--- title: "Eran Kinsbruner -- DevSecOps Continuous Testing" url: https://appsecpodcast.com/eran-kinsbruner-devsecops-continuous-testing/ date: 2021-08-20 duration_seconds: 2143 guests: ["Eran Kinsbruner"] topics: ["Security Testing", "DevSecOps and CI/CD", "Privacy and Compliance"] audio: https://www.buzzsprout.com/1730684/episodes/9020926-eran-kinsbruner-devsecops-continuous-testing.mp3 video: https://www.youtube.com/watch?v=SpSzx5m7NLY transcript: true --- # Eran Kinsbruner -- DevSecOps Continuous Testing *August 20, 2021 · 36 min* with [Eran Kinsbruner](https://appsecpodcast.com/guests/eran-kinsbruner/) on [Security Testing](https://appsecpodcast.com/topics/security-testing/), [DevSecOps and CI/CD](https://appsecpodcast.com/topics/devsecops/), [Privacy and Compliance](https://appsecpodcast.com/topics/privacy-and-compliance/) [Audio](https://www.buzzsprout.com/1730684/episodes/9020926-eran-kinsbruner-devsecops-continuous-testing.mp3) · [Video](https://www.youtube.com/watch?v=SpSzx5m7NLY) ## Show notes Mark Loveless - aka Simple Nomad - is a security researcher and hacker. He's spoken at numerous security and hacker conferences worldwide, including Blackhat, DEF CON, ShmooCon, and RSA. He's been quoted in the press including CNN, Washington Post, and the New York Times. Mark joins us to discuss his series of blog posts on Threat Modeling at GitLab. We discuss his philosophical approach, framework choice (spoiler alert, it's a pared-down version of PASTA), and success stories / best practices he's seen for threat modeling success. We hope you enjoy this conversation with... Aaron Kinsbruner is the Chief Evangelist and Senior Director at Perforce Software. The Application Security Podcast is brought to you by [Security Journey](https://www.securityjourney.com/). About Security Journey Aaron Kinsbruner is the Chief Evangelist and Senior Director at Perforce Software. → [Learn more about Security Journey](https://www.securityjourney.com/) Connect with Eran Kinsbruner: → [Perforce Software](https://www.perforce.com/) → [Jenkins](https://www.jenkins.io/) Mentioned in this episode: → [Perforce Software](https://www.perforce.com/) → [Jenkins](https://www.jenkins.io/) → [Alyssa Miller](https://twitter.com/AlyssaM_InfoSec) Chapters: 00:00 Meet Eran Kinsbruner: DevSecOps Continuous Testing 03:00 Okay. So in your time focusing on DevOps and DevSecOps before 04:46 As we get into testing or talk about testing, before we 07:19 One of the, one of the comments, or one of the 16:30 As I'm listening to the way you're describing quality gates and 21:19 Eran, you mentioned the word quality. a few times. And, you 24:37 I got a follow-up question related to quality. And so this 27:04 I think we're both on board with the idea that quality 31:26 Yeah, definitely. And I think you covered people in the last 33:01 Definitely. Eran, it's been great to talk to you today. I ## Transcript *5,509 words · assemblyai* **0:02 Chris Romeo:** Aaron Kinsbruner is the Chief Evangelist and Senior Director at Perforce Software. His published books include the 2016 Amazon bestseller, The Digital Quality Handbook, Continuous Testing for DevOps Professionals, and Accelerating Software Quality: ML and AI in the Age of DevOps. Aaron is a recognized influencer on continuous testing and DevOps thought leadership. He's also an international speaker and blogger. Aaron joins us to talk about the role of testing in a secure software pipeline. We talk about the intersection of security and quality, some of the biggest challenges that he's seen in getting started with testing and DevSecOps, and even a brief conversation about how static analysis is used to check automotive software. We hope you enjoy this conversation with Aaron Kinsbruner. Are you trying to build a security champions program? Everyone is these days. One challenge of rolling out security champions is, how do we educate all these new folks? Security Journey has your answer. We provide a security dojo environment with level-based security education that gives your newfound champions a path to follow. And the best part? It requires almost zero administration by you. Visit www.securityjourney.com to set up a demo and learn how you can use the Security Dojo to connect with your security champions. Today we're going to talk about testing, something that I feel like is neglected a lot of times in the conversations we have in security. But first, let me introduce our guest and we will jump right into his security origin story. Today we're joined by Aaron Kinsbruner. And he has written a number of books and done a lot of thinking and speaking about this idea of testing and the intersection with DevSecOps. But Eran, first, our audience demands that we ask, what is your security origin story? How did you get involved in the world of security? **2:08 Eran Kinsbruner:** It's very easy. I've been in, you know, DevOps, DevSecOps for almost 21 years now. Specifically with security, since I work for Perforce, Perforce owns a product for SAST, for static code analysis called Clockwork, as well