Podcast Rozchmurzony #25 - About security, DevSecOps and SecDevOps with Andrzej Dyjak

Опубликовано: 18 Май 2026
на канале: Cloudowski
206
3

Security conversations don't have to be boring, especially with interesting guests like Andrzej Dyjak.
Andrzej and I sat down and discussed interesting topics related to the security of modern application platforms.
Listen and learn, among other things:

Why is security often not a priority in smaller companies?
What was one of the most audacious attacks in recent years, exploiting vulnerabilities in the CI/CD process?
What is the OWASP Top 10?
What is one method that drastically improves security?

DevSecOps, DevSecOps, and SecDevOps - what are the differences?

Links:

OWASP Top 10 - https://owasp.org/www-project-top-ten/
OWASP Top 10 for Kubernetes - https://owasp.org/www-project-kuberne...
OWASP Top 10 for LLMs (Language Learning Models) - https://llmtop10.com/
OWASP ASVS (Application Security Verification Standard) - https://owasp.org/www-project-applica...
Cheat Sheet Series - https://cheatsheetseries.owasp.org/in...
The Consumer Authentication Strength Maturity Model (CASMM) - https://danielmiessler.com/p/casmm-co...
GDPR (General Data Protection Regulation) - https://gdpr.eu/
NIS (Directive on the Security of Network and Information Systems) - https://digital-strategy.ec.europa.eu...
Data Breach Investigation Report - https://www.verizon.com/business/en-n...
Homepage - https://dyjak.me
Secure Code - https://bezpiecznykod.pl
Security Automation in CICD: DevSecOps (ABCD) - https://abcdevsecops.pl
Offensive Web Application Testing (OTWA) - https://ofensywnetestowanie.pl