--- title: "Derek Fisher -- The Application Security Handbook" url: https://appsecpodcast.com/derek-fisher-the-application-security-handbook/ date: 2023-03-02 duration_seconds: 2493 guests: ["Derek Fisher"] topics: ["Building an AppSec Program", "Security Testing", "Software Supply Chain", "DevSecOps and CI/CD"] audio: https://www.buzzsprout.com/1730684/episodes/12356607-derek-fisher-the-application-security-handbook.mp3 video: https://www.youtube.com/watch?v=DgmlHgNT-UM transcript: true --- # Derek Fisher -- The Application Security Handbook *March 2, 2023 · 42 min* with [Derek Fisher](https://appsecpodcast.com/guests/derek-fisher/) on [Building an AppSec Program](https://appsecpodcast.com/topics/appsec-programs/), [Security Testing](https://appsecpodcast.com/topics/security-testing/), [Software Supply Chain](https://appsecpodcast.com/topics/supply-chain/), [DevSecOps and CI/CD](https://appsecpodcast.com/topics/devsecops/) [Audio](https://www.buzzsprout.com/1730684/episodes/12356607-derek-fisher-the-application-security-handbook.mp3) · [Video](https://www.youtube.com/watch?v=DgmlHgNT-UM) ## Show notes Derek is the author of “The Application Security Handbook. ” He is a university instructor at Temple University, where he teaches software development security to undergraduate and graduate students. He is a speaker on topics in the cybersecurity space and has led security teams, large and small, at organizations in the healthcare and financial industries. Derek joins us to unpack the goals of an application security program, what is cutting edge in application security programs today, the role of open source vs. commercial, and guidance such as "decentralized application security. " "enablement instead of gates; application security as a service," and "stop chasing the shiny new tool. The Application Security Podcast is brought to you by [Security Journey](https://www.securityjourney.com/). About Security Journey Derek Fisher is the author of The Application Security Handbook. → [Learn more about Security Journey](https://www.securityjourney.com/) Connect with Derek Fisher: → [The Application Security Handbook](https://www.manning.com/books/application-security-program-handbook) → [Application Security Program Handbook](https://www.simonandschuster.com/books/Application-Security-Program-Handbook/Derek-Fisher/9781633439818) Mentioned in this episode: → [The Application Security Handbook](https://www.manning.com/books/application-security-program-handbook) → [Application Security Program Handbook](https://www.simonandschuster.com/books/Application-Security-Program-Handbook/Derek-Fisher/9781633439818) → [Manning Publications](https://www.manning.com/) → [OWASP ModSecurity Core Rule Set](https://coreruleset.org/) Chapters: 00:00 Meet Derek Fisher: The Application Security Handbook 02:04 Excellent. And I know you just wrote a book or just 04:27 Derek, you mentioned in our previous conversation getting ready for this 10:27 Rewind the tape here. That's not entry-level. If you have to 14:51 It's, I mean, I think there is value though, right 17:26 With that in mind, in thinking about application programs today, is 20:02 I think about, you know, across the innovation we've seen in 22:18 I think part of the challenge is there really hasn't been 25:38 Yeah, it kind of brings you to more of a culture 30:17 Or sound impressive, right 33:52 So you also, you know, you kind of mentioned this a 38:16 Yeah, no, that's helpful, helpful to have that perspective. Like, it's 39:22 My, I'm going to go first with a key takeaway here ## Transcript *7,121 words · assemblyai* **0:00 Chris Romeo:** Derek Fisher is the author of The Application Security Handbook. He's a university instructor at Temple University where he teaches software development security to undergrad and graduate students. He's a speaker on topics in the cybersecurity space and has led security teams, large and small, at organizations in the healthcare and financial industries. Derek joins us to unpack the goals of an application security program. What is cutting edge in AppSec programs today? the role of open source versus commercial, and guidance on topics such as decentralized application security, enablement instead of gates, and stop chasing the shiny new tool. We hope you enjoy this conversation with Derek Fisher. How do you create security champions? Security Journey brings together 2 powerful approaches to provide application security education to help developers become security champions and produce safer applications. Security Journey training content extends beyond developers to reach the entire SDLC, creating a security-first organization. Learn more about our enterprise security training at securityjourney.com. **1:10 Robert Hurlbut:** Hey folks, welcome to another episode of the Application Security Podcast. My name is Robert Hurlbut, and I am a principal application security architect at Acquia, as well as focused on threat modeling. And I'm joined by my co-host, Chris Romeo. Hey, Chris. Hey, Robert. **1:40 Chris Romeo:** Chris Romeo, CEO at Curve Ventures, and I can't think of anything else more creative to say today, so I'm just gonna— I'm gonna leave it there. **1:47 Robert Hurlbut:** All right. And today we're gonna be, of course, talking about application security again. We have Our special guest today, Derek Fisher. Welcome, Derek, and thank you for joining us. **1:58 Derek Fisher:** Yeah, thanks for having me on. I'm excited to have some good conversation here. **2:03 