuss the latest findings on flaw fix rates in enterprises. Chris Eng, Vice President of Research, Veracode, offers perspective on what figures in the State of Software Security report reveal about the troubling amount of time it takes to address the majority of vulnerabilities. Listeners will learn about: • Average enterprise fix rates at one week and one month • Why enterprises still struggle with vulnerable open source components in software • What business can can do to mitigate risks associated with open source flaws</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode we discuss the latest findings on flaw fix rates in enterprises. Chris Eng, Vice President of Research, Veracode, offers perspective on what figures in the State of Software Security report reveal about the troubling amount of time it takes to address the majority of vulnerabilities. Listeners will learn about: • Average enterprise fix rates at one week and one month • Why enterprises still struggle with vulnerable open source components in software • What business can can do to mitigate risks associated with open source flaws</p>]]>
      </content:encoded>
      <itunes:duration>954</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[tag:soundcloud,2010:tracks/589051854]]></guid>
      <enclosure url="https://traffic.megaphone.fm/IDG1363298501.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Open Source Components Continue to Thwart Enterprises</title>
      <description>In this episode, we’ll discuss why enterprises still struggle with the occurrence of vulnerable open source components within their software - and what they can do to mitigate these risks. Listeners will learn more about: • The landscape of open source software today compared to internally developed code in enterprises • Why risk from open source components is an issue in most enterprises • The factors behind the friction between the process of DevOps and security</description>
      <pubDate>Tue, 26 Feb 2019 19:51:00 -0000</pubDate>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <itunes:episode>4</itunes:episode>
      <itunes:author>Foundry</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/09e951ea-e92e-11e9-ac60-eff7ac1792d3/image/artworks-000495295566-vjiomz-original.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode, we’ll discuss why enterprises st…</itunes:subtitle>
      <itunes:summary>In this episode, we’ll discuss why enterprises still struggle with the occurrence of vulnerable open source components within their software - and what they can do to mitigate these risks. Listeners will learn more about: • The landscape of open source software today compared to internally developed code in enterprises • Why risk from open source components is an issue in most enterprises • The factors behind the friction between the process of DevOps and security</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode, we’ll discuss why enterprises still struggle with the occurrence of vulnerable open source components within their software - and what they can do to mitigate these risks. Listeners will learn more about: • The landscape of open source software today compared to internally developed code in enterprises • Why risk from open source components is an issue in most enterprises • The factors behind the friction between the process of DevOps and security</p>]]>
      </content:encoded>
      <itunes:duration>686</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[tag:soundcloud,2010:tracks/581788899]]></guid>
      <enclosure url="https://traffic.megaphone.fm/IDG1322551714.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Building a Security-first Culture Starts with Coding</title>
      <description>In this episode, we learn about changes in application security and the partnership between development and security. Chris Wysopal, Chief Technology Officer and Co-Founder of Veracode, joins us to discuss the synergy between these teams – and what best practices help create a solid devsecops program. Listeners will learn more about: • The factors behind the evolving relationship between development and security • What this change means for secure coding in the future • Action items for creating a security-first culture in the enterprise</description>
      <pubDate>Tue, 26 Feb 2019 19:49:00 -0000</pubDate>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <itunes:episode>3</itunes:episode>
      <itunes:author>Foundry</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/0a171562-e92e-11e9-ac60-f3df2b70842f/image/artworks-000495293619-hl75fa-original.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode, we learn about changes in applic…</itunes:subtitle>
      <itunes:summary>In this episode, we learn about changes in application security and the partnership between development and security. Chris Wysopal, Chief Technology Officer and Co-Founder of Veracode, joins us to discuss the synergy between these teams – and what best practices help create a solid devsecops program. Listeners will learn more about: • The factors behind the evolving relationship between development and security • What this change means for secure coding in the future • Action items for creating a security-first culture in the enterprise</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode, we learn about changes in application security and the partnership between development and security. Chris Wysopal, Chief Technology Officer and Co-Founder of Veracode, joins us to discuss the synergy between these teams – and what best practices help create a solid devsecops program. Listeners will learn more about: • The factors behind the evolving relationship between development and security • What this change means for secure coding in the future • Action items for creating a security-first culture in the enterprise</p>]]>
