How does the impact of CRA compare with GDPR?
www.helpnetsecurity.com/2025/04/18/d...
How does the impact of CRA compare with GDPR?
www.helpnetsecurity.com/2025/04/18/d...
For the first time in my career I will be speaking at the main Global Appsec Conference.
If you are interested in appsec, or you are just a really good friend and want to support me, you are more than welcome to attend!
The main talk is on Thursday 29th of May at 3:30PM at CCIB Barcelona.
A layered perspective to security programs. What is the right level for you? codific.com/information-...
If the Gif isn't giving it for you, you can check it out here: www.linkedin.com/posts/codifi...
In 2024 we finally had the impression we moved the meter, at least a tiny bit, in helping to build a simple and safe digital future. The road is long and the steps are small. Let's take more baby steps in 2025 and mature the world appsec defences.
At Codific we invest a lot of effort in different OWASP projects, and OWASP SAMM is our favorite. We do this for "free" but we get a lot in return. Recognition is one thing, but more important is a seat at the table designing the simple and safe digital future. www.linkedin.com/posts/owasp-...
See you there! Or here, I live here :). Welcome to bcn Owasps!
There are more than 1000 controls in NIST 800-53, so how do you find your way? codific.com/what-is-nist...
Need to comply with HIPAA? My colleague Mahe just published a guide. codific.com/hipaa-an-imp...
FOMO? Dying to get hacked like everyone else you know. We got your back! codific.com/how-to-get-h...
Chess is still the king of all games, convince me otherwise! codific.com/appsec-and-c...
OWASP, NIST, ISO, so many standards and frameworks. If only your assessment in one could map to the next. Well, it turns out it can, kinda. codific.com/bridging-com...
Google calendar now has dark mode. But, I really don't care, and I don't get the fuss. All apps are boasting dark mode now as if it is something super high tech. Bro, I had dark mode on my MS-Dos pc.
NIST SSDF or OWASP SAMM which one to pick as the backbone of your application security program? And you really have to pick? codific.com/comparing-ni...
Black Friday special: OWASP SAMM is now free to use. Wait.. aren't all OWASP resources free? ...shhhh!
h, plack's constant
Ik heb de talk niet gehoord, maar ik denk best wel dat er heel wat CISOs daar hard over nagedacht hebben. Dat is mede de reden waarom OWASP SAMM bestaat. codific.com/reporting-wi...
Happy thanksgiving, and a special thank you to anyone who contributes to an open source project!
Doctors and nurses have always been there for us. From the first to the last breath, they are there when it really matters. So it is nice when we, the nerdy computer people, can do something back for them. youtu.be/k6oClwzUa9k?...
Molt be!
So what does a OWASP SAMM interview look like? Who do you interview? What does the interview look like? How many people should you interview? How can you get started? www.youtube.com/watch?v=3Btv...
Excited! Working on it!
Using OWASP SAMM allows you to communicate internally in a nuanced way about the security state and security roadmap of each team, project or business unit. codific.com/reporting-wi... #appsec #owasp #infosec
As a company you can keep track of all your appsec processes with BSIMM or SAMM. But which one should you pick? codific.com/bsimm-vs-samm/
Ik was mij niet bewust van een beperking. Ik ben Vlaming, close enough? Maar ik post eigenlijk altijd in het Engels, dat is inclusiever, alle Nederlandstaligen kunnen wel Engels.
Super bedankt! De Engelse lijst mag ook aub! Bedankt voor het initiatief te nemen.
Dag @jilles.com zou je mij kunnen toevoegen aan de lijst? Ik post vooral over OWASP en appsec.
Unpopular opinion: some regulations are good. Trump claims he will try to do away with a lot of regulation. But some regulation is actually actionable and effective. Case in point FISMA. Government and government contractors should be held to high security standards.
codific.com/how-to-imple...
Here is a deep dive by OWASP SAMM experts on the practical aspects of SAMM assessments. With
@aramh.bsky.social Maxim Baele, Brian Glas and Rob van de Veer. What a dream team :) youtu.be/Zg-HN17D3O8?...
So how is the other guy doing? Are you top off class? Find out in the OWASP SAMM benchmark. codific.com/owasp-samm-b...