Robert Hurlbut:** Excellent. And I know you just wrote a book or just, just got published, and I have a copy of it. Chris has as well, and we've been looking at it on Application Security Program Handbook. Fantastic book. But we want to first, before we dive into some questions about application security and programs and so forth, wanted to check in with you. What is your security origin story? **2:26 Derek Fisher:** Yeah, so, you know, I've been in engineering for, I guess, going on 30 years now. I started out in hardware engineering a long, long time ago and, you know, eventually got into software. And when I was in software engineering and development, I had the opportunity to partner up with one of our leading security individuals in the organization I was in. They were the Chief Product Security Officer, and I was able to really kind of be mentored by him, and I caught the bug. I felt that it was, you know, very obviously a very interesting space. That's why we're— those of us that are in it are in it. I think it's interesting. There's always something new. There's always a new challenge. And so I felt that that was, you know, it made sense for me to pursue that. I enjoyed the challenge, the ever-changing landscape. It's not indifferent from, you know, just general engineering in the sense that, you know, there's always something new going on. There's always, you know, new challenges to try to solve. But I think security has a little bit more of a— there's more at stake, right? I think we all understand that, You know, there's a lot of challenges that have very big implications for people, not just their data and their livelihoods, but in some cases, depending on the industry you're in, there's real-life consequences for some of the decisions that we make in security and engineering. So for me, I think, you know, that also added an additional facet of challenge to it. So I went off and pursued a cybersecurity degree, a graduate degree from Boston University, got several certifications, and have been in it for going on about 10 years now. So haven't looked back and enjoyed every moment of it. **4:27 Chris Romeo:** And Derek, you mentioned in our previous conversation getting ready for this that, you know, you're doing some teaching at Temple University. And so I'm curious, what are you taking away from that? What have you learned about the next generation of software engineers from that? **4:44 Derek Fisher:** Yeah, it's— I remember the way it got started there is kind of interesting. I partnered with a coworker and friend of mine that was teaching at Temple University as a QA. He was teaching a QA class and he said, hey, you know, maybe once a semester, why don't you come in and just, you know, take half the class and talk about security? And so, you know, because in fact I have these conversations today that, you know, QA is not much different than what we do from a security perspective. It's— instead of doing quality assurance, we're doing security assurance. So it was a nice partnership there between the two of us. And so, you know, I did that for a few semesters with him and eventually got introduced to the head of the technology department there. And we started having conversations about starting a class there. And I remember the guy that got me in there, that it was you know, the QA teacher, he said nobody's ever gonna sign up for that class. It's like, it's boring. Nobody's gonna sign up for that class. And it's been over capacity every single semester since I started teaching it, to the point now where I'm now teaching 2 sections per semester, and both of them are over capacity with a waitlist. And, you know, I'm fending off requests to join the class, you know, consistently every single semester. So So I think that, you know, there's one or two takeaways from this. The more comical takeaway that I usually hear from other people is that it's because it's an easy class and it's an easy A, and, you know, everyone wants to go do it because they know they're going to be able to get through it without too much trouble. You know, the way I prefer to look at it is that I think that there's a real genuine desire for engineers to have this under their belt. So the students that join my course are not just software engineers, but they're also IT specialists. So it's, you know, it's a mix of CIS and CS. And so I think that's beneficial in the sense that we're getting more technologists, whether they're developers or they're engineers or IT specialists or system admins, they're getting an appreciation of security. And, you know, that's one of the things that we often fight in this space is that we wanna make sure that we're not the only ones that know security. When everyone knows security and when everyone has a stake in security, then we're gonna be a more secure organization. So I think seeing the enthusiasm to join the class is great. Now, of course, you know, most students, it's an elective course, Temple, so, you know, nobody's really necessarily required. I hope that that changes, you know, as we kind of go forward, just in at the education level that, you know, we do make this required, not just at the college level, but even, you know, at the high school level, that we start making these types of classes more required. But it's good to see the enthusiasm for it and seeing people wanting to learn about this. But in the course, you could definitely see that there's some people that have some real security chops, like somebody