Relating to DevSecOps Podcast Por Ken Toler and Mike McCabe capa

Relating to DevSecOps

Relating to DevSecOps

De: Ken Toler and Mike McCabe
Ouça grátis

Sobre este título

A Podcast dedicated to forging iron clad relationships between developers, engineers, operations, and security practitioners by discussing hot topics in the world of DevSecOps. This podcast aims to air out some of the common gripes, misconceptions, and hardships that these teams face in the real world every day.© 2025 Relating to DevSecOps Economia Sucesso na Carreira
Episódios
  • Episode #080: Patch Me If You Can: Compliance, SLAs, and Other Fairytales
    Aug 25 2025

    Send us a text

    In this no-punches-pulled return from hiatus, Ken and Mike dig deep into the messy middle of vulnerability management, SLA fatigue, and the illusion of compliance. Are we building secure systems or just passing audits? From legacy cruft to exploitable CVEs, this episode unpacks the real-world pressures of SOC 2, the auditor dance, and whether fixing every “critical” is even feasible.

    Perfect for practitioners trying to balance the checkbox culture with actual risk reduction, this one’s got stories, strategies, and spicy takes. Bonus: tips on managing auditors without losing your mind—or your security posture.

    Exibir mais Exibir menos
    34 minutos
  • Episode 079: CISOver It: When Dashboards Replace Direction
    Jun 10 2025

    Send us a text

    In this episode of Relating to DevSecOps, Ken and Mike discuss the challenges faced by CISOs in today's security landscape, particularly the struggle to balance immediate security needs with long-term preventative strategies. They explore the disconnect between security leadership and practitioners, the urgency of addressing security issues, and the importance of understanding the root causes of vulnerabilities. The conversation emphasizes the need for CISOs to engage more deeply with their teams and to focus on effective, context-driven security solutions rather than simply reacting to the latest threats.

    Exibir mais Exibir menos
    37 minutos
  • Episode #078: 🔥 Burn Your 30-page Policies: Tanya’s Got Better Ideas
    Apr 22 2025

    Send us a text

    In this must-listen episode of Relating to DevSecOps, Ken welcomes the ever-inspiring Tanya Janca, aka SheHacksPurple—author, AppSec expert, and champion of making security usable. Together, they dig into why so many application security policies fail, why developers ignore them, and how to make them actually work. Tanya shares real-world experiences from both dev and security perspectives, plus her journey from being ignored to lobbying governments for change.

    From communication failures and TL;DR policy pages to leveraging wikis and code reuse, this episode is a practical masterclass in creating impactful, developer-friendly security standards.

    Exibir mais Exibir menos
    47 minutos
Ainda não há avaliações