Dr. Dag Flachet, Dr. Aram Hovsepyan
The AppSec Management Podcast
This podcast is about application security, OWASP and security first compliance. It is targeted at those involved with application security programmes and anyone interested in the frontier of cybersecurity in applications.
Author
Dr. Dag Flachet, Dr. Aram Hovsepyan
Category
Podcast website
Latest episode
Jun 16, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
CVE and CVSS are broken. 06.11.2025 15:20
This podcast is based on in depth analysis by Dr. Aram Hovsepyan. Voices and narrative are AI generated. For full factual accuracy refer to underlying article. https://codific.com/appsec-risk-with-cve-and-cvss/
Privacy Threat Modeling: Learn all about it from two experts in the field! 30.10.2025 50:23
Learn more about privacy threat modeling in this blog post: https://codific.com/privacy-threat-mo... In this podcast we had a very nice conversation with two experts in the field of privacy threat modeling, Kim Wuyts and Aram Hovsepyan. Privacy threat modeling is a process of identifying and assessing potential threats to an individual's personal information. Kim and Aram are experts in this t...
SAMM Assessment: Everything you need to know from industry experts 23.10.2025 56:24
Join us on this podcast as we convene with four leading Application Security specialists and focus on the assessment aspect of SAMM.SAMM Assessment is the process of figuring out the current security maturity for a given scope (which can be a team, a business unit or the entire organization). Software Assurance Maturity Model (SAMM) provides a clear-cut questionnaire with 90 multiple-choice questi...
Embedding Security into the SDLC: How Sign In Solutions uses SAMMY & OWASP SAMM 16.10.2025 41:34
In this episode, Jason Mordeno, Director of Compliance and Security at Sign In Solutions, shares how his team embedded application security directly into their SDLC using OWASP SAMM and SAMMY.Discover how Signin Solutions moved beyond ISO 27001 and SOC 2 checklists to create a behavior-driven, developer-friendly AppSec culture, resulting in improved security maturity, better risk posture, and even...
An introduction to BSIMM, Building Security in Maturity Model 09.10.2025 19:44
This content is based on an article written by Nicolas Montauban. Voices and narratives are AI generated. For full factual accuracy please refer to the underlying article: https://codific.com/bsimm-building-security-in-maturity-model-a-complete-guide/
How to integrate ZAP into Gitlab. 02.10.2025 15:39
This episode is based on an article by Dr. Aram Hovsepyan and Alex Ashkov. Voices and narrative are AI generated. For full factual accuracy refer to the underlying article. https://codific.com/how-to-integrate-zap-in-gitlab/
Appsec case study: Attendance Radar 25.09.2025 12:42
This narrative is based on content from the Codific and AttendanceRadar Websites. For full factual accuracy please refer to the websites: Codific.com Attendanceradar.com
Defect Management Best Practices 11.09.2025 20:14
This content is based on an article written by Nicolas Montauban. Voices and narrative is AI generated, for full factual accuracy refer to the underlying article. https://codific.com/how-to-implement-security-defect-tracking/
Preparing for CRA 04.09.2025 12:51
This content is based on an interview with Simon Montete. Voices and narrative are AI generated. For full factual accuracy please refer to the underlying article. https://codific.com/prepare-for-cra/
OWASP SAMM vs OWASP DSOMM 28.08.2025 19:26
This content is written by Nicolas Montauban. Voices are AI generated. For full factual accuracy refer to the underlying article: https://codific.com/dsomm-vs-samm
Introduction to OWASP DSOMM 21.08.2025 20:39
This content is written by Nicolas Montauban. Voices and narrative is AI generated. For full factual accuracy refer the the article: https://codific.com/owasp-dsomm-a-comprehensive-introduction
Using ASVS with SAMM. 14.08.2025 12:58
This content is written by Dr. Aram Hovsepyan. https://codific.com/requirements-driven-testing-the-best-roi-security-practice Voices and narrative are AI generated. For full factual accuracy refer to the underlying article.
Software Security Requirements Explained: Why It Matters and How to Implement It Effectively 07.08.2025 16:56
The content for this podcast is written by Dr. Aram Hovsepyan. https://codific.com/mastering-owasp-samm-security-requirements-explained Narrative and voices are by AI, for full factual accuracy refer to the article linked.
Mistakes to avoid in implementing OWASP SAMM 31.07.2025 17:26
The content of this episode is written by Dr. Aram Hovsepyan. https://codific.com/how-to-implement-owasp-samm-tooling-example-and-mistakes-to-avoid Voices and narrative are AI generated, refer to the article for full factual accuracy.
Stories from practical use of OWASP SAMM 24.07.2025 21:34
This episode is based on two articles. Voices are AI generated, for full factual accuracy refer to the articles below: https://codific.com/building-security-into-software/ https://codific.com/implementing-owasp-samm
How to implement ISO27001 17.07.2025 26:16
This episode is based on an article written by Michaella Masters. Voices are AI generated for full factual accuracy refer to the underlying article. https://codific.com/how-to-implement-iso-27001
Getting started with the Cyber Fundamentals (Cyfun) framework. 10.07.2025 18:29
This episode is based on an article written by Aram Hovsepyan. Voices are AI generated. Please refer to the underlying article for full factual accuracy. https://codific.com/what-is-cyfun-and-how-to-implement-it
How to choose good metrics in AppSec 03.07.2025 30:56
This article is based on a conference talk by Aram Hovsepyan at OWASP Global Appsec Barcelona 2025. Voices are AI generated. For full factual accuracy please refer to the underlying article: https://codific.com/security-metrics-with-purpose-and-strategic-impact/ There is also a free course on metrics by Aram Hovsepyan available on Thinkific. https://owaspsamm.thinkific.com/courses/metrics
Introduction to the SSDLC 26.06.2025 15:20
This podcast is based on the following article by Nicolas Montauban. Voices are AI generated, for full factual accuracy please refer to underlying article. https://codific.com/what-is-the-ssdlc-a-guide-to-secure-development
Implementing OWASP SAMM: A practical guide 19.06.2025 14:15
This episode is a practical guide to OWASP SAMM. It is based on the following article: https://codific.com/how-to-implement-owasp-samm-tooling-example-and-mistakes-to-avoid/ Voices by Notebook LM
What is FISMA and how to comply with it? 12.06.2025 18:29
This episode is an introduction to FISMA. Voices are by Notebook LM and content is based on the following article: https://codific.com/what-is-fisma-and-how-to-comply-with-it/
Security's Four Layers: SDLC to Information Security 05.06.2025 26:36
This episode is about the article by Aram Hovsepyan comparing the different layers in security management. https://codific.com/information-security-and-cybersecurity-understanding-the-layers/ Voices by Notebook LM
Contingency planning with NIST 800-34 29.05.2025 21:51
This episode is a guide to contingency planning with NIST 800-34. Voices are by Notebook LM. Content is from the following article: https://codific.com/nist-800-34-contingency-planning-a-practical-guide-to-resilience/
NIST 800-53: A practical guide. 23.05.2025 25:21
This episode is a practical guide to NIST 800-53. Voices are by Notebook LM. Content is based on the following articles: https://codific.com/how-to-implement-nist-800-53/ https://codific.com/what-is-nist-800-53-a-comprehensive-guide/
Implementing NIST SSDF 15.05.2025 15:39
This episode is a complete introduction to NIST SSDF. Voices are by Notebook LM and content is based on this article: https://codific.com/what-is-nist-ssdf-and-how-should-you-implement-it/
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.