that really— this is what they want to do. And I've actually, on my team, have hired 2 of them out of Temple onto my team that they report to me today. So there's, you know, there are, you know, there's, there's some people that are definitely wanting to do this as a career and they see the, you know, they see the benefits of that. And I think that's good. For those that are not, you know, going off to become security, you know, weenies, you know, down the road and their goal is just to understand more about security, then that's great too. I consider that that's, you know, a job well done. So, and I often tell the students, you know, at the end of the semester, like, hey, like, if This is gonna set you apart, right? I, you know, you, you look at all the university graduates that graduate with a CS degree or CIS degree, you know, I'm not, not throwing shade here, but I mean, you're, you're gonna be in the mix with a lot of other people with very, very similar skills. And, you know, having this type of background and this type of interest will set you apart from, from an employer standpoint. Even if you're not going into security, you know, even if you just say, hey, like, I understand how security gets integrated into applications, you know, development, that will set you apart. So, I think it's been good to see that. **9:38 Chris Romeo:** Yeah, and it's exciting that you're seeing that demand as well because, you know, I mean, we can argue about how many open cybersecurity roles, and I don't know that I trust the numbers that get thrown around. There's, you know, 750,000 unfilled jobs or what, and that seems a little bit excessive, but we know Anybody that works in this industry, we know we need more people to enter this industry. We know we're short. Like, we can all agree that. And it's good to hear that there's some enthusiasm now as people are looking at this. And that's just a positive thing for the future that we're going to have more people coming into this. Now, if we can just figure out how to create an entry-level role in security, like every time I look at this, like— **10:21 Derek Fisher:** Yeah. **10:22 Chris Romeo:** Oh, entry-level, 3 to 5 years experience. Well, hold on a second now. **10:25 Derek Fisher:** That's not entry-level. **10:26 Chris Romeo:** Rewind the tape here. That's not entry-level. If you have to have 3 to 5 years experience, that's a mid-level role. Like, call it what it is. And that's a whole other tangent. I know we're here to talk about AppSec programs. That's a whole other tangent. So, right, I better circle us back, you know, towards what we're here to talk about. So, I always ask this question of all of our authors, and I forgot to tell you in advance, but what Why write this book now? Like, what's the— what drove you to— because I know writing books is a labor of love from everybody's told me. It takes far more hours than anyone will ever know. But why this book and why now? **11:02 Derek Fisher:** So, it's kind of interesting because, you know, I had thought about writing this book for a while, for, you know, probably a year before I was approached by Manning, I had started thinking about, hey, In fact, I have notes to prove it, you know, that I had started jotting down stuff saying like, it'd be great if there was an AppSec like desk reference or something like that. And so I had started kind of thinking about it for a while, and Manning had just happened to reach out to me and say, hey, have you thought about writing a book on application security? I was like, yeah, actually I have. And so, you know, there's And this is the way that I've, you know, described it is, you know, we're all— those of us that are in space, we know that there's plenty of material out there. OWASP is a prime example of, you know, where you can go get a wealth of knowledge on web application security. What I think has been missing in the industry is, and again, this is just because I haven't necessarily seen it, it doesn't mean it doesn't exist, so I apologize if it is out there and I just missed it, but You know, what I've kind of haven't seen is what do you do if you're— if you are the leader of an application security function, or not even a leader, but you've been put in charge of developing an application security program within an organization, where do you start? And, you know, I think we could all probably answer that question mentally in our heads and walk through it and say, You know, well, we're going to start by, you know, doing risk analysis, gap analysis, and then we're going to start talking about, you know, with our budget and figure out what we can, you know, roll out. But I think, you know, having something that's been tried and tested and say, okay, here's— here is an experience of, you know, somebody that's gone through this, and here's what, you know, has worked, and here's what doesn't work, and here's why these things, you know, are important. I think that to me was kind of missing because, you know, you look at OWASP and it's very— and absolutely not, you know, discrediting anything OWASP does. I mean, it's absolutely 100% important and I utilize it every day, but, you know, it's here's how you, you know, here's tools, here's maturity models, here's, you know, threat model, Threat Dragon, here's, you know, the top 10. **13:26 Chris Romeo:** Yeah. **13:27 Derek Fisher:** But you still need to piece all that together, right? You still need to understand like, okay, well, here's where I integrate