as QAC. And we actually serve different industry verticals for the past few years, actually many years, around static code analysis for code written in Java, in C, C#, C++, recently added JavaScript. So as the market evolves, segments evolve, we are seeing so many threats, not just to security, by the way. Security is obviously a huge concern, but also safety and compliance with this kind of stuff and adhering to coding standards. So that's currently what I'm focused on. **3:00 Chris Romeo:** Okay. So in your time focusing on DevOps and DevSecOps before you got to Perforce, was there a particular moment in your career where you were like, I'm now transitioned into security, or did that happen when you got to Perforce, or what was that moment? And tell us some details about that. **3:21 Eran Kinsbruner:** So, I would say it definitely became my reality when I transitioned to Perforce several years ago. But I see security like many other, by the way, practices. You know, people will talk about performance and accessibility, right, which are not security. But these are kind of things which typically either are not well treated or neglected. Everyone talks about, you know, shifting left security, right? Doing more security testing and validation earlier in the dev cycle, right? Developers need to own security. But we see that as part of code design and stuff like that, these things are still not very well, uh, managed. Some of the reasons are, you know, lack of automation, the ability to automate the process of security, uh, validation as part of, you know, coding. And, you know, every pull request you also consider and think about what it means for— from a security standpoint. So, uh, yeah, I obviously, uh, became more and more involved as part of my role at Perforce, uh, but I think this is you know, one of a few other, I would say, non-functional aspects of development, of software development, which needs to be better addressed, automated, and shifted left as part of the development lifecycle. **4:46 Robert Hurlbut:** So as we get into testing or talk about testing, before we get into that, let's talk about SAST and in particular certain markets. We've talked For example, automotive and all the vehicles that we have now, electric or autonomous vehicles that may drive themselves and that sort of thing. What kind of role does SaaS have in those types of environments? **5:14 Eran Kinsbruner:** So huge role. And I think when you talk about security, people think about, you know, the business implications. But when you apply security as part of, you know, in the vertical of autonomous car in automotive, You know, and these are connected cars. It's all connected to the internet and stuff like that. So it's actually also life-threatening things. So security usually goes in the aspect of business implications and brand damage. It's this specific vertical can actually impact our lives. So it actually has implications on real lives here. So I'm actually happy but a bit concerned as well, uh, with few new standards and regulations coming to this automotive thing, such as ISO, uh, 21448 and ISO 21434 around safety and security in the automotive space, electric and autonomous cars. But I think this is not enough. I think we need to, uh, you know, and Perforce sits in different boards, in compliance boards around security you know, MISRA and AutoSAR and these kind of ISO compliance that are being formatted as we speak. I think we need to think a bit more, not just on the financial aspect, but also on the safety. When— by the way, safety can be a threat coming from security, right? Because this— and I spoke— actually, we just released as part of Perforce a huge automotive survey. Yeah. Around security and safety. And one of the key responses that we got from that is that these automotive vendors are concerned about unauthorized access to systems within the cars. Okay, everything is infotainment systems and stuff like that, which are connected to the internet and are exposed to security and cyber attacks. So yeah, I think it's very, very related to this new and emerging markets. **7:19 Chris Romeo:** And one of the, one of the comments, or one of the, the things that we discussed in advance, was about the role of SaaS. And so I'm curious, from your perspective, when you think about like automotive, like when I think SaaS, I think web applications, I think mobile applications, I think things that are more standard to software development and delivery. But when you're talking about a car, it's not I mean, maybe cars are filled with web apps and I just don't— maybe I'm out of the loop. But how does SaaS fit in? How do you run a SaaS tool against a car? **7:52 Eran Kinsbruner:** So that's a great question. And by the way, cars also have, you know, all these mobile-like systems, right? Apple CarPlay and Android Auto, which are systems that allows you— by the way, this is some of the loopholes that you have because this set of boxes that sit inside the car has tons of technology inside, and they connect via