At the most fundamental level, IT security is about buying software, while application security is about building software. The core mission of both groups is bringing risk down to an acceptable level.
SC Media talked with the Zero Day Initiative Director Brian Gorenc about how the project came to be, what the last 15 years have taught him about disclosure, and that time he inadvertently rendered NSA spy tools useless.