Episode
Armchair Architects: Secure Software Development Lifecycle (Part 1)
with Ulrich (Uli) Homann, Eric Charran, David Blank-Edelman
The secure software development cycle (SDLC) emphasizes integrating security at every stage of development, rather than as an afterthought. In this episode of the Armchair Architects (part of the Azure Essentials Show), our trio of architects discuss key points of SDLC, including the concept of shift left, secure by design, training and tools, and AI assistance. In this video, you'll also hear them discuss the importance of early security integration, and practical examples of secure coding practices. Be sure to catch part two of this conversation!
Chapters
- 00:00 - Introduction
- 01:13 - Eric defines Shift Left
- 02:21 - Secure by design
- 03:04 - The Internet changed everything
- 04:27 - Static Application Security Testing
- 06:23 - Dynamic Application Security Testing
- 07:13 - Examples
- 08:17 - SAST methods
- 08:46 - DAST methods
- 10:21 - Whats in part 2
Recommended resources
- Develop secure applications on Azure
- Practical advice for securing secrets across the SDLC
- Recommendations for securing a development lifecycle (WAF)
Related episodes
Connect
- Ulrich (Uli) Homann | LinkedIn: /in/ulrichhomann
- Eric Charran | LinkedIn: /in/ericcharran
- David Blank-Edelman | LinkedIn: /in/dnblankedelman
The secure software development cycle (SDLC) emphasizes integrating security at every stage of development, rather than as an afterthought. In this episode of the Armchair Architects (part of the Azure Essentials Show), our trio of architects discuss key points of SDLC, including the concept of shift left, secure by design, training and tools, and AI assistance. In this video, you'll also hear them discuss the importance of early security integration, and practical examples of secure coding practices. Be sure to catch part two of this conversation!
Chapters
- 00:00 - Introduction
- 01:13 - Eric defines Shift Left
- 02:21 - Secure by design
- 03:04 - The Internet changed everything
- 04:27 - Static Application Security Testing
- 06:23 - Dynamic Application Security Testing
- 07:13 - Examples
- 08:17 - SAST methods
- 08:46 - DAST methods
- 10:21 - Whats in part 2
Recommended resources
- Develop secure applications on Azure
- Practical advice for securing secrets across the SDLC
- Recommendations for securing a development lifecycle (WAF)
Related episodes
Connect
- Ulrich (Uli) Homann | LinkedIn: /in/ulrichhomann
- Eric Charran | LinkedIn: /in/ericcharran
- David Blank-Edelman | LinkedIn: /in/dnblankedelman
Have feedback? Submit an issue here.