Bluetooth to our smartphones, which are also exposed to security and other attacks. So, uh, I think, uh, the way our customers are doing SaaS, obviously, uh, a lot of simulation of things working on the set of boxes in isolated environments. And think about it, uh, these software, uh, builds are not, uh, with like a few hundred lines of code. We're talking about millions of lines of code that we need to, uh, analyze as part of this SAST process. And, uh, what we see, especially within Perforce, is, uh, that these, uh, vendors, you know, Audi and BMW and, and the likes, are leveraging what we call incremental analysis, okay, differential analysis. They are able Because, you know, you cannot really analyze these millions of lines of code per each build, per each code commit or pull request. You need a system that can analyze all the subsets of code that was changed from one code, you know, check-in to the next or whatever. So this incremental analysis is one way of these vendors to deal with all these incremental changes that are happening and actually segment their entire software into pieces and by that kind of own and control things. But with that in mind, they are still not able to automate everything that they can. And that's one of the concerns in this space because as they are innovating and doing more changes and mostly like C and C#, these are the languages that we are dealing with. You know, when you talk about mobile and web, you think about the Java, the JavaScript, and the Python of the world. When you're dealing with automotive, it's mostly C and C#. These are the main languages, and, uh, it's hard to analyze these lines of code, especially in huge code bases with dependencies and with connection to mobile and set-top boxes and stuff like that. So again, incremental analysis is one way of these, uh, vendors to cope with the complexity. Automating Uh, you know, again and again using machine learning. Okay, we have seen machine learning in automotive, especially in, uh, root cause classification, because when you are running SAST, you are getting blown by so many, uh, you know, issues and sometimes, uh, you know, violations of, uh, compliance regulations and stuff like that. How do you find really the issues that really care, which are going to bite you, right? So security, safety, uh, threats, you might fail an audit, right? These guys need to, uh, present an audit report upon each, uh, release of their software, okay? So they need to really find the needle in a haystack, and that's very hard. So differentiating is quality dashboard. Uh, sometimes they're doing some risk assessment, and they're not guessing because you cannot guess with, uh, real life here, but They're really building prioritization dashboards through machine learning. Some of it comes from Perforce, some of it they have their own systems, but they're slicing and dicing a lot of the quality data coming from SaaS to make judge decision, data-driven decisions. And that's how they move. **11:40 Chris Romeo:** Yeah, I guess that makes a lot of sense. And you've helped me to refresh my understanding of the architecture inside like a modern automobile. I hadn't thought of it as just like, hey, there's a set-top box, equivalent of a set-top box sitting inside the car, which is delivering the infotainment experience. But putting in that perspective, I've studied and thought a lot about the threats that go after the cable system and the set-top boxes and stuff. And then you connected it back to mobile. Yeah. I mean, these systems are just extensions of our Apple or Android-based phone that's connected into this. And then you've got the whole safety systems, which sit kind of on the other side. But it's good to know that they're all written in C. A lot of it's written in C and C#, and that's code that we can run SAST against. So, I could probably talk about and ask you a million questions about security in automobiles today, but we want to talk about testing. That's what we advertise as far as this conversation goes. So, I want to transition into that direction. And so, When I think about DevSecOps, I'm using the term secure software pipelines. That's the term that I'm using to describe what's happening in DevSecOps. And so right from the beginning, I want you to, Eran, if you can set the stage for us about what is the role of test in a secure software pipeline. **13:03 Eran Kinsbruner:** So that's a great question. And by the way, once I speak to that, also think about, you know, these automotive vendors have development teams that are very much spread. You know, you don't have, especially today in the COVID times, you don't have a team that actually sits together. You have testing teams that sometimes is remote, even dev teams that are separated into, you know, different units. And how you make all of this process, to your question, work together requires a lot of synchronization. Obviously good management and systems and tools and working based on requirements. But to your point, I think that what I've seen in our