Security Journey Blog
Here you’ll find the latest news, information, and trends in application security and compliance, plus tips and strategies for writing safer code and building a security culture.
Stay Up-to-Date on all Security Journey news and events.
Featured Articles
Empower Your Developers, Secure Your APIs: Free OWASP Top 10 Training
The digital world thrives on APIs, the connectors that power seamless interactions between applications and services....
What You Need To Know About Secure Coding Training for PCI DSS v4.0 Requirements
The latest version of the Payment Card Industry Data Security Standard (PCI DSS), version 4.0, was released in March 2022. Although the requirements won't take effect until 2025, it's crucial to start preparing now.
Read More
Posts by Security Journey/HackEDU Team
Jen Easterly, US Director of the Cybersecurity and Infrastructure Agency (CISA), recently called for universities to include security as a standard element in computer science coursework.
What You Need To Know About PCI Assessments And Vulnerability Remediation Requirements
No matter your company size -- or how many credit card transactions you process-- you must follow PCI compliance standards. These standards are designed to protect the data shared with you by your customers.
Using the Security Champions Framework to Optimize Your Security Program
Mike talks to Chris Romeo about the growth of champions programs, the Security Champions Framework, and the mistake that organizations make with their programs.
Secure Coding Training Against Injection Vulnerabilities [INFOGRAPHIC]
This infographic breaks down the stats around injection vulnerabilities and how secure coding training can help protect your organization.
Security Champions, Are We Doing It All Wrong? Part 3
This is part 3 in a 3-part series about Security Champions by Michael Burch, host of The Security Champion Podcast. You can read part 1 and part 2 on our website.
How To Improve Your Code Reviews
The key you should know about code reviews – the review is only as good as the developer. Giving your development team effective, secure coding training is the best way to improve your code review process.
Security Champions, Are We Doing It All Wrong? Part 2
This is part 2 in a 3-part series about Security Champions by Michael Burch, host of The Security Champion Podcast. You can read part 1 on our website.
Security Champions, Are We Doing It All Wrong? Part 1
This is part 1 in a 3-part series about Security Champions by Michael Burch, host of The Security Champion Podcast.
Customizing Your AppSec Learning Themes (with Examples)
Are you looking for ways to elevate your AppSec training? First, it's essential to keep in mind that not all learners are the same, and everyone has different learning needs and preferences – whether on an organizational level, team level, or employee level.
Patch Tuesday: March 2023
Following March’s Patch Tuesday updates, it’s important that we don’t forget equally critical patches released earlier in the month.
What is Application Security Training?
Does your organization have application security training? Considering that 95% of data breaches last year were on web apps, now may be the time to invest in comprehensive training that can be applied to everyone within your SDLC.