SlideShare a Scribd company logo
How to do application security right
Meet the
panel
Executive Partner, Independent Security Evaluators
Infosec Skills Author
Jeff Peters
Director of Content Marketing
Infosec
Ted Harrington
Additional training resources
More from Ted Harrington
⮚ How to secure your software faster and better (ebook)
⮚ Ted’s Infosec Resources articles
⮚ How to Do Application Security Right courses
(need to create a free Infosec Skills account)
Other free resources from Infosec
⮚ Infosec Skills Monthly Challenge
⮚ Infosec YouTube channel
⮚ Infosec Accelerate Scholarship
Agenda: 10 mistakes organizations make
Challenges: Skills shortage
“Your best option is to
take a two-pronged
approach: build your
own expertise in-house,
and also hire an external
security team.”
Organizational security
External
team
In-house
experts
Testing: What methodology?
Black box is a testing
methodology that limits
information
White box is a testing
methodology that
maximizes information
vs.
Testing: What type?
“Asking for penetration
testing, being sold
vulnerability scanning,
but likely need
vulnerability
assessments.”
Scanning
Penetration
testing
Vulnerability
assessments
Find and remediate issues
Source: Hackable
“Advanced tactics is
where the magic
happens. When you
go beyond the basics,
that’s where the
critical-type issues are
found.”
Let’s talk money!
“No rational person
wants anything to be 25
times harder or 10.1
percent more expensive
than it needs to be. Yet,
companies do this all the
time when they choose
to bolt on security.”
Source: Hackable
Questions?
15 scholarships. 5 categories. $225,000+ value.
Learn cybersecurity with Infosec Skills
Infosec Skills subscription:
➢ 190+ role-based learning paths (e.g., Ethical Hacking,
Digital Forensics, Advanced Intrusion Detection)
➢ 100s of hands-on labs in cloud-hosted cyber ranges
➢ Custom certification practice exams and skill
assessments aligned to key cybersecurity roles
Infosec Skills live boot camp:
➢ Live, instructor-led training (in-person or live online)
➢ Free annual Infosec Skills subscription
➢ 1-year extended access to all boot camp video replays
and materials
➢ Exam voucher and Exam Pass Guarantee
infosecinstitute.com/skills
About us
Infosec believes knowledge is power when fighting
cybercrime. We help IT and security professionals advance
their careers with skills development and certifications
while empowering all employees with security awareness
and privacy training to stay cyber-safe at work and home.
www.infosecinstitute.com

More Related Content

PPTX
Learn intrusion detection: Using Zeek and Elastic for incident response
PPTX
A public discussion about privacy careers: Training, certification and experi...
PPTX
Top_10_Interview_Questions_That_You_Should_Know_as_an_Information.pptx
PDF
Myth-busting in Application Security
PPTX
Getting started in digital forensics
PPTX
Cyber Security 101: Training, awareness, strategies for small to medium sized...
PPTX
Intro to INFOSEC
PDF
Information Security Awareness
Learn intrusion detection: Using Zeek and Elastic for incident response
A public discussion about privacy careers: Training, certification and experi...
Top_10_Interview_Questions_That_You_Should_Know_as_an_Information.pptx
Myth-busting in Application Security
Getting started in digital forensics
Cyber Security 101: Training, awareness, strategies for small to medium sized...
Intro to INFOSEC
Information Security Awareness

Similar to How to do application security right (20)