space, especially with SaaS and security and testing in general, is using good quality gates in between each teams. Okay? I can tell you that one of our clients, you know, does not even— the testing team does not even start looking at a build, at a software build, whether it's an automotive uh, you know, build or, uh, other, other, uh, segment that provides the software, you know, from the chipset manufacturers before they see a compliance report. Okay, they run the SAST upon, uh, you know, each code changes and they get a report. Without this report that shows, you know, the basic, uh, flows covered and, uh, green as much as possible— and these teams are using obviously CI/CD tools like Jenkins and other continuous integration tools, but they produce at the end of this initial build some kind of a build acceptance test report that also includes the SAST, includes the security and the safety and stuff like that. That's kind of the trigger for the testing team to get it and start doing functional and regression and non-functional and other testing to really validate the build. So I think that the successful teams that I'm working with are working based on quality gates. And they really are very— you need to be strict. The timelines are quite short. Everyone complains. We don't have time for quality. We don't have time for security. We have just a 2-week or 3-week sprint. In the automotive, it's a bit bigger than that. But time is time. Yeah. And without, uh, uh, process, without these quality gates, you know, and the handoffs— even though you, you think about handoffs as a waterfall, no, handoffs are just quality gates in between the DevSecOps process that guides the next team so they can really, uh, you know, test with confidence. Because you can get a build and hand it over to testing and they will do the stuff, but Lack of confidence, lack of validation that happens beforehand is a huge risk to the end process. So again, I will repeat it: quality gates, looking at audit reports that are, by the way, integrated. SAST is integrated into CI, so there is no excuse. Yeah, it was too much manual work. I couldn't integrate it into my DevOps pipeline. It's very easy to integrate security and shift it into the build process. So the next phase of validations prior to really releasing something to the next level into production should be automated as much as possible. So that's how I see it. **16:28 Robert Hurlbut:** So in the— **16:30 Chris Romeo:** as I'm listening to the way you're describing quality gates and testing, not picking up a particular build until after certain checkpoints and things that are happening, it's making me wonder, like, How fast is this in the process that you're laying out here? Because one of the things that I think is encouraging and exciting for people when they start to move towards a DevOps world is, hey, I can push 50 builds a day, right? I can push, and that's, I'm thinking from a mobile app, web app perspective where we're hitting the gas pedal all the time and we can't have a manual step, for example. Like there can't be a quality gate where there's a person or a group of people that stand in the way of the build. And so, Sounds like you, you're kind of coming from a slightly different perspective, so I'd love if you can just kind of fill in some context around that about how is the, the, the description that you've given so far, how does that maintain the speed and the velocity that DevOps is known for? **17:30 Eran Kinsbruner:** Oh, that, that, that's a great point, Chris. And, uh, you know, especially, and I also serve mobile and web testing, and, uh, to your point, yes, these guys can move much faster than you know, an automotive vendor or a chipset manufacturer because they deal with a smaller code size, right? The gap that they need to validate is much smaller. When you deal with an automotive, and by the way, automotive are also emerging and they are practising DevOps and agile development, but the way they are doing it, and that's based on my experience with my clients in the automotive space, they do test-driven development. Okay, test-driven development is not something that is just for mobile and web. Uh, these guys are using it, and especially when you write the test before you write the code and this kind of, you know, TDD, BDD, uh, and sometimes actually they are using, uh, automated code generation tools as well. So they have ways to expedite the coding and the software development process through TDD and code development and model-driven development, which is also something these guys are using. You know, they're modeling the application and by that kind of abstracting different layers of the application that serves the agility. But this does not, uh, cover all the testing stuff. It just brings them to the testing phase a bit faster. Okay, they can identify issues, violations, uh, security vulnerabilities much faster by doing these agile processes, adopting agile processes. So, uh, to your point, yes, there are a lot of things in common between, you