Level 2: Adoption of basic security practices: Regular security training for all
Description:
Conduct security awareness training for all roles currently involved in the management, development, testing, or auditing of the software. The goal is to increase the awareness of application security threats and risks, security best practices, and secure software design principles. Develop training internally or procure it externally. Ideally, deliver training in person so participants can have discussions as a team, but Computer-Based Training (CBT) is also an option.
Course content should include a range of topics relevant to application security and privacy, while remaining accessible to a non-technical audience. Suitable concepts are secure design principles including Least Privilege, Defense-in-Depth, Fail Secure (Safe), Complete Mediation, Session Management, Open Design, and Psychological Acceptability. Additionally, the training should include references to any organization-wide standards, policies, and procedures defined to improve application security. The OWASP Top 10 vulnerabilities should be covered at a high level.
Training is mandatory for all employees and contractors involved with software development and includes an auditable sign-off to demonstrate compliance. Consider incorporating innovative ways of delivery (such as gamification) to maximize its effectiveness and combat desensitization.
Source: OWASP SAMM 2
Risk:
Understanding security is hard.
Measure:
Provide security awareness training for all internal personnel involved in software development on a regular basis like twice in a year for 1-3 days.
Difficulty of Implementation:
Knowledge: High (two disciplines)
Time: Very High
Resources: Medium
Usefulness:
Very High
Implementation:
- OWASP JuiceShop
- Tags
- URL
- https://github.com/bkimminich/juice-shop
- Description
- In case you do not have the budget to hire an external security expert, an option is to use the OWASP JuiceShop on a "hacking Friday"
- OWASP Cheatsheet Series
- Tags
- URL
- https://cheatsheetseries.owasp.org/
- Description
Обязательно
для уровня зрелости
1
2