Redefining What Secure Application Development Looks Like: Bringing Application Security into Foc...

Channel:
Subscribers:
4,690
Published on ● Video Link: https://www.youtube.com/watch?v=PgEp9v_ykiY



Duration: 0:00
2 views
0


In this On Location episode during OWASP AppSec Global 2025 in Barcelona, Josh Grossman, co-leader of the OWASP Application Security Verification Standard (ASVS) project, shares key updates and strategic thinking behind the release of ASVS version 5. This release, years in the making, reflects a renewed focus on making the standard more approachable, practical, and actionable for development teams and security leaders alike.


ASVS is designed to provide a comprehensive and verifiable set of security requirements for building and maintaining secure applications. More than just a checklist, it offers a clear blueprint for what a secure application should look like—making it easier to benchmark progress, develop secure design requirements, and implement effective controls. Version 5 emphasizes accessibility, particularly by lowering the barrier to entry for organizations adopting Level 1 of the standard, reducing the threshold of required controls from nearly 50% to under 30%.


One of the major shifts in this new version is the tighter focus on the application itself, moving away from system-level topics like backup policies that tend to fall outside the scope of app development teams. This makes the standard more relevant to software architects, developers, and QA engineers—providing requirements that fall within their sphere of influence, while still covering the full software lifecycle from design to deployment.


Grossman explains how organizations can customize ASVS to include their internal controls and build out secure coding checklists, implementation guides, and requirements documents tailored to their environments. He also highlights how ASVS aligns with other OWASP projects, like the Cheat Sheet Series and SAMM, for both control-level guidance and organizational process development.


For security leaders looking to improve their application security programs, ASVS v5 offers a foundation to build on—clear, community-driven, and extensible. And true to OWASP’s spirit, the project is backed by a passionate community, from project co-leads like Grossman and Elar Lang to contributors around the world. As Grossman puts it, OWASP is about connection—people tackling similar challenges, working together to make software safer.


If you’re looking for a way to bring practical, standards-based security into your software lifecycle, this conversation is your starting point.

GUEST: Josh Grossman | CTO of Bounce Security and co-leader of the OWASP Application Security Verification Standard (ASVS) project | https://www.linkedin.com/in/joshcgrossman/


HOST: Sean Martin, Co-Founder at ITSPmagazine and Host of Redefining CyberSecurity Podcast | https://www.seanmartin.com/


SPONSORS


Manicode Security: https://itspm.ag/manicode-security-7q8i


RESOURCES


OWASP Application Security Verification Standard (ASVS): https://owasp.org/www-project-application-security-verification-standard/


Learn more and catch more stories from OWASP AppSec Global 2025 Barcelona coverage: https://www.itspmagazine.com/owasp-global-appsec-barcelona-2025-application-security-event-coverage-in-catalunya-spain


Catch all of our event coverage: https://www.itspmagazine.com/technology-and-cybersecurity-conference-coverage


Want to tell your Brand Story Briefing as part of our event coverage? Learn More 👉 https://itspm.ag/evtcovbrf


Want Sean and Marco to be part of your event or conference? Let Us Know 👉 https://www.itspmagazine.com/contact-us




Other Videos By ITSPmagazine


2025-05-31Chats on the Road to Infosecurity London, Kick-Off Episode — On Location with Sean and Marco
2025-05-30From Dashboards to Decisions: Why Your Security Metrics Might Be Leading You Astray | An OWASP Ap...
2025-05-30From Dashboards to Decisions: Why Your Security Metrics Might Be Leading You Astray | Aram Hovsepyan
2025-05-30From Dashboards to Decisions: Why Your Security Metrics Might Be Leading You Astray | An OWASP Ap...
2025-05-29Why Global Community-Led Innovation Is Driving Real Application Security Progress | An OWASP AppS...
2025-05-29Holding the Line on Quality in an AI-Driven SDLC | An OWASP AppSec Global 2025 Conversation with ...
2025-05-29Holding the Line on Quality in an AI-Driven SDLC | An OWASP AppSec Global 2025 Conversation with ...
2025-05-29Why Global Community-Led Innovation Is Driving Real Application Security Progress
2025-05-29Why Global Community-Led Innovation Is Driving Real Application Security Progress | An OWASP AppS...
2025-05-29Holding the Line on Quality in an AI-Driven SDLC | OWASP AppSec Global 2025 w/ Sarah-Jane Madden
2025-05-28Redefining What Secure Application Development Looks Like: Bringing Application Security into Foc...
2025-05-27Turning AppSec into a Workflow, Not a Roadblock – Building Security Programs That Teams Want to Use
2025-05-27Turning AppSec into a Workflow, Not a Roadblock – Building Security Programs That Teams Actually ...
2025-05-27Turning AppSec into a Workflow, Not a Roadblock – Building Security Programs That Teams Actually ...
2025-05-26The 30s | A Conversation with Bryan Wish | After 40 Podcast with Dr. Deborah Heiser
2025-05-26The 30s | A Conversation with Bryan Wish | After 40 Podcast with Dr. Deborah Heiser
2025-05-26Agentic AI to the Rescue? From Billable Hours to Bots: The New Legal Workflow
2025-05-25Outside the Ivory Tower: Connecting Practice and Science—Why Human-Centered Cybersecurity Needs Both
2025-05-25Teaser: Measuring the Blast Radius of Tech Experimentation
2025-05-25Outside the Ivory Tower: Connecting Practice and Science — Why Human-Centered Cybersecurity Needs...
2025-05-25Agentic AI to the Rescue? From Billable Hours to Bots: The New Legal Workflow | A Conversation wi...