
Matt Rose -- Software Supply Chain Security Means Many Different Things to Different People
The Application Security Podcast
00:00
Integrating Security: The Role of Threat Modeling
This chapter emphasizes the critical role of threat modeling in software development, advocating for security considerations to be integrated from the initial stages. It discusses the urgency of identifying design weaknesses early and the complexities of software supply chain security, highlighting the recent rise in library compromises. The speakers argue for a comprehensive approach to application security that goes beyond Software Composition Analysis, pointing out the necessity of addressing a wide range of vulnerabilities.
Transcript
Play full episode