this, here's where I integrate that. And that part I think has been somewhat missing. So— **13:38 Chris Romeo:** Yeah, I agree with you wholeheartedly. I did a talk back at OWASP, the global OWASP in London, oh boy, maybe 4 years ago, 5 years ago. And I just went and stitched together like 10 OWASP projects and did a talk on how you could make a program using these things. But the stitching together didn't exist. And there was no— I didn't go to a project and say, here's how I bring them together. I stitched them together kind of from based on my experience. And so yeah, totally agree with you. Like OWASP is an excellent resource. We love OWASP. But part of what OWASP was missing is the glue amongst all those different things. **14:14 Derek Fisher:** Right? Yeah. And, you know, earlier you mentioned about, you know, it's a labor of love. I— that is, you know, I get asked that question as well. Like, would you ever write another It's like, I don't know. Man, that was— and I remember when Manning approached me and I said, yeah, I could probably do it in 9 months, you know, and get it out the door. And I think after a few days of just really kind of plotting it out, I was like, there's no way I'm gonna do this in 9 months. So I went back and said, yeah, it's gonna be a year. And that was, that was even close. So it's, it's, it's painstaking. **14:48 Robert Hurlbut:** Yeah. **14:49 Derek Fisher:** It's very painstaking. **14:51 Robert Hurlbut:** Yeah. **14:51 Chris Romeo:** But it's, I mean, I think there is value though, right? Like, you've created something now. And to your point, there's just not a lot of guidance out there about, for the— because what I hear a lot of people, this is still a common thing that I hear. Somebody gets hired on and this person is now, you're going to build an AppSec program. Like, literally, that's the— they're a single-person team and that's— they're given that charter. And our industry, it's crazy to think our industry of AppSec has existed for 20-plus years, but there are still the bulk of organizations are saying, You are going to build an AppSec program by yourself. **15:25 Derek Fisher:** Right. **15:26 Chris Romeo:** And that person's sitting there going, um, okay, DAST, SAST. **15:30 Derek Fisher:** Yeah. **15:31 Chris Romeo:** Like, these are the, you know, like these, you know, that, so they need that. So, this is definitely, so what you've written is definitely needed. Like, there's a, there's a need in our industry. And so, let's transition now into kind of diving into AppSec programs. And, you know, when you think at a high level, what is the goal of the AppSec program? What are we trying to achieve with this thing? **15:52 Derek Fisher:** You know, it comes down to balancing risk against the business. And so, you know, the business still needs to deliver value to the customers, right? And application security's position in that is to ensure that that goes out the door with as few risks as possible, right? And that is what the boiled-down strategy is, you know, for application security, at least in my mind. You know, and me, You know, I've done— I've been in engineering. I understand, maybe to a fault, that, you know, there's things have to get out the door. Like, you can't be— and we all know this in the security space— like, you can't be the team of no. And we also can't be the team of, you know, here's a scan report that we ran totally unfiltered, slap it in somebody's face and tell them to go fix it. You know, so I think we you know, as an application security team, our job and our goals should be to ensure that, you know, that the application goes out not with no risk but with identified measured risk that, you know, we can either, you know, assign. You know, if we're going out the door with risk, we acknowledge that there's risk, it has to be assigned, we have protection mechanisms in place to hopefully stop any, you know, exploitation. But, you know, the bottom line is, you know, value needs to go out to the customer. We need to be able to enable that value to go out the door with as little risk as possible. **17:26 Robert Hurlbut:** With that in mind, in thinking about application programs today, is there anything that you would consider to be cutting edge? **17:39 Derek Fisher:** You know, I'll be boring. So, because I think, you know, and I believe I mentioned this in maybe in my book, but I know I've talked about this before. It's like, you know, with when we look at our peer teams in security, like you look at like network security and operations security and cloud security, there's, there's a lot of cutting-edge stuff out there, right? There's, there's, you know, especially when it buzzwords, AI, ML, you know, there's a lot of stuff out there that we can leverage. I think, you know, when it comes down to application security, it's blocking and tackling that I think we're missing. Things like, you know, the basics like visibility, you know, knowing what it is that we have. I think there's some cool stuff when it comes to CI/CD security in the sense that, you know, not just security in the pipeline, but security of the pipeline. I think, you know, there's, there's some cool stuff that's being done there. But one of the biggest challenges with, with development and application security is that if you're in an organization that is of any reasonable size, there's no standard. Nobody, you know, not your entire shop is not designing software on C# running an IIS on-prem. you