---
title: "Building a Robust AppSec Program With the OODA Loop Framework"
url: "https://www.armorcode.com/podcast/building-a-robust-appsec-program-with-the-ooda-loop-framework"
markdown_url: "https://www.armorcode.com/podcast/building-a-robust-appsec-program-with-the-ooda-loop-framework.md"
llm_canonical: "https://www.armorcode.com/podcast/building-a-robust-appsec-program-with-the-ooda-loop-framework.md"
canonical_for_llm: true
entity_type: "Article"
primary_entity: "Building a Robust AppSec Program With the OODA Loop Framework"
citation_value: "Published on ArmorCode; canonical URL https://www.armorcode.com/podcast/building-a-robust-appsec-program-with-the-ooda-loop-framework."
last_updated: "2025-02-21T08:01:08-08:00"
---

<h1>Building a Robust AppSec Program With the OODA Loop Framework</h1>

Observe, Orient, Decide, Act. Johnson Controls Product Security Director Brian Pitts walks us through how a framework developed for military applications can help us secure the software kind. OODA puts into letters a process that should be familiar to most security practitioners: 1. collecting data from the environment; 2. contextually assessing findings; 3. prioritizing based on risk context, scores, and/or severity; and 4. taking remedial action. Brian thoughtfully shares a bit of how ArmorCode enables his team at Johnson Controls to painlessly OODA at scale.
