Artwork

Inhalt bereitgestellt von CISO Tradecraft®. Alle Podcast-Inhalte, einschließlich Episoden, Grafiken und Podcast-Beschreibungen, werden direkt von CISO Tradecraft® oder seinem Podcast-Plattformpartner hochgeladen und bereitgestellt. Wenn Sie glauben, dass jemand Ihr urheberrechtlich geschütztes Werk ohne Ihre Erlaubnis nutzt, können Sie dem hier beschriebenen Verfahren folgen https://de.player.fm/legal.
Player FM - Podcast-App
Gehen Sie mit der App Player FM offline!

#160 - Secure Developer Training Programs (with Scott Russo) Part 1

42:21
 
Teilen
 

Manage episode 390184686 series 2849492
Inhalt bereitgestellt von CISO Tradecraft®. Alle Podcast-Inhalte, einschließlich Episoden, Grafiken und Podcast-Beschreibungen, werden direkt von CISO Tradecraft® oder seinem Podcast-Plattformpartner hochgeladen und bereitgestellt. Wenn Sie glauben, dass jemand Ihr urheberrechtlich geschütztes Werk ohne Ihre Erlaubnis nutzt, können Sie dem hier beschriebenen Verfahren folgen https://de.player.fm/legal.

In this episode of CISO Tradecraft, host G Mark Hardy invites Scott Russo, a cybersecurity and engineering expert for a deep dive into the creation and maintenance of secure developer training programs. Scott discusses the importance of hands-on engaging training and the intersection of cybersecurity with teaching and mentorship. Scott shares his experiences building a secure developer training program, emphasizing the importance of gamification, tiered training, showmanship, and real-world examples to foster engagement and efficient learning. Note this episode will continue in with a part two in the next episode

ISACA Event (10 Jan 2024) With G Mark Hardy - https://www.cisotradecraft.com/isaca

Scott Russo - https://www.linkedin.com/in/scott-russo/

HBR Balanced Scorecard - https://hbr.org/1992/01/the-balanced-scorecard-measures-that-drive-performance-2

Transcripts - https://docs.google.com/document/d/124IqIzBnG3tPj64O2mZeO-IDTx9wIIxJ

Youtube - https://youtu.be/NkrtTncAuBA

Chapters

  • 00:00 Introduction
  • 03:00 Overview of Secure Developer Training Program
  • 04:46 Motivation Behind Creating the Training Program
  • 06:03 Objectives of the Secure Developer Training Program
  • 07:45 Defining the Term 'Secure Developer'
  • 14:49 Keeping the Training Program Current and Engaging
  • 21:10 Real World Impact of the Training Program
  • 21:46 Understanding the Cybersecurity Budget Argument
  • 21:58 Incorporating Real World Examples into Training
  • 22:26 Personal Experiences and Stories in Training
  • 24:06 Industry Best Practices and Standards
  • 24:18 Aligning with OWASP Top 10
  • 25:53 Balancing OWASP Top 10 with Other Standards
  • 26:12 The Importance of Good Stories in Training
  • 26:32 Duration of the Training Program
  • 28:37 Resources Required for the Training Program
  • 32:23 Measuring the Effectiveness of the Training Program
  • 36:07 Gamification and Certifications in Training
  • 38:56 Tailoring Training to Different Levels of Experience
  • 41:03 Conclusion and Final Thoughts

  continue reading

187 Episoden

Artwork
iconTeilen
 
Manage episode 390184686 series 2849492
Inhalt bereitgestellt von CISO Tradecraft®. Alle Podcast-Inhalte, einschließlich Episoden, Grafiken und Podcast-Beschreibungen, werden direkt von CISO Tradecraft® oder seinem Podcast-Plattformpartner hochgeladen und bereitgestellt. Wenn Sie glauben, dass jemand Ihr urheberrechtlich geschütztes Werk ohne Ihre Erlaubnis nutzt, können Sie dem hier beschriebenen Verfahren folgen https://de.player.fm/legal.

In this episode of CISO Tradecraft, host G Mark Hardy invites Scott Russo, a cybersecurity and engineering expert for a deep dive into the creation and maintenance of secure developer training programs. Scott discusses the importance of hands-on engaging training and the intersection of cybersecurity with teaching and mentorship. Scott shares his experiences building a secure developer training program, emphasizing the importance of gamification, tiered training, showmanship, and real-world examples to foster engagement and efficient learning. Note this episode will continue in with a part two in the next episode

ISACA Event (10 Jan 2024) With G Mark Hardy - https://www.cisotradecraft.com/isaca

Scott Russo - https://www.linkedin.com/in/scott-russo/

HBR Balanced Scorecard - https://hbr.org/1992/01/the-balanced-scorecard-measures-that-drive-performance-2

Transcripts - https://docs.google.com/document/d/124IqIzBnG3tPj64O2mZeO-IDTx9wIIxJ

Youtube - https://youtu.be/NkrtTncAuBA

Chapters

  • 00:00 Introduction
  • 03:00 Overview of Secure Developer Training Program
  • 04:46 Motivation Behind Creating the Training Program
  • 06:03 Objectives of the Secure Developer Training Program
  • 07:45 Defining the Term 'Secure Developer'
  • 14:49 Keeping the Training Program Current and Engaging
  • 21:10 Real World Impact of the Training Program
  • 21:46 Understanding the Cybersecurity Budget Argument
  • 21:58 Incorporating Real World Examples into Training
  • 22:26 Personal Experiences and Stories in Training
  • 24:06 Industry Best Practices and Standards
  • 24:18 Aligning with OWASP Top 10
  • 25:53 Balancing OWASP Top 10 with Other Standards
  • 26:12 The Importance of Good Stories in Training
  • 26:32 Duration of the Training Program
  • 28:37 Resources Required for the Training Program
  • 32:23 Measuring the Effectiveness of the Training Program
  • 36:07 Gamification and Certifications in Training
  • 38:56 Tailoring Training to Different Levels of Experience
  • 41:03 Conclusion and Final Thoughts

  continue reading

187 Episoden

Kaikki jaksot

×
 
Loading …

Willkommen auf Player FM!

Player FM scannt gerade das Web nach Podcasts mit hoher Qualität, die du genießen kannst. Es ist die beste Podcast-App und funktioniert auf Android, iPhone und im Web. Melde dich an, um Abos geräteübergreifend zu synchronisieren.

 

Kurzanleitung