
The AppSec Management Podcast
The AppSec Management Podcast focuses on application security, OWASP guidelines, and security-first compliance. It is aimed at professionals involved in application security programs and anyone interested in the cutting edge of cybersecurity within software applications. The show covers practical strategies for integrating security into development processes and staying ahead of emerging threats.
Episodes

CRA Horizontal Standards Explained
This chapter summarizes the horizontal standards of CRA and is based on resources from complycra.eu. Voices and narrative is AI generated based on in depth resources. For full factual accuracy refer to complycra.eu

CRA Sessions: Technical Security Requirements
The Cyber Resilience Act makes it mandatory to take security into consideration from a product’s design until sunsetting. But what are these technical security requirements? Is this about yet another checkbox exercise we can "fake it until we make it" along with a bunch of documents we can now effortlessly generate?

PRC, Product Risk and Compliance
Traditional GRC tools were built for corporate IT, not for modern software development. As regulations like the EU Cyber Resilience Act raise the bar for product-level security, a new discipline is emerging: Product Risk and Compliance (PRC).

CRA Sessions: Risk Assessment
Risk assessments are the starting point of your application security program and as it turns out your Cyber Resilience Act compliance strategy. If you think about it, it makes absolute sense. If there is no risk, you don't really need security. Unfortunately, that's not the world we are living in and creating a crystal clear understanding of the risk profile for each of your products is essential.

What is CRA and why do we care?
Lara and I kick off our new series on the EU Cyber Resilience Act (CRA), where we'll go deep on what the regulation actually means for product security teams and how to translate it into concrete application security practice.In this first episode, we cover the foundations:What the CRA is and why it existsWhich products fall under its scope, and which don'tHow compliance requirements diffe

Is security becoming prompt-driven? The future of AppSec in the age of AI
AI is changing everything - including how attackers think. But is the security industry keeping up?This webinar, hosted jointly with Toreon, tackles one of the biggest questions in AppSec right now: as AI agents, LLMs, and prompt-driven development become the norm, what does application security even look like?📌 Follow us on LinkedIn: https://www.linkedin.com/company/9420309/🌐 Or visit our website

AppSec at SMEs, how are your peers doing?
In this chapter we have the research team of PXL University of Applied Sciences that did an in depth analysis of the state of AppSec processes at SMEs. They report on their outcomes and findings.

Operational Security With SAMMY
You can use SAMMY for free on sammy.codific.com

Appsec Management With SAMMY
You can use sammy for free on sammy.codific.com

AI in AppSec, May 2026 Update
This episode looks at the latest developments around AI tools in Application Security. Guidance and best practices in the new context.

Introduction to EU DORA
This is deep dive into DORA the EU Digital Operational Resilience Act. For more details refer to the Codific website: https://codific.com/summary-of-dora/

CRA Standards
This episode covers the EN-40000 standards that serve as a provisional basis for CRA Horizontal Standards. This is the summary of resources collected on complycra.eu for the full story and presentation please refer to the website:https://complycra.eu/cra-standards/

Introduction to Secure Control Frameworks
This content is a summary of a deep dive by the Codific team. For the full coverage refer to the article on the Codific Website: https://codific.com/secure-controls-framework-a-comprehensive-overview/

How to build and manage your appsec program.
This is a summary of interviews in the Codific website.For the full stories please refer to the Codific website: https://codific.com/codifics-customers-success-stories/

NIS2 Directive: Everything you need to know
This is a summary of a deep dive by the Codific team.For the full article please refer to the Codific website:https://codific.com/nis-2-directive-compliance-guide-fines-scope/

NIST SSDF 1.2: an introduction
This is a summary of a deep dive by Aram Hovsepyan.For the full article refer to the Codific website: https://codific.com/nist-ssdf-1-2-explained/

Women in cybersecurity, what it really looks like, and where you can fit
In this International Women’s Day interview, we speak with Kim Wuyts, a privacy engineer and privacy by design advocate with 15+ years across security and privacy. Kim helped develop LINDDUN, a privacy threat modeling framework, and regularly speaks at international security and privacy conferences.This conversation is for women who are considering cybersecurity or privacy, women already in tech w

Can we do Application Security with AI? An analysis of Claude Code Security.
This episode is based on analysis by Aram Hovsepyan.For the full story refer to his blog post here: https://codific.com/claude-code-security-will-ai-disrupt-application-security/

Understanding the Cyber Resilience Act (CRA): What Software and Product Companies Need to Know
In this episode, Viktor Lukachyk, Security Manager at Sigma Software, joins Nicolas and Dag from Codific to break down the Cyber Resilience Act (CRA) and what it means for software and digital product companies operating in the EU.We discuss how CRA fits alongside regulations like NIS 2 and DORA, which products fall into scope, and why CRA is focused on secure by design principles rather than comp