know, it's going to be a mixture of multi-cloud, you're going to have Java, you're going to have Node, you're going to have C#, you're going to have, you know, all these different languages, you're going to have multiple types of CIs, you're going to have multiple types of CDs. And so there's— it's not as easy for us, and I'm not going the woe is, you know, AppSec type thing, but, you know, it's not as easy for us to say, all right, we're going to deploy this, you know, EDR solution and it's going to work across the board because we know that it's either Linux or Windows that's running, you know, and we're going to be able to, you know, manage this easily. For us in AppSec, it's a little more challenging, but I think, you know, when you look at some of the good work that's being done today, I think, you know, look to the, you know, security of the CI/CD. There's a lot of where at least I'm putting my focus today is, you know, trying to really dive deep on that. Yeah. Yeah. **20:01 Chris Romeo:** And when I think about, you know, across the innovation we've seen in AppSec in the last couple of years, I'm still willing to put RASP in that bucket of cutting edge. And I know it seems odd to put something that was announced and released like 3 or 4 years ago in the cutting-edge bucket, but RASP is still relatively untapped from what I see. And I've been a user of it for 4 or 5 years since it first came out because I saw it, and being someone who loves AppSec, and I'm like, wow, that is the first piece of tech that can legitimately say we don't have false positives because if they can see it, there's no— So what are your thoughts on that, Derek? **20:45 Derek Fisher:** Yeah, definitely. And You know, there's— so to your, you know, to your point, I mean, it's been around for a little bit, right? So, but again, it gets down to protection. So I think when we look at anything that's able to detect and prevent something in real time, absolutely. That's, you know, that's because again, we know that this is the challenge between AppSec and our peers is that If you have an operating system vulnerability, you can blast the patch out across, you know, thousands of hosts within a short period— not a short period of time, but you know what I mean. You can do that rather quickly. With development, it's a little different. You need that runtime protection because you may have a long lead time to get a patch out, so you need— or to get that software remediated. And you're going to need that virtual patching, whether it's through something like a RASP or a WAF or— excuse me— some other, you know, some other type of tool. But I think RASP is something that has been not as, you know, has not been tapped as much as it should be because, you know, in some cases we rely heavily on something like a WAF, you know, that's going to get us, you know, some level of application layer protection. You know, but it's not going to give us that intelligence that RASP does. Yeah. **22:17 Chris Romeo:** And I think part of the challenge is there really hasn't been an open-source player in the world of RASP. And I remember a conversation I had with the project lead for the mod security rule set, the core rule set from OWASP, Christian Fellini. I had a conversation with him years and years ago, and I asked him that question. I said, You know, what about a RASP that came out of, you know, mod_security and, you know, the core rule set kind of, and they had dreams of it, but it's just one of those things that's never come to fruition, probably because it's a lot more complicated than originally thought of, you know, from an open source perspective. But brings me to this question. I want, Derek, I want to get your take on, you know, what is the role of open source versus commercial software? **23:03 Robert Hurlbut:** Yeah. **23:04 Chris Romeo:** in the AppSec program? **23:05 Derek Fisher:** So, you know, I'm of the camp where you, you should be using both. I think it depends on where in like the pipeline that you're leveraging them. I think open source, you know, I— and I'm desperately trying to not use the word shift left because I know that we're, you know, as a, you know, AppSec, we're trying to You know, like, shouldn't just be shift left, we should be shifting, you know, all that other stuff. But anyway, but I think, you know, as you look at the, you know, our traditional method of, you know, shifting left, I think open source tools should play a bigger role far left, right? So if you are, you know, a developer in your IDE, if you can integrate open source tools to try to detect, you know, whether it's, whether you're running a SAST or you're running some type of open-source scanner like DependencyCheck or something like that, and if you have the ability to run maybe some container image scanning open-source, you know, tools, like, there's where you should be running those open-source tools at that, you know, on the left-hand side. As you get, you know, closer to production, that's where I think you need your, your, I'll say, the heavier-hitting tools that are commercial off-the-shelf. that, you know, provides you a little bit more assurance that you're getting your money's worth. So I think there is, you know, benefits to running both. What I would caution though, and this is something that I even struggle with, you know, myself, is that do we need yet another tool? You know, because now you're in the space where you have to manage multiple tools. you need expertise in those