      </content:encoded>
      <itunes:duration>687</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[tag:soundcloud,2010:tracks/581787771]]></guid>
      <enclosure url="https://traffic.megaphone.fm/IDG4690322657.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>Data Supports DevSecOps Practices</title>
      <description>In this episode, we will look at the emergence of DevSecOps in the enterprise. Tim Jarrett, Senior Director of Product Marketing with Veracode, joins us to explain the goal of building security into the software development process at the outset. Listeners will learn more about: • What research says about the effectiveness of DevSecOps • The core principles of DevSecOps • What is holding DevSecOps back from going mainstream? • Predictions on where this practice is heading in the future</description>
      <pubDate>Tue, 29 Jan 2019 15:23:00 -0000</pubDate>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <itunes:episode>2</itunes:episode>
      <itunes:author>Foundry</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/0a4120aa-e92e-11e9-ac60-af8c63357915/image/artworks-000479738940-0g2qwa-original.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In this episode, we will look at the emergence of…</itunes:subtitle>
      <itunes:summary>In this episode, we will look at the emergence of DevSecOps in the enterprise. Tim Jarrett, Senior Director of Product Marketing with Veracode, joins us to explain the goal of building security into the software development process at the outset. Listeners will learn more about: • What research says about the effectiveness of DevSecOps • The core principles of DevSecOps • What is holding DevSecOps back from going mainstream? • Predictions on where this practice is heading in the future</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In this episode, we will look at the emergence of DevSecOps in the enterprise. Tim Jarrett, Senior Director of Product Marketing with Veracode, joins us to explain the goal of building security into the software development process at the outset. Listeners will learn more about: • What research says about the effectiveness of DevSecOps • The core principles of DevSecOps • What is holding DevSecOps back from going mainstream? • Predictions on where this practice is heading in the future</p>]]>
      </content:encoded>
      <itunes:duration>1028</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[tag:soundcloud,2010:tracks/566624910]]></guid>
      <enclosure url="https://traffic.megaphone.fm/IDG8557174869.mp3" length="0" type="audio/mpeg"/>
    </item>
    <item>
      <title>The State of Software Security is Still a Challenge</title>
      <description>In the first episode of the series, we are joined by Chris Eng, Vice President of Research at Veracode. We’ll detail highlights of the Veracode State of Software Security Volume 9 report and discuss what the findings reveal in terms of the progress companies are making with fixing flaws. How are factors like flaw severity, business criticality of applications, and exploitability of the flaws impacting how companies view vulnerabilities? We’ll also examine information about industry performance, differences by region, third-party component risks, and vulnerability trends to give security and development teams a holistic view of the state of software security.</description>
      <pubDate>Thu, 03 Jan 2019 15:27:00 -0000</pubDate>
      <itunes:episodeType>full</itunes:episodeType>
      <itunes:season>1</itunes:season>
      <itunes:episode>1</itunes:episode>
      <itunes:author>Foundry</itunes:author>
      <itunes:image href="https://megaphone.imgix.net/podcasts/0a691b14-e92e-11e9-ac60-b7b225d1cf32/image/artworks-000466702275-jvrq1s-original.jpg?ixlib=rails-4.3.1&amp;max-w=3000&amp;max-h=3000&amp;fit=crop&amp;auto=format,compress"/>
      <itunes:subtitle>In the first episode of the series, we are joined…</itunes:subtitle>
      <itunes:summary>In the first episode of the series, we are joined by Chris Eng, Vice President of Research at Veracode. We’ll detail highlights of the Veracode State of Software Security Volume 9 report and discuss what the findings reveal in terms of the progress companies are making with fixing flaws. How are factors like flaw severity, business criticality of applications, and exploitability of the flaws impacting how companies view vulnerabilities? We’ll also examine information about industry performance, differences by region, third-party component risks, and vulnerability trends to give security and development teams a holistic view of the state of software security.</itunes:summary>
      <content:encoded>
        <![CDATA[<p>In the first episode of the series, we are joined by Chris Eng, Vice President of Research at Veracode. We’ll detail highlights of the Veracode State of Software Security Volume 9 report and discuss what the findings reveal in terms of the progress companies are making with fixing flaws. How are factors like flaw severity, business criticality of applications, and exploitability of the flaws impacting how companies view vulnerabilities? We’ll also examine information about industry performance, differences by region, third-party component risks, and vulnerability trends to give security and development teams a holistic view of the state of software security.</p>]]>
      </content:encoded>
      <itunes:duration>955</itunes:duration>
      <itunes:explicit>no</itunes:explicit>
      <guid isPermaLink="false"><![CDATA[tag:soundcloud,2010:tracks/553538550]]></guid>
      <enclosure url="https://traffic.megaphone.fm/IDG4972104776.mp3" length="0" type="audio/mpeg"/>
    </item>
  </channel>
</rss>
