Against the backdrop of an increasing cadence of compromise, developers cannot afford to continue to apply the same simplistic solutions to the dynamic, multi-dimensional problem, “AppSec”, or software security. Assumptions are provably flawed. Some widely held industry "folklore" is demonstrably incorrect. This session will detail misconceptions and then provide field tested solutions.