Gary talks to Cigital\u2019s Chandu Ketkar. With 20+ years of experience as a developer prior to getting into security, Chandu brings a unique and enlightened view to software security. Chandu shares his insight into why developers and security experts struggle to get along, and offers a solution from the world of economics. He also provides lessons from the healthcare industry and aviation that he believes can improve security processes, particularly when it comes to threat modeling and architecture risk analysis. Listen in for Gary and Chandu\u2019s take on threat modeling, risk analysis, the principal-agent paradox, the checklist manifesto and more.\nRelated Links\n\nSoftware [in]security and scaling architecture risk analysis\nMcGraw on assessing medical devices: Security in a new domain\nPrincipal-agent problem\nThe Checklist Manifesto: How to Get Things Right\n Kishori Amonkar, Jaipur Gharana singer\nRaga Rageshree\n\nThe post Show 113: Chandu Ketkar Discusses Software Security Best Practices appeared first on Cigital \xbb The Silver Bullet Security Podcast with Gary McGraw.\nThe post Show 113: Chandu Ketkar Discusses Software Security Best Practices appeared first on Cigital \xbb The Silver Bullet Security Podcast with Gary McGraw.