tools, you need to be able to pull that data and, you know, aggregate it and dashboard it, all that other good stuff that, you know, can further complicate things. But if you're using an open source tool, you give it to the, you know, put in the hands of the developers and say, hey, you know, if you run these, you know, locally or at least, you know, pre-commit and can get, you know, a sense of your vulnerabilities and hopefully resolve them before you, you know, issue a merge or pull request, then that gets us something, right? And maybe that's something that the AppSec team doesn't have to be responsible for, only making sure that the developers have access to it and are utilizing it correctly. **25:38 Chris Romeo:** Yeah, it kind of brings you to more of a culture of security where developers are using the open source tools, not because it's mandated, not because there's some governance that's happening to say, did you run that scanner? It's because they're catching the value proposition of, if I run this tool before I check the code in, the commercial tools find less things that I have to then go back and issue rework and work my way through. **26:03 Derek Fisher:** Exactly. **26:04 Chris Romeo:** And so, I'm going to jump a little bit out of order here just because you mentioned, you kind of teased out this, one of the things I pulled out from the book, this idea of stop chasing the shiny new tool. So, I thought, let's talk about that a little more depth now because you teased it in that last conversation. So, when you say stop chasing the shiny new tool, like, why give that guidance to those that are running programs? **26:27 Derek Fisher:** You know, I think, and maybe it's just been my experience, but I'm pretty sure that I'm not the only one, but it's, you know, we as an industry, and it's not a security, you know, unique to security, I think it's just we are so enamored by, you know, the new hotness that comes out, and it's like, oh, well, that, you know, and vendors are trained to do that, right? They're— that's what they do. They want to sell you the new, you know, thing and push, you know, and drive, you know, a new tool into the hands of the, you know, the experts. And so I think, The point of that, you know, not chasing that, you know, that new tool is that remember what you have, you know, and remember what value those tools provide. So, you know, just as an example, I mean, a lot of the COTS tools that we use within, you know, our organizations often have capabilities that extend beyond the way we're using them. So if we're, if we're running a DAST tool, you know, chances are there's an SCA component of that, or there may be even SAST components of that. So, you know, and it may not be doing, doing it, you know, as well as buying a special purpose tool specifically for that type of scanning. However, is it really worth dropping, depending on the size of your organization, another $100 grand to bring in a tool to staff up to manage that, when instead you can just switch on something, you know, in a tool that you currently already own, that you already have feeds, you know, for reports, you already have expertise in the organization for, you know, which one's easier? So I think, you know, some of it is, you know, realizing what you currently have and utilizing that, you know, as much as possible. And also there's that early adopter you know, mindset too, where sometimes being the first, you know, to use the brand-new tool isn't always the best thing. You know, you're, you're now the guinea pig. And I've been in situations where, you know, we've, we've, in some of the organizations I've worked in, where we brought in a new tool and we were the guinea pigs, you know, and it's like, you, you've, you asked for like basic features and you're like, why does this tool not do this? **28:57 Chris Romeo:** Right. **28:58 Derek Fisher:** And, you know, the vendor will come back and say, oh, we're working on it. It's like, well, wait a minute, that should be— this should be basics, you know? And so, you know, that could also be a, you know, a challenge. So. **29:09 Chris Romeo:** Yeah, I think about— you mentioned earlier, you know, the DR space, the EDR, MDR, XDR. Let's just make up a new one, JDR. Did you hear about the new JDR tool? No, I have not. You know, it's Joyous Detection and Response. The thing, it sings. a happy song when it finds something. Like, that's a space— like, I swear, like, you know, I spend so much time in AppSec, but like, there's a— like, I probably couldn't do an explanation of all the DR-style tools. Like, right, what's the difference? **29:39 Robert Hurlbut:** Like, I don't know. **29:40 Chris Romeo:** There's like— it just seems like people are coming up with new stuff and throwing it against the wall, and everybody's getting excited about it. And maybe I'm completely off base, but— **29:47 Derek Fisher:** No, but if you— you know, I've been spending some time on, uh, not— I don't know if I should Mentioning Gartner, you know, and reading through some of their material. And, and it's like, man, the acronyms that they throw out there, and it's like, I, you know, I've only heard of half of these. And it's like, and I gotta go look them up. And it's like, oh, well, it's just, it just means this. It's just an extension of that. And it's like, oh, okay. And like, more things for us to, you know, to throw around during meetings where, you know, we can massively confuse people. **30:15 Chris Romeo:** So keep