PDF
Fissea09 mgupta-day3-panel process-program-build-effective-training
PPTX
Slide Deck – Class Session 1 – FRSecure CISSP Mentor Program
PDF
Slide Deck - CISSP Mentor Program Class Session 1
PDF
KnowBe4-Presentation-Overview.pdf
PDF
Information Security Analyst- Infosec train
PDF
Cybersecurity: Not Just a Skill A Shield for the Digital World
PPTX
How to build a cyber threat intelligence program
PPTX
Countering the Cyber Threat
PDF
How Cyber Security Courses Opens Up Amazing Career Opportunities?
PDF
How to Become a Cyber Security Analyst in Delhi_ Career Roadmap.pdf
PDF
CEH Vs CISSP: Which one is better?
PPTX
Ceh vs Cissp difficulty, Salary, Job!
PPTX
EthicalHack{aksdladlsfsamnookfmnakoasjd}.pptx
PPTX
Best Ethical Hacking course in delhi-ncr
PPTX
7 Ultimate Benefits Of Ethical Hacking Course To Boost Your IT Career.pptx
PDF
Girl Geek X Indeed Talks (January 18, 2018)
PDF
Vulnerability Analyst interview Questions.pdf
PPTX
Cybersecurity: An FBI perspective: how cyber criminals exploit the goodness o...
DOCX
Ethnosit.net
PDF
Banning Whining, Avoiding Cyber Wolves, and Creating Warrior
Fissea09 mgupta-day3-panel process-program-build-effective-training
Slide Deck – Class Session 1 – FRSecure CISSP Mentor Program
Slide Deck - CISSP Mentor Program Class Session 1
KnowBe4-Presentation-Overview.pdf
Information Security Analyst- Infosec train
Cybersecurity: Not Just a Skill A Shield for the Digital World
How to build a cyber threat intelligence program
Countering the Cyber Threat
How Cyber Security Courses Opens Up Amazing Career Opportunities?
How to Become a Cyber Security Analyst in Delhi_ Career Roadmap.pdf
CEH Vs CISSP: Which one is better?
Ceh vs Cissp difficulty, Salary, Job!
EthicalHack{aksdladlsfsamnookfmnakoasjd}.pptx
Best Ethical Hacking course in delhi-ncr
7 Ultimate Benefits Of Ethical Hacking Course To Boost Your IT Career.pptx
Girl Geek X Indeed Talks (January 18, 2018)
Vulnerability Analyst interview Questions.pdf
Cybersecurity: An FBI perspective: how cyber criminals exploit the goodness o...
Ethnosit.net
Banning Whining, Avoiding Cyber Wolves, and Creating Warrior
Ad

More from Infosec (20)

PPTX
CompTIA PenTest+ is changing in 2025: Everything you need to know
PPTX
Bridging the gap From security awareness training to human risk management - ...
PPTX
How to stay relevant as a cyber professional: Skills, trends and career paths...
PPTX
AWS Certified DevOps Engineer: What it is and how to get certified
PPTX
AWS Cloud Operations Administrator: What it is and how to get certified
PPTX
AWS Certified Security - Specialty: What it is and how to get certified
PPTX
AWS Certified Solutions Architect Webinar.pptx
PPTX
Infosec and AWS - A new way to train for your AWS certification (1).pptx
PPTX
How AI and ChatGPT are changing cybersecurity forever.pptx
PPTX
2023.06 - CompTIA Security+ Everything you need to know about the new exam .pptx
PPTX
NCSAM 2023 Webinar.pptx
PPTX
CompTIA CySA+ certification (CS0-003) changes: Everything you need to know
PPTX
Skills training value: How to differentiate your staff and your organization ...
PDF
Learning ≠ Education: How people really learn and what it means for security ...
PPTX
Security awareness training - 4 topics that matter most
PPTX
Join the hunt: Threat hunting for proactive cyber defense.pptx
PPTX
Threat hunting foundations: People, process and technology.pptx
PPTX
Get started in cybersecurity in 2022
PDF
CompTIA PenTest+: Everything you need to know about the exam
PPTX
CompTIA CASP+ | Everything you need to know about the new exam
CompTIA PenTest+ is changing in 2025: Everything you need to know
Bridging the gap From security awareness training to human risk management - ...
How to stay relevant as a cyber professional: Skills, trends and career paths...
AWS Certified DevOps Engineer: What it is and how to get certified
AWS Cloud Operations Administrator: What it is and how to get certified
AWS Certified Security - Specialty: What it is and how to get certified
AWS Certified Solutions Architect Webinar.pptx
Infosec and AWS - A new way to train for your AWS certification (1).pptx
How AI and ChatGPT are changing cybersecurity forever.pptx
2023.06 - CompTIA Security+ Everything you need to know about the new exam .pptx
NCSAM 2023 Webinar.pptx
CompTIA CySA+ certification (CS0-003) changes: Everything you need to know
Skills training value: How to differentiate your staff and your organization ...
Learning ≠ Education: How people really learn and what it means for security ...
Security awareness training - 4 topics that matter most
Join the hunt: Threat hunting for proactive cyber defense.pptx
Threat hunting foundations: People, process and technology.pptx
Get started in cybersecurity in 2022
CompTIA PenTest+: Everything you need to know about the exam
CompTIA CASP+ | Everything you need to know about the new exam
Ad