know, mobile and web and the digital apps and the more heavier code bases. And the common thing is the way that you adopt agile processes to model-driven development, uh, automated code generation, and test-driven development. **19:22 Chris Romeo:** Yeah, that makes sense. Then when you start to think about how DevOps integrates and DevSecOps with the different verticals, mobile, web, people that are working with those type of technologies are going to move fast. But like automotive, you start to think about like, what's the threat model of a car, you know, an autonomous car, even just a modern car that has all the infotainment systems and things in them. There are people in these automobiles driving down the street right now at this moment. And so, there's a safety angle which causes us to be More, more on edge, I guess, about— so I could see how, like, from an automotive perspective, there would be— you still want to do DevOps, but you're going to do it in a slower cadence because the potential for danger and damage is so much higher. We're talking about if there was a vulnerability in a piece of car software, people could crash into things, people could die. Whereas mobile apps, web apps, you could say the stakes are lower. It feels weird to say that the stakes are lower, they're not as high, but I think that's really what you're saying. Yeah. **20:30 Eran Kinsbruner:** Yeah, you know, uh, not being able to load a new level in my mobile gaming application, uh, wouldn't result in any, you know, uh, severe thing other than frustration by the end user. **20:40 Robert Hurlbut:** Yeah. **20:41 Eran Kinsbruner:** Uh, while, you know, autonomous, uh, and, uh, electric vehicles, which kind of, uh, exposes, uh, the user, the driver, even though, uh, it's selfless, uh, car, uh, to safety and, uh, other, uh, life-threatening risks. Obviously is a huge concern. And this is why these vendors are mixing, are mixing, you know, the safety, security concerns together with edge. So they are trying to move faster while also making sure that they're not kind of compromising these very important considerations. **21:18 Robert Hurlbut:** Eran, you mentioned the word quality. a few times. And, you know, quality is something that we've thought about, and it's really important to a number of us over the— over years in lots of industries. And of course, software is another thing we look at as well. But in DevSecOps, what is the role of quality? And then also, how can we enhance quality or improve quality, whatever may be there? So maybe could you talk on those couple things there? **21:52 Eran Kinsbruner:** Of course, of course. Quality is very, very close to my heart. I've been involved in quality for over 21 years now, and I think that I've seen a major shift in the importance of quality to developers actually over the past few years, you know, with the terms of DevSecOps. Test-driven development is a dev focused method, but it's quality-oriented, you know, developers trying to find defects earlier across the pipeline. You know, as soon as they write the line of code, they actually already know what it's going to actually cause from a quality perspective. I think that with the excitement in mind, quality requires huge investment. Quality, if it's not automated, you know, you don't have the DevSecOps, uh, coin in mind because Automation drives velocity. And today, to ensure that quality is being met across each code change— and there are always risks, you're taking a lot of risk when you're doing software development, we know that— but quality, especially in, you know, in regulated industries, in automotive, aerospace, by the way, and defense as well, which is obviously error-prone and very dangerous when you do safety mistakes or security issues, you need to— and I hate the term shift left. I know that everyone is using that, but I would not— I won't say shift left. I would say automate and enable developers to own quality because I think that there are already blurred lines between testers and developers. **23:33 Robert Hurlbut:** Okay. **23:34 Eran Kinsbruner:** you know, my role and my paycheck. At the end of the day, you are delivering software which gives purpose, gives value to the end users, and the end users expect software to work, to not harm their safety or lives, and obviously don't compromise, you know, security and their privacy, okay? By the way, just this week as we are speaking, Google, that comes from the mobile space, are mandating each mobile application, not just games, any mobile-related application being shipped to the Google Play starting January 2022 must come with a privacy policy, and they are hitting hard on security there. So we need this quality to be automated and be owned by both developers, DevOps engineers, and QA engineers. And to do so, everyone needs to be aware of the importance of that and take part of that. Everyone based on his obviously capabilities and abilities and tools that he has. **24:37 Chris Romeo:** So I got a follow-up question related to quality. And so this