Frameworks and maturity models explained
ISO 27001, NIST CSF, NIST SSDF, CIS Critical Security Controls Framework. All these things are called frameworks. But what are they really? Why do we need them? And are they only relevant for GRC teams in large organizations? If all your tools show green dashboards, isn’t that enough to claim your software product is secure?In this episode of AppSec Science I explain why frameworks are essential f

The Reality of AppSec Risk Management using CVEs and CVSS scores
Many organizations treat Common Vulnerability Enumerations or CVEs as first class citizens. Some even enforce strict SLAs on CVE remediation times depending on their severity scores expressed with the CVSS metric.The numbers make sense as they are built on top of real and hard data. Moreover, attackers also have access to this data, so building your complete strategy around vulnerability dashboard

The science of security metrics
"If you can’t measure it you can’t improve it.". It is hard to argue with that. But here is the catch, what are we measuring and what are we improving. Measuring the right things right is not a rocket science, but it is a science. Common sense might get you so far, but in my experience common sense is failing us. Organizations are focusing on metrics that are readily produced by tooling,

What is the cost of a Data Breach?
This episode is based on the the IBM cost of a Data Breach report, for full data refer to the report.https://www.ibm.com/reports/data-breach

How to comply with CRA
This episode is based on content from the the Codific website. Voices and narrative are AI generated. For full factual acurracy refer to the Codific website. https://codific.com/application-security-insights-and-other-exciting-stories/

OWASP ASVS, an introduction
This content is based on an article written by Nicolas Montauban. Voices and narrative are AI generated, for full factual accuracy refer to the underlying article.https://codific.com/owasp-asvs-a-comprehensive-overview/

The New OWASP TOP 10, what has changed and why.
This podcast is based on the presentations and press releases of the OWASP and Codific team. For the latest insights check the Codific website.

Top Application Security Failures at Fortune 500 Companies
This podcast is based on in depth analysis by Dr. Aram Hovsepyan. Voices and narrative are AI generated. For full factual accuracy refer to underlying article.https://codific.com/top-application-security-failures-in-fortune-500-companies/

CVE and CVSS are broken.
This podcast is based on in depth analysis by Dr. Aram Hovsepyan. Voices and narrative are AI generated. For full factual accuracy refer to underlying article.https://codific.com/appsec-risk-with-cve-and-cvss/

Privacy Threat Modeling: Learn all about it from two experts in the field!
Learn more about privacy threat modeling in this blog post: https://codific.com/privacy-threat-mo...In this podcast we had a very nice conversation with two experts in the field of privacy threat modeling, Kim Wuyts and Aram Hovsepyan. Privacy threat modeling is a process of identifying and assessing potential threats to an individual's personal information. Kim and Aram are experts in this to

SAMM Assessment: Everything you need to know from industry experts
Join us on this podcast as we convene with four leading Application Security specialists and focus on the assessment aspect of SAMM.SAMM Assessment is the process of figuring out the current security maturity for a given scope (which can be a team, a business unit or the entire organization). Software Assurance Maturity Model (SAMM) provides a clear-cut questionnaire with 90 multiple-choice questi

Embedding Security into the SDLC: How Sign In Solutions uses SAMMY & OWASP SAMM
In this episode, Jason Mordeno, Director of Compliance and Security at Sign In Solutions, shares how his team embedded application security directly into their SDLC using OWASP SAMM and SAMMY.Discover how Signin Solutions moved beyond ISO 27001 and SOC 2 checklists to create a behavior-driven, developer-friendly AppSec culture, resulting in improved security maturity, better risk posture, and even

An introduction to BSIMM, Building Security in Maturity Model
This content is based on an article written by Nicolas Montauban. Voices and narratives are AI generated. For full factual accuracy please refer to the underlying article:https://codific.com/bsimm-building-security-in-maturity-model-a-complete-guide/

How to integrate ZAP into Gitlab.
This episode is based on an article by Dr. Aram Hovsepyan and Alex Ashkov. Voices and narrative are AI generated. For full factual accuracy refer to the underlying article.https://codific.com/how-to-integrate-zap-in-gitlab/

Appsec case study: Attendance Radar
This narrative is based on content from the Codific and AttendanceRadar Websites. For full factual accuracy please refer to the websites:Codific.comAttendanceradar.com

Defect Management Best Practices
This content is based on an article written by Nicolas Montauban. Voices and narrative is AI generated, for full factual accuracy refer to the underlying article.https://codific.com/how-to-implement-security-defect-tracking/

Preparing for CRA
This content is based on an interview with Simon Montete. Voices and narrative are AI generated. For full factual accuracy please refer to the underlying article.https://codific.com/prepare-for-cra/

OWASP SAMM vs OWASP DSOMM
This content is written by Nicolas Montauban. Voices are AI generated. For full factual accuracy refer to the underlying article:https://codific.com/dsomm-vs-samm

Introduction to OWASP DSOMM
This content is written by Nicolas Montauban. Voices and narrative is AI generated. For full factual accuracy refer the the article: https://codific.com/owasp-dsomm-a-comprehensive-introduction

Using ASVS with SAMM.
This content is written by Dr. Aram Hovsepyan.https://codific.com/requirements-driven-testing-the-best-roi-security-practiceVoices and narrative are AI generated. For full factual accuracy refer to the underlying article.