it simple. **30:17 Robert Hurlbut:** Or sound impressive, right? **30:18 Derek Fisher:** Yeah, or sound impressive. Yeah, exactly. **30:19 Robert Hurlbut:** Because I know all these acronyms. **30:21 Derek Fisher:** What do they mean? **30:21 Robert Hurlbut:** I don't know, but I know the acronym. **30:24 Derek Fisher:** Yeah. **30:27 Robert Hurlbut:** Something else you mentioned in your book is this idea of decentralized application security. What does that mean? **30:34 Derek Fisher:** So, I mean, we know this in this space in application security that we can never hire enough people. You know, the way I describe it is my team could be 4 times the size it is today, and I still won't have enough people. So, you know, and it's only going to get worse over time, you know, as engineering functions expand and grow and as new things come in, just not going to be able to hire enough people to do the work that needs to be done. So, you know, how do you manage that? And I think one of the ways to think about it is to decentralize your application security function. And this isn't a new concept. I think when we look at things like whether you call them champions or evangelists or, you know, there's tons of different words for it, but basically being able to deputize people in the engineering space to be security experts. And, you know, that's generally what most organizations will do as an initial step. It's like, okay, well, let's build a champions program and and have individuals within the engineering teams and development teams that are responsible for ensuring that security is in place. I think if we take that a step further and say, okay, well, some of these things that we do, can we make them into services that can be called by the development teams in their CI/CD? For instance, you know, can we create fuzz testing that is developed by the application security team that follows the standards and guidelines by, you know, that are set forth by the application security team that, you know, align with the organizational goals and turn that into an API that can be called during the CI/CD or turn into a runner or some type of job that can be called during the CI/CD that, you know, can then provide a test. And therefore your AppSec team doesn't need to have a a ticket open to them to say, you know, I mean, fuzz testing may not be a great example because a developer can go do that on their own, but, you know, let's say, you know, an automated penetration test or something like that. You know, those services, I think we can, we can create APIs or services of those tasks, and that allows you to again push the work to the development teams to be able to call those, integrate them into their pipeline, get the results as early as possible, remediate, and, you know, rinse, repeat. And the AppSec team can then focus on maybe the bigger ticket items, doing things like threat models, risk assessments, doing the design and architecture reviews, building security requirements, those types of tasks that require a little bit more thought power as opposed to doing the, you know, the manual stuff. Again, like engineering teams, development teams, they hate manual work, right? Anything that requires, you know, manual repetitive motion are going to get automated at some point. And I think, you know, application security teams should take the similar approach. **33:52 Chris Romeo:** And so you also, you know, you kind of mentioned this a little bit in that explanation, but in the book I saw you referred to application security as a service. And so you use this term enablement instead of gates. And so I want to unpack that a little bit. What do you mean when you say enablement instead of gates? **34:13 Derek Fisher:** Yeah, we, you know, we have other words for that, whether it's paved road or golden road or guardrails. But where we should be striving as an industry, as an application security industry, is that we should be providing the, the enablement in the sense that developers shouldn't be worried that their code is going out with vulnerabilities. They should be worried that their code is going out to deliver the features that the client wants. And so it's up to us to ensure that that roadway, you know, that roadway to production is built in such a way that they understand what vulnerabilities may be impacting the code that they wrote, that they're able to remediate that as soon as possible before it goes out into production. So I think, you know, the way I, I look at this is the same way that developers run unit tests, regression tests. Like, those things are, you know, we, we shouldn't really distinguish security tests from, you know, regression testing. In fact, security tests should be part of regression testing. And same thing with building abuse case, misuse cases as unit tests that can be run, you know, in the development environment. And all those, all those, you know, methods come together to be able to provide the developer the— reaching for a word here, but, you know, the assurance that they're going to be able to get that out into production with without worrying about the security of it. We don't necessarily want, you know, we want the developers to be aware of security and have a security mindset, but we don't want them to be spending their time doing, you know, security vulnerability remediation, right? That's not where they want to spend their time. That's not where, you know, the business wants them to spend their time. They want them