
Shuning, Veracode Community Manager (Veracode) asked a question.
Hello Community! 👋
The challenges (and opportunities!) of driving collaboration across security and development present in AppSec programs at any stage. What does the collaboration look like in your organization? Any best practices you’re applying or questions you’re seeking feedback from your fellow members and the Veracode team?
---Suggested Resource---
If that’s a topic you’d like to learn more about, you may find the Spring Virtual Summit helpful - Building a Bridge Between Security & Development. The experts from the Veracode exec team will address:
- What security needs to know about modern software development
- The best practices for nurturing the development/security relationship
- The most effective ways to scan code for security in development
- Lessons learned from real security teams working with developers
Time: May 20, 2020
Register: here (recording is available on-demand)
Bonus: Is there any question you’d like the speakers to address? Share in a comment below and we’ll pass them to the speakers!
.png)
My experience in AppSec since 2005 taught me that empowerment and enablement are the two key fundamental activities that lead to development teams taking responsible for all aspects of their application's security. BEFORE releasing tools and confounding processes to development teams, it's essential that every team member clearly understands the reasoning and the intent of using AppSec tools/processes, so when they're required, there's less resistance (or sabotage). Once people 'get it', things change quickly and people come to the Security Team looking for guidance and assistance in building-in AppSec tools and processes to the DNA of development work. As people gain experience, they often find improvements that they share with the Security Team for promulgation to other teams, and best practices are born. The relationship between development and Security is symbiotic when it's done correctly. The bottom line is that AppSec is a PEOPLE issue so addressing everything in that vein is the fastest path to Appsec compliance, and ultimately, to AppSec success.
Additionally what I find helpful in engaging our "customers" is thinking a lot about their user experience. Trying to not treat them as a ticket to get through and rather go and think about where they are coming from and tailor the information you are getting across in a reasonable and contextual manner.
We are making progress in our organization but we have a ways to go, the security team needs to be flexible and adapt to the development teams methods, each group will want to scan and remediate a little different, if the Security team wants to succeed they will be flexible, issues will get resolved it just might not be in Security time but Development time. I agree with MM in respect to the People issue of appsec.
@MMerkow181566 provides a great response and correctly identifies that appSec is a people issue. I sometimes say "AppSec isn't something you buy, but something you do". Executive backing is imperative as a foundation for building a successful program. It should be a given.
After that, establish good working relationships and be held accountable to common goals and objectives to ensure alignment across security, ops and development. Most important are the different feedback loops. The maturity of an org could be based on feedback and collaboration with the various stakeholders: (1) feedback to executives to show ROI. (2) feedback to development teams for flaws and mitigations. (3) feedback to ops teams for automation, integrations, monitoring and alerting. (4) feedback to product owners to show a more secure, high-quality product.
Lastly, every org is different, so there is no "one size fits all". For larger orgs, a healthy security champion program provides multiplicity and helps to reinforce a security-first mindset on a daily basis to help bridge these gaps. For smaller orgs, we are the program, the champions and the bridge.
Totally agree with @Mark_M (Community Member)'s point. AppSec is a PEOPLE issue.
I would like to share one of our successful experience here. We have some people with developer background in security team. Then, security team and developers review the Veracode findings and discuss the mitigation proposal TOGETHER. Although the application languages/technologies are different, the security concepts and best practices are almost same. As @Mark_M (Community Member) mentioned "Once people get it", the same best practices will be installed in the development team. In the end, we keep our compliance rate above 90% most of time. The collaboration between security team and development teams are also very close. (Of course, we do have the support from the executives. So, the developers can spend certain amount time/resource on secure coding discussion.)