Software Security Requirements Explained: Why It Matters and How to Implement It Effectively
The content for this podcast is written by Dr. Aram Hovsepyan.https://codific.com/mastering-owasp-samm-security-requirements-explainedNarrative and voices are by AI, for full factual accuracy refer to the article linked.

Mistakes to avoid in implementing OWASP SAMM
The content of this episode is written by Dr. Aram Hovsepyan.https://codific.com/how-to-implement-owasp-samm-tooling-example-and-mistakes-to-avoidVoices and narrative are AI generated, refer to the article for full factual accuracy.

Stories from practical use of OWASP SAMM
This episode is based on two articles. Voices are AI generated, for full factual accuracy refer to the articles below:https://codific.com/building-security-into-software/https://codific.com/implementing-owasp-samm

How to implement ISO27001
This episode is based on an article written by Michaella Masters. Voices are AI generated for full factual accuracy refer to the underlying article. https://codific.com/how-to-implement-iso-27001

Getting started with the Cyber Fundamentals (Cyfun) framework.
This episode is based on an article written by Aram Hovsepyan. Voices are AI generated. Please refer to the underlying article for full factual accuracy.https://codific.com/what-is-cyfun-and-how-to-implement-it

How to choose good metrics in AppSec
This article is based on a conference talk by Aram Hovsepyan at OWASP Global Appsec Barcelona 2025.Voices are AI generated. For full factual accuracy please refer to the underlying article:https://codific.com/security-metrics-with-purpose-and-strategic-impact/There is also a free course on metrics by Aram Hovsepyan available on Thinkific.https://owaspsamm.thinkific.com/courses/metrics

Introduction to the SSDLC
This podcast is based on the following article by Nicolas Montauban. Voices are AI generated, for full factual accuracy please refer to underlying article.https://codific.com/what-is-the-ssdlc-a-guide-to-secure-development

Implementing OWASP SAMM: A practical guide
This episode is a practical guide to OWASP SAMM. It is based on the following article:https://codific.com/how-to-implement-owasp-samm-tooling-example-and-mistakes-to-avoid/Voices by Notebook LM

What is FISMA and how to comply with it?
This episode is an introduction to FISMA. Voices are by Notebook LM and content is based on the following article:https://codific.com/what-is-fisma-and-how-to-comply-with-it/

Security's Four Layers: SDLC to Information Security
This episode is about the article by Aram Hovsepyan comparing the different layers in security management.https://codific.com/information-security-and-cybersecurity-understanding-the-layers/Voices by Notebook LM

Contingency planning with NIST 800-34
This episode is a guide to contingency planning with NIST 800-34. Voices are by Notebook LM. Content is from the following article:https://codific.com/nist-800-34-contingency-planning-a-practical-guide-to-resilience/

NIST 800-53: A practical guide.
This episode is a practical guide to NIST 800-53. Voices are by Notebook LM. Content is based on the following articles:https://codific.com/how-to-implement-nist-800-53/https://codific.com/what-is-nist-800-53-a-comprehensive-guide/

Implementing NIST SSDF
This episode is a complete introduction to NIST SSDF. Voices are by Notebook LM and content is based on this article:https://codific.com/what-is-nist-ssdf-and-how-should-you-implement-it/

OWASP SAMM a comprehensive introduction.
This is a comprehensive introduction to OWASP SAMM.The voices are by Notebook LM based on this article by Nicolas Montauban. https://codific.com/owasp-samm-comprehensive-introduction/ Corrections:The correct business functions are:- Governance- Design- Implementation- Verification- Operations

The EU Cyber Resilience Act or CRA
Together with several OWASP experts we analysed the expected impact of the EU CRA regulation, industry readiness, gaps and expected fines. The voices are generated by Notebook ML based on this article:https://codific.com/cra-fines/
Recommended

The Bread and Banter Podcast

The Church of What's Happening Now: The New Testament

Deadline: White House

English Vocabulary Help

این نقطه

Solved Murders - True Crime Stories

紐約鳥|New York Aperture

Doctor Zhivago Slow Read

Apple News In Conversation

The Young and Called Podcast .

Jubal Phone Pranks from The Jubal Show

پلی لیست | PlayList