I think is one of the age-old debates. I've heard this debate going on for 20 years. So I'm curious, Aaron, to what your perspective is. Can you have security without quality? I've heard people argue this for a long time, and I'm curious to see what's your answer. Can I have security without quality? **25:05 Eran Kinsbruner:** I would risk and say you can't. I think that all the TY at the end, security, accessibility, quality, these kind of things, at the end of the day, if you take some piece out of your software, you add the limitation to your software, It reduces the quality of the software, right? If someone considers your application, your car, as insecure, it's obviously, it's bad reputation. And you say, okay, that's not high quality. You know, you don't want to buy something that has a negative implication. A product which is not secure has negative implication, and that's quality at the end of the day. So quality, user experience, security, accessibility for everyone, right? These kind of things are all in my mind under the umbrella of quality. And security is one of the top, top of mind these days because we hear almost every week, every day, you know, I have friends from Cyber Reason. I'm based in Boston, so Cyber Reason and CyberArk are good friends of mine, and they keep talking about, you know, their, uh, daily experiences, what they experience. Working with Perforce with the Clockwork product and QAC, we see so many clients coming to us because they are concerned about security, but they see security again as part of their quality assurance. I spoke recently with IDC and they have a term, application security testing, okay? AST. AST is their, you know, Kind of like a Forrester Wave, right? IDC looks at AST as their Wave report for quality and security. They look at them at the same level. So I would say yes. **26:57 Chris Romeo:** Interesting. **26:58 Eran Kinsbruner:** Security and quality are together. **26:59 Chris Romeo:** Yeah, I don't think you're going to get any debate, at least from me. I don't know, Robert, are you? **27:03 Robert Hurlbut:** No, not at all. **27:04 Chris Romeo:** I think we're both on board with the idea that quality and security are very much intermingled and you can't have one without the other. You can't say this is secure, but the quality is terrible because if the quality's terrible, vulnerabilities there somewhere that somebody will find. So, I want to kind of, as our final question before we get to key takeaways, I want to understand what do you think are some of the biggest challenges when getting started with testing in a DevSecOps pipeline? Because we want to empower and help our listeners that may be sitting out there saying, hey, we're new to DevOps, we're trying to figure out how this security thing fits in. What are some of the challenges that you've seen with integrating test into DevOps? And then also, what are the solutions right alongside? Tell them the solutions at the same time. **27:53 Eran Kinsbruner:** Of course. And I think you gave me a clue to my answer because when you say integrate, I think the key for success, but also the challenge is when quality and testing are not embedded into the process, into the software development process. If testing breaks the process or kind of causes changes to the process of developers, people won't do it enough. Okay, testing needs to be automated. It needs to be integrated into the pipeline. When you're doing a pull request, something Jenkins, Bitrise, whatever CI/CD tools that are out there today, Bitbucket, needs to ignite a process of testing of quality security, functionality, non-functional testing, uh, whatever testing that fits your segment. If that doesn't work, obviously people won't consume and won't do the testing. So the challenge in my mind, the first one, is making sure that you bake quality into the process of software development. Second is the tools and the matching of the tools to the skill set. Sometimes, and I hear it too often, organization leaders, you know, that are not always the most technical guys are enforcing tools that simply are not well matched to the team skill set. Okay, you have strong C# developers and you are giving them a good JavaScript tool. That's not a good match. So these guys need to feel confident with the tools that they are asked to use as part of their test development activities. And the third one is obviously automate, automate, and maintain. Treat testing as code. Okay, you write tests, you know, I mentioned earlier C and C# for the automotive space. You write your test cases also in C and C#, whether you are using an internal testing framework or you are using an open source framework, it doesn't matter. It needs to be maintained because changes happen to development, to the code. Changes are also impacting the stability and the flakiness of your test code as well, security tests as well. So you need to continuously maintain, and that's one of the hardest challenges because, yeah, you build the test case, it runs on the, on the first