---
title: "Getting Started with AppSec"
url: "https://www.armorcode.com/podcast/getting-started-with-appsec"
markdown_url: "https://www.armorcode.com/podcast/getting-started-with-appsec.md"
llm_canonical: "https://www.armorcode.com/podcast/getting-started-with-appsec.md"
canonical_for_llm: true
entity_type: "Article"
primary_entity: "Getting Started with AppSec"
citation_value: "Published on ArmorCode; canonical URL https://www.armorcode.com/podcast/getting-started-with-appsec."
last_updated: "2025-04-14T12:38:52-07:00"
---

<h1>Getting Started with AppSec</h1>

It’s a common misconception that the first step to building an application security program is sorting out the tooling. In reality, security tools translate well, and most early-game head-scratching will center on process. It helps to start small: SCA (source composition analysis) being an un-intensive and non-invasive first measure is a great launch point. This is not only due to the great availability of SCA tools, but also because its ease of adoption primes security teams before they pursue more investigation- and work-heavy practices like SAST, DAST, IAST, etc.
