
technologyFeb 14, 202337:30pending
Ep 111: How to use the Software Assurance Maturity Model (SAMM) to Build Highly Secure Applications
About this episode
The “buzz” in building more secure applications is “shift security left,” which means integrating security into and throughout the Software Development Lifecycle (SDLC).
The Software Assurance Maturity Model (SAMM) is an excellent tool from OWASP that provides a framework for assessing and improving your development processes, resulting in more secure applications. In this episode, your host, John Verry, CISO and Managing Partner at Pivot Point Security, sits down with Sebastien Deleersnyder, co-lead of the OWASP SAMM project, to discuss in depth how you can use SAMM to improve your application security program.
Join us as we discuss the following:
● The biggest challenge teams face in developing secure applications
● Using OWASP SAMM to assess your current security process
● Where most orgs really are today in terms of AppSec
● Identifying quick wins to improve web app security
● Leveraging SAMM alongside other security frameworks like NIST 800-218 and ISO 27001
To hear this episode and many more like it, we encourage you to subscribe to the Virtual CISO Podcast on our YouTube here.
To Stay up to date with the newest podcast releases, follow us on LinkedIn here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
The Software Assurance Maturity Model (SAMM) is an excellent tool from OWASP that provides a framework for assessing and improving your development processes, resulting in more secure applications. In this episode, your host, John Verry, CISO and Managing Partner at Pivot Point Security, sits down with Sebastien Deleersnyder, co-lead of the OWASP SAMM project, to discuss in depth how you can use SAMM to improve your application security program.
Join us as we discuss the following:
● The biggest challenge teams face in developing secure applications
● Using OWASP SAMM to assess your current security process
● Where most orgs really are today in terms of AppSec
● Identifying quick wins to improve web app security
● Leveraging SAMM alongside other security frameworks like NIST 800-218 and ISO 27001
To hear this episode and many more like it, we encourage you to subscribe to the Virtual CISO Podcast on our YouTube here.
To Stay up to date with the newest podcast releases, follow us on LinkedIn here.
Listening on a desktop & can’t see the links? Just search for The Virtual CISO Podcast in your favorite podcast player.
Get every episode summarized
Each time The Virtual CISO Podcast publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from The Virtual CISO Podcast

Episode 157: AI Security: Testing, Exploits, and Threat Feeds With Marco Figuero...
The Virtual CISO Podcast
Apr 3, 202650:13failed

Episode 156: AI Security: Threat Modeling & Pipeline Evolution with Jason Rebhol...
The Virtual CISO Podcast
Feb 25, 202648:52pending

Episode 155: Incident Response Testing in Cloud Forward Organizations with Matt...
The Virtual CISO Podcast
Dec 17, 202530:16pending

Ep 154: How DORA Will Impact US Companies with Dejan Kosutic
The Virtual CISO Podcast
Nov 6, 202533:56pending