build. Guess what? The next version of the code, the tests are breaking, are breaking because you didn't maintain them. So treating tests as code is again a solution but also a challenge in today's world. **30:26 Chris Romeo:** Mm-hmm. **30:27 Eran Kinsbruner:** And last, again, there are obviously many other challenges, but I think one of the biggest ones that especially is growing and you see a lot of machine learning and AI that are coming to the rescue is the size of code, the data. Okay. How do you make sense out of the data, test data, production data, secure data, issues and vulnerabilities that you get from these different build types that you are doing? So having the ability to slice and dice data, again, it doesn't matter if it's from development, from production, security, functional testing, regardless, you need to have the dashboards and the ability to make sense out of these data points so you are better suited to do the next regression cycle, to do the next iteration, but it's based on data and not just guesswork. So I think I mixed my response with both the challenges but also some of the tips that I would, you know, give to practitioners. **31:25 Chris Romeo:** Yeah, definitely. And I think you covered people in the last answer. You covered process and how testing has to be involved in as part of the software development process. You talked about tools. Alyssa Miller, on an earlier interview, challenged us and has changed my thinking about the people, process, tools. approach, she added governance on the end. So I'm curious, are there any challenges that you've seen from a governance perspective in regards to testing in a DevSecOps world? **31:55 Eran Kinsbruner:** Yes, I think governance can mean many things, but, you know, in our security thing, okay, so when do I switch to a new regulation? What do I pick from these types of compliances? Because, you know, you have CWE, you have OWASP Top 10, You have MISA, you have AUTOSAR, you have different ISO. So obviously doing quality and doing testing is important, but where do I start? What's my threshold, you know, to decide, okay, this is good enough to go? It's outside of the people, process, tools, or technology, okay? It's governance, it's more process-oriented, it's risk management related. So, and again, we talked about safety and, you know, different technologies which have much more implications to life and stuff like that. But I think, yeah, governance, and especially in the term of security, is very, very important. So we were probably challenged correctly by her. I agree, that's very important. **33:00 Robert Hurlbut:** Definitely. Eran, it's been great to talk to you today. I know we've talked a lot about things that teams can do and listeners can do, but are there any other key takeaways or a call to action that maybe you want to leave with listeners? Just to wrap this up today? **33:17 Eran Kinsbruner:** Yes, I think we covered a lot of ground today. I think that everyone who is listening to this podcast needs to understand that, and probably they know it already, the market continuously changes, evolves with AI, machine learning, big data, SaaS, new security regulations, new threats coming from different markets and segments. I think awareness has become the most important thing in my mind, being connected to the communities because you can learn so much things that are surrounding you. We are too occupied. We are developers and practitioners. We are too occupied in our daily lives dealing with our daily tasks. Sometimes we forget what's happening around us. Understanding what's coming next and sometimes actually taking action, with these kind of opportunities and being ready or being prepared to the next wave of technology, you know, not being afraid of, but being ready is very, very important. So we talked about so many things. I would just add to that, be aware, understand what's coming next, make sure that your technology, your people, you know, process and technology stack are all ready for the future, for the next wave of innovation. will definitely get you there. You might get some action immediately. You might put, you know, in the next quarter some action items of research, but continuously evolve and innovate because the market is doing so regardless of you sitting and writing your own lines of code. Excellent. **34:55 Robert Hurlbut:** So what I heard, great advice: be aware, be ready, evolve, and innovate. Excellent. Really appreciate it. Thank you again, Eran, for joining us today. Really appreciate it. **35:07 Eran Kinsbruner:** It was my pleasure. Thank you so much for having me. **35:09 Chris Romeo:** Thanks for listening to the Application Security Podcast. You'll find the show on Twitter @AppSecPodcast and on the web at www.securityjourney.com/resources/podcast. You can also find Chris on Twitter @edgeroute and Robert @RobertHurlbut. Remember, with application security, there are many paths but only one destination. --- Source: https://appsecpodcast.com/eran-kinsbruner-devsecops-continuous-testing/