
Seb! (Veracode) asked a question.
Hello Community!
My name is Seb and I'm an application security engineer. I'm part of the ASC team at Veracode where we assist with remediating code flaws and helping you get the most out of Veracode tooling.
Application Security is hard.
As I've seen noted in previous Community posts there is a huge people aspect to what we do. Finding flaws is one part of the problem - helping developers to care enough to fix, to learn, to improve security knowledge is a whole different ball game.
To help bring that people element to a successful AppSec programme, security champions is an effective way of turning security interested developers into security evangelists for your organisations. They become a bridge and a multiplier, transferring knowledge to their teams and working with security teams to find better, faster, more secure ways of working.
I know many of you have security champions initiatives, I'm curious:
- How did you stand up your security champions programme?
- How did you find the right individuals?
- How did you mature your programme over time?
🔖 Related Reads
Analyst Report: "Build a Developer Security Champions Program" by Forrester
Takeaways:
- The importance of embedding AppSec where developers need it most
- The need for executive sponsorship and funding for your programme
- Five critical steps to consider when building a programme
.png)
We run a multi-tiered Security Champions program with a few select 'uber' Security Champions from the major products who join us on the AppSec Team of CISO staff members (8 members). Our weekly meetings are to discuss the needs and demands of each Scrum Team's Security Champion, which management has agreed is a mandatory role for someone on the team. We publish the criteria for who makes a 'good' security champion and we support the champions in any ways that they need. As we make changes to the Secure SDLC or Secure Dev Standard, they're the first group that gets to weigh-in on changes to make sure they're implementable changes, and make adjustments to it as needed.
We also support the network of security champions (The AppSec Guild - over 80 members) with monthly meetings, cyber range exercises, and periodic presentations on select topics. Many of the 'user' security champions take on a duty of weekly brown bag lunch meetings for the champions within their product lines. We also encourage role-based training and provide resources for the materials we chose to use for training and we create in-house materials for company-specific controls and implementation guidance.
Our security champions are thought of as liaisons to Information Security and we can help them with any InfoSec needs beyond AppSec. Our network is looked at as the model for how Guilds show operate and we're asked for help when other Guild leaders get stuck or need direction or advice.
Hi @MMerkow181566
Thanks so much for taking the time to give us some insight into your security champions initiative and it’s awesome you have an appsec guild.
I think your spot on with cyber range exercises and presentations. Trying to create a buzz and feed the interest in application security is something that too often missing. And good for you for being a leader in how guilds should operate at your organization. I’ve worked with organizations in the past that have a “best guild of the year” award, I hope your organization is able to recognize the team’s efforts in a similar way.
I’m going to go straight in with a tough question – how do you mange your “pipeline” of new security champions coming in? One of the challenges with tech is how quickly people move on, either to new roles or new companies. I was surprised how much effort I needed to put in to scouting and bring new members into the fold. Do you have a similar challenge?
Thanks for participating!
Seb
Thanks Seb for your response!
In a word -- gently. We try to identify people who seem to have the right attitudes about AppSec and slowly work with them to increase their interest, and ultimately their skills and knowledge about AppSec. Since it's a purely-human issue, we can only move so fast, otherwise we risk chasing off those who could become stellar Sec Champions. We find ways to provide the opportunities for people to 'shine' through regular engagement with dev teams and some of them bubble up to the top and identify themselves as would-be advocates, minimally, then champions over time.
Patience, more than anything, is vital and the process is not too much different than recruiting new employees to the firm.
Does that make sense?
Standing up the program came organically, as the next thing "to do", after finding it impossible to be everywhere at all times!
In a large/global organization establishing security champions as "satellite" appSec resources makes great sense. The program office will never be funded with all the resources and can never have a presence everywhere. Developing the champions who are embedded within these teams can provide transparency between appSec and developers, essentially becoming your liaisons. The best champions take the initiative and step up out of a curiosity and desire to learn about security. Those two traits serve as fuel to fire up a passion for appSec.
I've found some teams are culturally more ready than others when it comes to bubbling up a champion. I think that is ok, as some teams and individuals will adopt things quicker than others. Work with the ones who have the desire, and measure the value a champion provides over non-champion teams. I believe that you "get what you measure". If you can show the value of champions, then it will lead to greater adoption and desire for more teams to want to join, either thru a "gentle nudge" from senior leadership, or from a product owner if the no clear champion emerges on his/her own.
Lastly, keeping the flame fueled appropriately with giving out corporate swag, extra training, or recognizable achievements keeps the passion burning. Another idea that I haven't done yet is to host an "Application Security Summit" where all the Champions meet, get training, share ideas, and have focused security working sessions.