to spend their time, you know, delivering value. It's on us to make sure that that Yeah, that's helpful. **36:19 Chris Romeo:** That's helpful to get that kind of philosophical understanding because once again, we're trying to help people that are building programs and a lot of these folks are going to be relatively new to building programs. And so, it's important for them to understand the philosophies that you've experienced over time and then you've been able to quantify those in the book so that new people can take those philosophies and maybe they don't understand all of the details about how we got there in the beginning, but it's principles that they can apply to their programs to be successful. **36:51 Derek Fisher:** Yeah. And one, you know, just one little extra color there is that, you know, we as a security in general is seen as no, and maybe not so much anymore, but that was definitely the feeling, you know, 5, 10 years ago was that we were the people that would come in and, you know, spoil everyone's party. And I think that that is not, you know, I kind of go back to saying what I said earlier about risk, right? We, our job is to limit the risk. If we can eliminate it, great. We're not going to get there. There's always going to be a risk when, you know, software goes out the door. Our job is to try to identify and assign and, and, you know, ensure that we reduce that risk as, as much as possible. And that's the same, you know, mindset when we have enablement versus gates. So instead of saying you can't go out the door with any risk, you know, that's, that's just not possible, right? And that's just gonna, that's gonna just bog the system down. Whereas saying, look, here's how we manage the risk, here's how we're gonna reduce the risk. You can still, um, you know, deploy, uh, but, you know, we need to make sure that we have the risk quantified, um, and, uh, properly, you know, assigned and, and controls in place. **38:15 Chris Romeo:** Yeah, no, that's helpful, helpful to have that perspective. Like, it's easy for us as AppSec people to say, well, we're— you're just going to fix everything, right? But that's, that's like to— I mean, one of the earliest things you said when you were talking about the goal of AppSec programs, it's It's really to enable the business. And that's the part that I see a lot of technologists, they can almost never make that leap into understanding. And I think the only reason that I have a deeper appreciation for that is, you know, starting a startup and running a business through the whole thing where you start to see things, well, wait, there's a business side to this problem. **38:53 Derek Fisher:** Yep. **38:53 Chris Romeo:** It's not just about the beauty or the excellence of technical fixes or issues or architectures, I have to measure that against or weigh that against the business and say, sometimes I just have to say, I'm going to have to accept that risk for a period of time, right? Because I got to run the business, right? And that's, that can be a struggle for technologists who don't, don't ever gain that appreciation, right? **39:19 Derek Fisher:** Yeah, absolutely. **39:21 Chris Romeo:** So my, I'm going to go first with a key takeaway here. And so I'm going to take you know, the one that Derek might share, but that'll give him room to do another one because I'm a fan of this book. And the book is Application Security Program Handbook. And this is, as Derek mentioned, it's from Manning Publishing, the folks that put this out. And so, my key takeaway to our audience, or my call to action, is get a copy of this book and check it out, read it, and look at— there's a lot of powerful things in here you can absorb and apply to a new program or a program that's been around for a long time. Derek, how about you? What's your key takeaway or call to action for our audience coming out of this conversation? **40:01 Derek Fisher:** Yeah, you know, I always come back to, you know, like I said earlier, I don't think that we can ever have enough application security personnel out there. You know, it's just, it's not possible for us to do. So I think, you know, my kind of goal and what I've been doing over the past several years is just trying to evangelize as much as possible around, you know, security and make sure that people are aware of Just basic risk. And I think, you know, we do this on a daily basis, not even in the technology space, but we do this as humans. You know, we, you know, we identify risk and we, you know, understand, you know, what our risk is. And I think, you know, those types of activities, just, it's a matter of trying to share that information and share that knowledge with as many people as possible. And I think that's something that as AppSec professionals and as security professionals, it's on us to make sure that we are trying to bring that to as many people as possible. **41:03 Chris Romeo:** Definitely. Well, Derek, thank you for sharing your experiences and telling us about the book. And yeah, I mean, it's been excellent just to gain some more knowledge and understanding about where you're coming from as you're writing this. You know, maybe we'll encourage some other people to write books coming out of this too. **41:23 Derek Fisher:** Yeah, absolutely. You know, the more, more the merrier and the more we can share, the better. So, definitely. Thanks, Derek. All right. Thank you. --- Source: https://appsecpodcast.com/derek-fisher-the-application-security-handbook/