
Season 1: Open Source Security
Episode 6: Software Composition Analysis Selection Criteria
The Language of Love (and Code)
Accuracy: The Goldilocks Zone
Speed: Because Time is Money (and Sanity)
Remediation: The Path of Least Resistance
User-Friendly: No Computer Science Degree Required
Timing is Everything
The Never-Ending Story
Oct 7, 2024
7 min

Season 1: Open Source Security
Episode 5: Embarking on the Open Source Security Journey.
When Organisations Take the Leap
The Crucial Role of Awareness and Buy-in
The First Steps: Gaining Visibility
Key Takeaways for a Successful Program
Practical Steps and Resources
Sep 23, 2024
7 min

Season 1: Open Source Security
Episode 4: 5 Steps for Securing Your Open Source Supply Chain
Most modern applications are assembled from open-source components with developers typically writing less than 15% of the code for their application. Here are the 5 Steps for securing your open source supply chain.
Step 1: Maintain a Software Bill of Materials (SBOM)
Step 2: Perform Due Diligence - Scan for Vulnerabilities
Step 3: Have a Centralized Artifact Repository - Use Only Approved Software
Step 4: Always Use Latest - Don't Use Stale Components
Step 5: Run a Web Application Firewall (WAF)
Sep 9, 2024
10 min

Series 1: Open-Source Security
Episode 3: How Secure Are Your Open Source Software
Get ready for an eye-opening episode that could change the way you think about the building blocks of modern applications.
The Open-Source Paradox
The Security Controls Gap
The Open-Source Enigma
The Due Diligence Disparity
The Cost of Insecure Open Source: A Walk Down Memory Lane
Best Practices for Secure Open-Source Usage
Aug 26, 2024
10 min

Season 1: Open Source Security
Episode 2: Do Your Applications Have A Software Bill of Materials?
“Oh, I didn’t realise we were exposed to as I didn’t think that application was using .”
I often heard such comments during the initial stages of our application security uplift. There was a lack of visibility on what open-source components applications relied on. Developers were often surprised, and sometimes in disbelief, as most of these vulnerable software components weren’t listed as application dependencies; they were transitive dependencies.
In this episode we're diving into a crucial topic: "Do You Have a Software Bill of Materials?" Get ready for an enlightening episode as we explore why SBOMs are essential in today's software landscape.
The Visibility Problem
The Open-Source Reality
What is an SBOM?
The Benefits of SBOMs
Keeping SBOMs Up-to-Date
Recent Developments in SBOM Adoption
Aug 12, 2024
13 min

Season 1: Open Source Security
Episode 1: You're Using More Open-Source Than You Realise
We're diving into a topic that might surprise you: "You're Using More Open-Source Than You Realize." Get ready for an eye-opening episode that could change the way you think about your applications.
• The Open-Source Reality Check
• Real-World Example: The Log4j Wake-Up Call
• The Rise of AI in Development
• The Exponential Growth of Open-Source Usage
• The Log4j Saga Continues
• Why Are We Still at Risk?
• The Hidden Costs of Open-Source
• Best Practices for Managing Open-Source
Jul 29, 2024
10 min

Welcome to AppSec Unlocked, the podcast that's all about
demystifying application security and empowering developers and security professionals alike. I'm your host, Edwin Kwan, and I'm thrilled to kick off this exciting journey with you.
What is AppSec Unlocked?
AppSec Unlocked is your key to understanding the complex world of application security. Whether you're a seasoned security professional, a curious developer,
or somewhere in between, this podcast is designed to provide you with actionable insights, expert interviews, and the latest trends in the rapidly evolving field of application security.
Jul 29, 2024
5 min