Recently uploaded (20)

PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
Encapsulation theory and applications.pdf
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
Electronic commerce courselecture one. Pdf
PPTX
sap open course for s4hana steps from ECC to s4
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PPTX
MYSQL Presentation for SQL database connectivity
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
KodekX | Application Modernization Development
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PDF
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
Approach and Philosophy of On baking technology
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
MIND Revenue Release Quarter 2 2025 Press Release
PPTX
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
Review of recent advances in non-invasive hemoglobin estimation
Encapsulation theory and applications.pdf
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Electronic commerce courselecture one. Pdf
sap open course for s4hana steps from ECC to s4
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Dropbox Q2 2025 Financial Results & Investor Presentation
MYSQL Presentation for SQL database connectivity
Building Integrated photovoltaic BIPV_UPV.pdf
KodekX | Application Modernization Development
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
NewMind AI Weekly Chronicles - August'25 Week I
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Approach and Philosophy of On baking technology
Digital-Transformation-Roadmap-for-Companies.pptx
MIND Revenue Release Quarter 2 2025 Press Release
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx

How to do application security right

  • 2. Meet the panel Executive Partner, Independent Security Evaluators Infosec Skills Author Jeff Peters Director of Content Marketing Infosec Ted Harrington
  • 3. Additional training resources More from Ted Harrington ⮚ How to secure your software faster and better (ebook) ⮚ Ted’s Infosec Resources articles ⮚ How to Do Application Security Right courses (need to create a free Infosec Skills account) Other free resources from Infosec ⮚ Infosec Skills Monthly Challenge ⮚ Infosec YouTube channel ⮚ Infosec Accelerate Scholarship
  • 4. Agenda: 10 mistakes organizations make
  • 5. Challenges: Skills shortage “Your best option is to take a two-pronged approach: build your own expertise in-house, and also hire an external security team.” Organizational security External team In-house experts
  • 6. Testing: What methodology? Black box is a testing methodology that limits information White box is a testing methodology that maximizes information vs.
  • 7. Testing: What type? “Asking for penetration testing, being sold vulnerability scanning, but likely need vulnerability assessments.” Scanning Penetration testing Vulnerability assessments
  • 8. Find and remediate issues Source: Hackable “Advanced tactics is where the magic happens. When you go beyond the basics, that’s where the critical-type issues are found.”
  • 9. Let’s talk money! “No rational person wants anything to be 25 times harder or 10.1 percent more expensive than it needs to be. Yet, companies do this all the time when they choose to bolt on security.” Source: Hackable
  • 11. 15 scholarships. 5 categories. $225,000+ value.
  • 12. Learn cybersecurity with Infosec Skills Infosec Skills subscription: ➢ 190+ role-based learning paths (e.g., Ethical Hacking, Digital Forensics, Advanced Intrusion Detection) ➢ 100s of hands-on labs in cloud-hosted cyber ranges ➢ Custom certification practice exams and skill assessments aligned to key cybersecurity roles Infosec Skills live boot camp: ➢ Live, instructor-led training (in-person or live online) ➢ Free annual Infosec Skills subscription ➢ 1-year extended access to all boot camp video replays and materials ➢ Exam voucher and Exam Pass Guarantee infosecinstitute.com/skills
  • 13. About us Infosec believes knowledge is power when fighting cybercrime. We help IT and security professionals advance their careers with skills development and certifications while empowering all employees with security awareness and privacy training to stay cyber-safe at work and home. www.infosecinstitute.com