Overview
Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
This 35-minute OWASP Foundation talk draws insightful parallels between marathon running and application security program management. Learn from a speaker who has completed seven marathons and qualified for the Boston Marathon, while also building AppSec programs for over a decade. Discover how principles of disciplined training, strategic pacing, and incremental progress apply to both domains. Explore essential mindset strategies, goal-setting techniques, and the right tools needed for success—from choosing proper running footwear to implementing SAST, DAST, and SIEM systems. Understand how targeted training methodologies like interval training translate to AppSec practices such as threat modeling and security audits. Gain insights into continuous monitoring mechanisms, adaptation strategies for emerging threats, and common pitfalls to avoid. The presentation emphasizes collaboration and knowledge sharing as foundations for success, highlighting how community engagement fosters growth in both fields. Key takeaways include developing the right mindset, setting realistic goals with concrete plans, and enjoying the process—essential elements for running both marathons and effective security programs.
Syllabus
Running Your Application Security Program Like a Marathon - Derek Fang
Taught by
OWASP Foundation