Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

2 Commits
 
 
 
 

Repository files navigation

Intro

Application Security Training Playbook is part of the IBM AppSec Champion Service. It describes the main steps for fast establishment of a Security Champions program regardless of the company size and maturity of the existing security processes.

Who should take part of the Application Security Training?

According to OWASP definition, Security Champions are "active members of a team that may help to make decisions about when to engage the Security Team". They act as a core element of security assurance process within the product or service, and hold the role of the Single Point of Contact (SPOC) within the team.

What is covered in the security training?

  • Actively participate in the AppSec JIRA and WIKI
  • Collaborate with other security champions
  • Review impact of 'breaking changes' made in other projects
  • Attend weekly meetings
  • Are the single point of contact for their assigned team
  • Ensure that security is not a blocker on active development or reviews
  • Assist in making security decisions for their team

Low-Moderate security impact

  • Empowered to make decisions
  • Document decisions made in bugs or wiki

High-Critical security impact

  • Work with AppSec team on mitigations strategies
  • Help with QA and Testing
  • Write Tests (from Unit Tests to Integration tests)
  • Help with development of CI (Continuous Integration) environments

What benefits does Application Security Training bring to a company?

Main advantages of having a team of Security Champions:

  • Scaling security through multiple teams
  • Engaging "non-security" folks
  • Establishing the security culture

Application Security Training Playbook

To keep it simple, I've listed six easy-to-follow steps with clarifications for each step. Chapters include general recommendations, links to known good sources as well as personal experience. I will be happy to hear your feedback and update the playbook. Current version:


Simplified diagram

alt text

About

An approach to application security training for developers and security professionals.

Resources

Stars

2 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors