Dr. Dag Flachet, Dr. Aram Hovsepyan

The AppSec Management Podcast

This podcast is about application security, OWASP and security first compliance. It is targeted at those involved with application security programmes and anyone interested in the frontier of cybersecurity in applications.

Author

Dr. Dag Flachet, Dr. Aram Hovsepyan

Category

Technology

Podcast website

podcasters.spotify.com

Latest episode

Jun 16, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

CVE and CVSS are broken. 06.11.2025

This podcast is based on in depth analysis by Dr. Aram Hovsepyan. Voices and narrative are AI generated. For full factual accuracy refer to underlying article. https://codific.com/appsec-risk-with-cve-and-cvss/

Privacy Threat Modeling: Learn all about it from two experts in the field! 30.10.2025

Learn more about privacy threat modeling in this blog post: https://codific.com/privacy-threat-mo... In this podcast we had a very nice conversation with two experts in the field of privacy threat modeling, Kim Wuyts and Aram Hovsepyan. Privacy threat modeling is a process of identifying and assessing potential threats to an individual's personal information. Kim and Aram are experts in this t...

SAMM Assessment: Everything you need to know from industry experts 23.10.2025

Join us on this podcast as we convene with four leading Application Security specialists and focus on the assessment aspect of SAMM.SAMM Assessment is the process of figuring out the current security maturity for a given scope (which can be a team, a business unit or the entire organization). Software Assurance Maturity Model (SAMM) provides a clear-cut questionnaire with 90 multiple-choice questi...

Embedding Security into the SDLC: How Sign In Solutions uses SAMMY & OWASP SAMM 16.10.2025

In this episode, Jason Mordeno, Director of Compliance and Security at Sign In Solutions, shares how his team embedded application security directly into their SDLC using OWASP SAMM and SAMMY.Discover how Signin Solutions moved beyond ISO 27001 and SOC 2 checklists to create a behavior-driven, developer-friendly AppSec culture, resulting in improved security maturity, better risk posture, and even...

An introduction to BSIMM, Building Security in Maturity Model 09.10.2025

This content is based on an article written by Nicolas Montauban. Voices and narratives are AI generated. For full factual accuracy please refer to the underlying article: https://codific.com/bsimm-building-security-in-maturity-model-a-complete-guide/

How to integrate ZAP into Gitlab. 02.10.2025

This episode is based on an article by Dr. Aram Hovsepyan and Alex Ashkov. Voices and narrative are AI generated. For full factual accuracy refer to the underlying article. https://codific.com/how-to-integrate-zap-in-gitlab/

Appsec case study: Attendance Radar 25.09.2025

This narrative is based on content from the Codific and AttendanceRadar Websites. For full factual accuracy please refer to the websites: Codific.com Attendanceradar.com

Defect Management Best Practices 11.09.2025

This content is based on an article written by Nicolas Montauban. Voices and narrative is AI generated, for full factual accuracy refer to the underlying article. https://codific.com/how-to-implement-security-defect-tracking/

Preparing for CRA 04.09.2025

This content is based on an interview with Simon Montete. Voices and narrative are AI generated. For full factual accuracy please refer to the underlying article. https://codific.com/prepare-for-cra/

OWASP SAMM vs OWASP DSOMM 28.08.2025

This content is written by Nicolas Montauban. Voices are AI generated. For full factual accuracy refer to the underlying article: https://codific.com/dsomm-vs-samm

Introduction to OWASP DSOMM 21.08.2025

This content is written by Nicolas Montauban. Voices and narrative is AI generated. For full factual accuracy refer the the article: https://codific.com/owasp-dsomm-a-comprehensive-introduction

Using ASVS with SAMM. 14.08.2025

This content is written by Dr. Aram Hovsepyan. https://codific.com/requirements-driven-testing-the-best-roi-security-practice Voices and narrative are AI generated. For full factual accuracy refer to the underlying article.

Software Security Requirements Explained: Why It Matters and How to Implement It Effectively 07.08.2025

The content for this podcast is written by Dr. Aram Hovsepyan. https://codific.com/mastering-owasp-samm-security-requirements-explained Narrative and voices are by AI, for full factual accuracy refer to the article linked.

Mistakes to avoid in implementing OWASP SAMM 31.07.2025

The content of this episode is written by Dr. Aram Hovsepyan. https://codific.com/how-to-implement-owasp-samm-tooling-example-and-mistakes-to-avoid Voices and narrative are AI generated, refer to the article for full factual accuracy.

Stories from practical use of OWASP SAMM 24.07.2025

This episode is based on two articles. Voices are AI generated, for full factual accuracy refer to the articles below: https://codific.com/building-security-into-software/ https://codific.com/implementing-owasp-samm

How to implement ISO27001 17.07.2025

This episode is based on an article written by Michaella Masters. Voices are AI generated for full factual accuracy refer to the underlying article. https://codific.com/how-to-implement-iso-27001

Getting started with the Cyber Fundamentals (Cyfun) framework. 10.07.2025

This episode is based on an article written by Aram Hovsepyan. Voices are AI generated. Please refer to the underlying article for full factual accuracy. https://codific.com/what-is-cyfun-and-how-to-implement-it

How to choose good metrics in AppSec 03.07.2025

This article is based on a conference talk by Aram Hovsepyan at OWASP Global Appsec Barcelona 2025. Voices are AI generated. For full factual accuracy please refer to the underlying article: https://codific.com/security-metrics-with-purpose-and-strategic-impact/ There is also a free course on metrics by Aram Hovsepyan available on Thinkific. https://owaspsamm.thinkific.com/courses/metrics

Introduction to the SSDLC 26.06.2025

This podcast is based on the following article by Nicolas Montauban. Voices are AI generated, for full factual accuracy please refer to underlying article. https://codific.com/what-is-the-ssdlc-a-guide-to-secure-development

Implementing OWASP SAMM: A practical guide 19.06.2025

This episode is a practical guide to OWASP SAMM. It is based on the following article: https://codific.com/how-to-implement-owasp-samm-tooling-example-and-mistakes-to-avoid/ Voices by Notebook LM

What is FISMA and how to comply with it? 12.06.2025

This episode is an introduction to FISMA. Voices are by Notebook LM and content is based on the following article: https://codific.com/what-is-fisma-and-how-to-comply-with-it/

Security's Four Layers: SDLC to Information Security 05.06.2025

This episode is about the article by Aram Hovsepyan comparing the different layers in security management. https://codific.com/information-security-and-cybersecurity-understanding-the-layers/ Voices by Notebook LM

Contingency planning with NIST 800-34 29.05.2025

This episode is a guide to contingency planning with NIST 800-34. Voices are by Notebook LM. Content is from the following article: https://codific.com/nist-800-34-contingency-planning-a-practical-guide-to-resilience/

NIST 800-53: A practical guide. 23.05.2025

This episode is a practical guide to NIST 800-53. Voices are by Notebook LM. Content is based on the following articles: https://codific.com/how-to-implement-nist-800-53/ https://codific.com/what-is-nist-800-53-a-comprehensive-guide/

Implementing NIST SSDF 15.05.2025

This episode is a complete introduction to NIST SSDF. Voices are by Notebook LM and content is based on this article: https://codific.com/what-is-nist-ssdf-and-how-should-you-implement-it/

Listen to the The AppSec Management Podcast podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.