Application Security Training Playbook is part of the IBM AppSec Champion Service. It describes the main steps for fast establishment of a Security Champions program regardless of the company size and maturity of the existing security processes.
According to OWASP definition, Security Champions are "active members of a team that may help to make decisions about when to engage the Security Team". They act as a core element of security assurance process within the product or service, and hold the role of the Single Point of Contact (SPOC) within the team.
- Actively participate in the AppSec JIRA and WIKI
- Collaborate with other security champions
- Review impact of 'breaking changes' made in other projects
- Attend weekly meetings
- Are the single point of contact for their assigned team
- Ensure that security is not a blocker on active development or reviews
- Assist in making security decisions for their team
- Empowered to make decisions
- Document decisions made in bugs or wiki
- Work with AppSec team on mitigations strategies
- Help with QA and Testing
- Write Tests (from Unit Tests to Integration tests)
- Help with development of CI (Continuous Integration) environments
Main advantages of having a team of Security Champions:
- Scaling security through multiple teams
- Engaging "non-security" folks
- Establishing the security culture
To keep it simple, I've listed six easy-to-follow steps with clarifications for each step. Chapters include general recommendations, links to known good sources as well as personal experience. I will be happy to hear your feedback and update the playbook. Current version: