World Congress 2021 Jun 30, 2021

Software Security 101: Secure Coding Basics

Thomas Konrad

Are you sacrificing software security for faster release cycles? Discover how to prevent crippling technical debt by mastering foundational secure coding practices and architectural threat modeling.

Pause
Mute Enter Fullscreen
#1 about 8 min

Understanding the importance of building secure software systems

Early integration of security practices reduces future costs and technical debt.

#2 about 15 min

Establishing core security terms and design principles

Understanding key concepts like technical debt, bugs versus flaws, and defense in depth establishes communication baselines.

#3 about 18 min

Evaluating programming languages by their security criteria

Programming attributes like memory safety, type strictness, and sandbox support heavily impact overall application robustness.

#4 about 20 min

Validating and encoding inputs to prevent injection attacks

Differentiating input validation from sanitization safely embeds untrusted data into target structures.

#5 about 17 min

Implementing strong cryptography, session management, and concurrency

Establishing non-guessable session identifiers and avoiding race conditions prevents severe logic exploits.

#6 about 13 min

Identifying and mitigating top software vulnerability classes

Navigating recognized vulnerability lists like OWASP Top 10 establishes targeted defensive strategies.

#7 about 6 min

Managing risks associated with generic third-party dependencies

Mitigating potential exploits introduced by external code requires automated dependency auditing inside deployment pipelines.

#8 about 7 min

Integrating security into the software development process

Shifting left using the OWASP Software Assurance Maturity Model discovers design flaws effectively early.

#9 about 7 min

Recommended training platforms for developing security mindsets

Exploring deliberately vulnerable applications and educational environments helps developers practice active hacking techniques.

#10 about 14 min

Answering audience questions on practical application security

Expert insights address discovering vulnerabilities, static analysis tool selection strategies, and memory management considerations.

Matching moments

2:05 min

Making security a foundational feature in software development

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

7:46 min

Defining fundamental starting points for software application security

LIVE

7:16 min

Addressing developer adoption and future software security risks

Anna Fritsch-Weninger · LIVE

5:25 min

Introduction to secure development and OWASP SAMM

Mathias Tausig · LIVE

5:30 min

Identifying non-coding software vulnerabilities and organizational risks

Tino Sokic · WWC 2023

2:22 min

Introduction to speaker and software security concepts

Sebastian Leuer Sebastian Leuer · WWC 2024

Upcoming sessions on this topic

Open session

World Congress 2026 North America

Practical Threat Modeling for Software Developers

Mudassir Syed

Lead Security Software Engineer

Mudassir Syed
Open session

World Congress 2026 North America

Secure-by-Inclusion: Preventing Accessibility Barriers from Becoming Security Vulnerabilities

Radostina (Ina) Tsvetkova

Norwegian Directorate of Labour and Welfare (NAV), Senior Advisor in Digital Accessibility and Inclusive Design

Radostina (Ina) Tsvetkova
Open session

World Congress 2026 North America

Don’t kill my Vibes - Simple Steps to Stay Secure when Vibe Coding

Isaac Evans

Co-founder & CEO of Semgrep

Isaac Evans
Open session

World Congress 2026 North America

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer @ Capital One

Desmond Lamptey
Open session

World Congress 2026 North America

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

SecurePrompt: Building a Pre-Flight Security Layer for Agentic AI

Ravi Sastry Kadali

AI/ML Engineer at General Motors

Ravi Sastry Kadali