Home
Categories
EXPLORE
True Crime
Comedy
Society & Culture
Business
Sports
Technology
Health & Fitness
About Us
Contact Us
Copyright
© 2024 PodJoint
Podjoint Logo
US
00:00 / 00:00
Sign in

or

Don't have an account?
Sign up
Forgot password
https://is1-ssl.mzstatic.com/image/thumb/Podcasts211/v4/ab/b0/da/abb0dac0-046c-0dcf-9ed2-3608f7da6605/mza_7681932657336190582.jpg/600x600bb.jpg
The Elephant in AppSec
The Elephant in AppSec
77 episodes
3 days ago
Time to discuss AppSec issues no one talks about.
Show more...
Technology
RSS
All content for The Elephant in AppSec is the property of The Elephant in AppSec and is served directly from their servers with no modification, redirects, or rehosting. The podcast is not affiliated with or endorsed by Podjoint in any way.
Time to discuss AppSec issues no one talks about.
Show more...
Technology
https://d3t3ozftmdmh3i.cloudfront.net/staging/podcast_uploaded_episode/39783987/39783987-1756293522329-a779c769e39a6.jpg
OWASP SAMM vs BSIMM: Which Maturity Model Reigns Supreme?
The Elephant in AppSec
46 minutes 26 seconds
2 months ago
OWASP SAMM vs BSIMM: Which Maturity Model Reigns Supreme?

Today, I'm joined by Nariman Aga-Tagiyev, a seasoned cybersecurity architect and threat modeling coach, bringing over two decades of experience in the software development industry. 

As the founder of SecureHabits, he’s on a mission to help software manufacturers mature their secure software development lifecycle.

Nariman is a familiar face at OWASP Netherlands Chapter events and an active contributor to projects like OWASP SAMM and the Security Champions Maturity Model. His work bridges the gap between theory and practice, empowering teams to build security into their culture - not just their code.

In this episode, we dive into a memorable "battle" Nariman had at the RSA conference, where he argued both sides of the SAMM vs. BSIMM debate—mostly with himself, after BSIMM expert Caroline Wong couldn’t attend. 

We also explore why organizations often skip the foundational steps before rushing to buy security tools, why true maturity is so rare, and what the new regulatory frameworks like the Cyber Resilience Act mean for businesses in the EU.


Dive right in! 

The Elephant in AppSec
Time to discuss AppSec issues no one talks about.