<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic State of Software Security Report in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/State-of-Software-Security-Report/m-p/34422#M2524</link>
    <description>&lt;P&gt;Earth shattering news from Veracode today in its &lt;A href="https://info.veracode.com/report-state-of-software-security-volume-10.html?utm_source=idg&amp;amp;utm_medium=digital-ad&amp;amp;utm_campaign=VER012T000000sarjQAA&amp;amp;utm_term=playlist-brandpost&amp;amp;utm_content=soss-v10" target="_blank" rel="noopener"&gt;State Software Security Report Volume 10&lt;/A&gt;: &lt;STRONG&gt;Apps are insecure!&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;83 percent of applications have at least one flaw in their initial scan&lt;/LI&gt;&lt;LI&gt;68 percent of developers say their organizations don't provide training in application security&lt;/LI&gt;&lt;LI&gt;Newly found security flaws are prioritized over older flaws&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The bottom line: &lt;STRONG&gt;application security debt&lt;/STRONG&gt; is piling up! Do your part to reduce technical debt, sponsor a bug fixit week for your organization. Make your next sprint security focused.&lt;/P&gt;</description>
    <pubDate>Mon, 09 Oct 2023 09:29:22 GMT</pubDate>
    <dc:creator>AppDefects</dc:creator>
    <dc:date>2023-10-09T09:29:22Z</dc:date>
    <item>
      <title>State of Software Security Report</title>
      <link>https://community.isc2.org/t5/Tech-Talk/State-of-Software-Security-Report/m-p/34422#M2524</link>
      <description>&lt;P&gt;Earth shattering news from Veracode today in its &lt;A href="https://info.veracode.com/report-state-of-software-security-volume-10.html?utm_source=idg&amp;amp;utm_medium=digital-ad&amp;amp;utm_campaign=VER012T000000sarjQAA&amp;amp;utm_term=playlist-brandpost&amp;amp;utm_content=soss-v10" target="_blank" rel="noopener"&gt;State Software Security Report Volume 10&lt;/A&gt;: &lt;STRONG&gt;Apps are insecure!&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;83 percent of applications have at least one flaw in their initial scan&lt;/LI&gt;&lt;LI&gt;68 percent of developers say their organizations don't provide training in application security&lt;/LI&gt;&lt;LI&gt;Newly found security flaws are prioritized over older flaws&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The bottom line: &lt;STRONG&gt;application security debt&lt;/STRONG&gt; is piling up! Do your part to reduce technical debt, sponsor a bug fixit week for your organization. Make your next sprint security focused.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 09:29:22 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/State-of-Software-Security-Report/m-p/34422#M2524</guid>
      <dc:creator>AppDefects</dc:creator>
      <dc:date>2023-10-09T09:29:22Z</dc:date>
    </item>
    <item>
      <title>Re: State of Software Security Report</title>
      <link>https://community.isc2.org/t5/Tech-Talk/State-of-Software-Security-Report/m-p/34434#M2528</link>
      <description>&lt;P&gt;Also look to provide app scanning as part of your vulnerability management process.&lt;/P&gt;&lt;P&gt;Institute measures to offer app scanning at multiple points in the process, In Development, Pre-production, and Post-Production. Create a process where developers can ask for ad-hoc/on demand scans. Look to add value to your security department by providing a service that helps both departments.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Too often I see a vulnerability management program that only does vulnerability scanning on endpoints or servers but forgets to include applications or farms it out to a third-party once every three or more years.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2020 11:54:45 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/State-of-Software-Security-Report/m-p/34434#M2528</guid>
      <dc:creator>CISOScott</dc:creator>
      <dc:date>2020-04-03T11:54:45Z</dc:date>
    </item>
  </channel>
</rss>

