
gwhittemore (Veracode, Inc.) asked a question.
Hello Community!
My name is Glenn, Sr. Solution Architect at Veracode. Think of me as a technical liaison bridging the gap between security, development and operations. It is my pleasure to walk customers through deploying application security testing (AST) solutions through meaningful and practical ways, translating operational success to business success.
Following up on @Mark_M (Community Member) and @Seb! (Veracode)'s discussion earlier this month on what a security champion program can look like, I want to drill into the role as a security champion.
Security champions can take many forms depending on the goals, resources, and culture of your organization. I've seen the security team drive this effort, ensuring there's a security voice represented on each development team. I've also seen developers thrive in this role, being the liaison between their own team and the (often more centralized) security team.
Here are my tips for developers and security professionals to succeed in this role:
- For developers
- Make friends in the security org!
- Raise your hand early when security scanning results don't make sense!
- Challenge tests when the results are in your hands, and don't just throw them back over the wall to security. Ensure accuracy and that the results are actionable.
- If you have experience writing secure code, enable and coach your team members to success.
- Deploy automation testing in the CI pipeline wherever possible!
- Fail fast! That way you know where security defects are before it's too late when you need to go to production.
- For security professionals
- Make friends in the development org!
- Identify critical business applications, start small – no more than 5-10!
- Create a baseline - You don't know what you don't know until you have tested and created a framework to work from. Start with testing against common requirements, including OWASP Top 10 and CWE SANS25.
- Don't just throw the results over the wall to development to fix. Instead, help them, enable them and ensure the team is setup for success. After all, you are on the same team and remediation efforts will be far more successful with open communication channels.
💡 What other tips do you have to be more effective as a security champion?
- Tell us about your functional role, are you a developer or a security professional?
- Do you have a formal role as a security champion that rotates in your company? Or does everyone on the dev/security team is assumed with the responsibilities?
- If you're a developer, what are your tips to keep up with your security knowledge? How do you influence those in your tribe to follow best practices?
- If you're a security professional, how do you think the idea of security champion challenges the status quo of security in the modern SDLC today?
.png)
In my experience, the *right* tips depend on where you are in your security journey.
We have multiple groups, a couple large ones from an acquisition, a primary legacy group that already had an established Security program, and then a new group that has started with a clean slate.
Each different group is in a different state. The new one is in great shape with clearly defined roles, the "right" people selected for Security Champions and great support. The legacy team is well established, with the right people with solid training who know what to do and when and where to do it.
The other two teams are new to the roles of Security Champions and how and where to apply security throughout the SDLC. I am on one of those teams leading a group of new Security Champions. Here are a few things that have made a big difference.
@scrobinson (Community Member) , Thank you so much for a very detailed post. I think we can agree that the *right* tips certainly depend on the security journey. With so many factors to consider (and deciding which ones are really more important than others), the task at hand evolves over time and is certainly not on 'on switch', -thank you for coining that so well! What we can all pull from your post in particular is the insight to TIME matters and people who VOLUNTEER. If organizations are able to make those two ideas common-practice, and truly work together, imagine the work that could be accomplished!
Thank you again for your contribution to the community.
Regards,
Glenn
Another thing that is top of mind for me at the moment and is consistent across the security journey is a way to measure and track progress as a way to communicate both where you are and how far you still have to go towards your goals.
Here are a few ideas, but I'd love to hear others:
Thank you very much for these great ideas! A few others points come to mind:
Within my larger organization there are some teams that are focused solely on security, largely at a high level and enforce the individual teams to adhere to standards and provide guidance.
Within my product's team we have a security group with a few members that is used for approvals in areas like the release pipelines and the like. Other than that, the company does say security is everyone's responsibility. So while there are some that have specialized security specific knowledge within my team, we don't centralize it on a single individual at this time within my team.
My role is a developer on our product team. The best way I've found to stay sharp on security is to continue to expand your skill set in the use of new frameworks for development as they come out. It's easier to see the security benefits that a stack has on offer when you have something to compare it with. If your product has been around for a while and diverse enough, you also have an opportunity to see how the common pitfalls apply and keep those in the back of your mind. There are also a number of processes (Veracode included) that shine light on things that need to be addressed. Your company may consider hiring penetration testing consultants or specialists to help you get ahead which also helps with the accumulation of security knowledge over time.
Thank you @LGordon178543 (Community Member) for your post! It is very refreshing to see your perspective from an active contributor in development, especially from direct product. I like how you put 'security is everyone's responsibility' as a central message, and it is one that is commonly misunderstood and overlooked. When active members of the security and development community help the common business culture understand its importance (it is actually supposed to help not get in the way/cause pain), product to market begins to see great improvements over time and the peace of mind that there are less security defects and/or technical debt to deal with in the future.
We are share the tips every monthly developers meeting
Thank you for the input @dtakeoka029387 (Community Member) ! Curious -- what would you say are the top 3 most helpful tips that you've learned from the meetings so far?
There's a wide variety of terrific answers on this discussion, but one area that's vitally important is to keep the channels of communications WIDE open ALL the time. As much as you can share with the Security Champions as a community reinforces the importance of the role and provides rapid feedback on proposed changes to the program and ideas for other improvements.