Listen "Steve Lipner of SAFECODE on Supply Chain Security - Is It Even Possible?"
Episode Synopsis
In this conversation, Steve Lipner of SAFECODE explains what secure software is, and recounts his own experiences on Microsoft’s Software Security Development Lifecycle Team as the point of the spear in Microsoft’s Trustworthy Computing Initiative. Lipner stresses that secure software must come from within (so to speak). Outside consultants may be able to promote best practices, but they will never be able to grasp what needs fixing. That’s why an organization’s developers need to be trained and motivated to write secure code, which means seeing mistakes as they write code and throughout the entire development process. Lipner also talks about the Biden Administration’s Executive Order (EO) on Improving the Nation’s Cybersecurity, released in May 2021. Lipner believes that the impact of the EO is still a work in progress. He’s particularly a “fan” of Section 4 of the EO, which lists the requirements for a robust software security program.
More episodes of the podcast ConversingLabs Podcast
The State of Vulnerability Management
05/11/2025
Who Will Maintain Open Source’s Future?
14/10/2025
Security Badging Open-Source Projects
21/08/2025
Aviation Has A Software Problem
10/07/2025
The Threat of Package Hallucinations
01/07/2025
Going Back to Basics to Thwart Attacks
08/05/2025
AppSec Girl Power
10/04/2025
Cybersecurity's Double-Edged Sword
26/03/2025
The Evolution of Threat Intel
17/03/2025
Hackers Hacking Hackers
01/10/2024
ZARZA We are Zarza, the prestigious firm behind major projects in information technology.