diff --git a/POC/MKDocs/site/Get_involved.html b/POC/MKDocs/site/Get_involved.html index f408677..f4ae473 100644 --- a/POC/MKDocs/site/Get_involved.html +++ b/POC/MKDocs/site/Get_involved.html @@ -491,8 +491,17 @@ - + @@ -504,6 +513,50 @@ + + + + @@ -715,8 +768,41 @@ - + + @@ -731,22 +817,26 @@ +

Get involved

+

If you are running a Security Champions Program, or starting one, contact us via LinkedIn message!

-

Call for Security Champions Artifacts!

+

Call for Security Champions Artifacts!

The OWASP SCG Committee is looking for contributions in the form of artifacts and interviews. These can be (anonymized) presentations, program documents, or whatever tools have been useful to your organization.

-

For example: -* Program Charters -* KPIs & Metrics -* Training Materials -* Guidelines & Best Practices -* Success Stories & Case Studies -* See more artifact types and their descriptions here!

+

For example:

+

We’re collecting data from companies worldwide that have Security Champions Programs at any stage of maturity (including wishful thinking!). Please contact us (Irfaan Santoe, Marisa Fagan, Aleksandra Kornecka) to set up a time to meet and donate.

-

Collaborate

+

Collaborate

Let’s talk, see where we can help, and most importantly, if you used anything from us, let us know if that worked for you! If you have a platform where we can discuss our Security Champions Program and would like to offer a collaboration or publication, reach out, too! This helps drive the message.

Contact us on LinkedIn to get involved!

-

Updates

+

Updates

Follow us on LinkedIn to get instantly notified of news and publications!

diff --git a/POC/MKDocs/site/search/search_index.js b/POC/MKDocs/site/search/search_index.js index 268c565..2ab30f7 100644 --- a/POC/MKDocs/site/search/search_index.js +++ b/POC/MKDocs/site/search/search_index.js @@ -1 +1 @@ -var __index = {"config":{"lang":["en"],"separator":"[\\s\\-]+","pipeline":["stopWordFilter"]},"docs":[{"location":"index.html","title":"OWASP Security Champions Guide","text":"

Welcome to the home of the OWASP Security Champions Guide Project! Our goal is to create an open-source, vendor-neutral guidebook for AppSec professionals to help them build and improve their own successful Security Champion programs.

One size will not fit all \u2013 so this playbook is designed for you to pick and choose the elements your organization can adopt or leverage to create your own customized program. We will provide customizable artifacts that can be used to start or improve your program. It doesn\u2019t stop there! As your program matures, the playbook will provide you with next steps and new factors for consideration to further empower your program and your champions.

To make this happen, our project team is interviewing security leaders, program coordinators, and security champions to establish what makes a successful program. Participants represent a range of company sizes, industries, geographies, and also different levels of security program maturity. We want to know what works, what doesn\u2019t work, what promotes success, and what leads to failure.

We are looking for more participants to take part in this exciting project. Whatever your experience of Security Champions programs \u2013 good or bad \u2013 we want to hear from you! Especially if you are/have been:

Watch our project launch video here.

We\u2019d love to hear your feedback and ideas. Check out the \u2018Get Involved\u2019 tab for more details.

"},{"location":"Anticipate_personnel_changes.html","title":"Principles","text":""},{"location":"Anticipate_personnel_changes.html#what","title":"What","text":"

The field of information security staffing has undergone significant changes over the last decade. The increased reliance on technology has made Information security skills essential in many industries, leading to a high demand for information security talent and a lot of job opportunities. This high demand and abundance of opportunities has impacted the turn-over rate of staff significantly and companies find it harder to retain information security talent. Therefore, organizations need to anticipate these personnel changes in their organization and their security champions program as they are unavoidable.

"},{"location":"Anticipate_personnel_changes.html#why","title":"Why","text":"

Placing too high of a demand on a limited number of individuals as Security Champions increases the risk of a Security Champions program failing when certain, key, individuals leave the organization or change role within the organization.. Organizations need to acknowledge that people will leave, and ensure this does not bring the continuity of their Security Champions program in danger.

"},{"location":"Anticipate_personnel_changes.html#how","title":"How","text":"

In order to ensure consistency and continuity in the Security Champions the following, complementary, recommendations can be made:

"},{"location":"Be_passionate_about_security.html","title":"Principles","text":""},{"location":"Be_passionate_about_security.html#what","title":"What","text":"

Ensure the people involved in your security champion program are passionate about security. This passion helps to drive the program further and boost the security culture.

"},{"location":"Be_passionate_about_security.html#why","title":"Why","text":"

Being passionate about security is crucial because it creates a mindset where security is not just a compliance requirement, but a fundamental part of how an organization operates. When employees are passionate about security, they are more likely to take ownership of security issues, be proactive about identifying potential risks, and advocate for security best practices throughout the organization.

"},{"location":"Be_passionate_about_security.html#how","title":"How","text":"

Promote security top down and on all levels within your organization. Show security is taken seriously by management and is a key element of the DNA of the company. Then explain the importance of the security champions program within your organization. It should be clear what the program brings and what is expected of the people involved. The employees with passion for security should naturally be attracted to the program and raise their voice. Start with recruiting those volunteers and avoid assigning security champions when possible.

Be sure to enable passionate champions and invest in keeping them onboard. Trigger their curiosity and offer opportunities to keep on growing no matter what level they are on. Ideally, they also drive the program forward and make sure it covers their needs.

Don\u2019t limit yourself to internal recruitment. Highlight the importance of security in your vacancies to attract passionate people that can boost the security culture. Ask candidates about their security experience and see if you can find that spark.

There are lots of opportunities to spark the passion of security champions. This checklist can be used to discover possible touch points and opportunities to do so.

"},{"location":"Create_a_community.html","title":"Principles","text":""},{"location":"Create_a_community.html#what","title":"What","text":"

A community provides a platform for security champions to share knowledge, experiences, challenges, and best practices with each other. A community furthermore helps to foster a culture of security awareness, collaboration, and continuous learning among the security champions and their teams. A community can provide recognition, feedback, and support for the security champions.

"},{"location":"Create_a_community.html#why","title":"Why","text":"

Creating an active and vibrant community of Security Champions is vital to the success of any Security Champions Program and provides an additional channel to scale the security program.

"},{"location":"Create_a_community.html#how","title":"How","text":"

To create a community for a security champions program, the following should be considered:

"},{"location":"Get_involved.html","title":"getinvolved","text":"

If you are running a Security Champions Program, or starting one, contact us via LinkedIn message!

"},{"location":"Get_involved.html#call-for-security-champions-artifacts","title":"Call for Security Champions Artifacts!","text":"

The OWASP SCG Committee is looking for contributions in the form of artifacts and interviews. These can be (anonymized) presentations, program documents, or whatever tools have been useful to your organization.

For example: * Program Charters * KPIs & Metrics * Training Materials * Guidelines & Best Practices * Success Stories & Case Studies * See more artifact types and their descriptions here!

We\u2019re collecting data from companies worldwide that have Security Champions Programs at any stage of maturity (including wishful thinking!). Please contact us (Irfaan Santoe, Marisa Fagan, Aleksandra Kornecka) to set up a time to meet and donate.

"},{"location":"Get_involved.html#collaborate","title":"Collaborate","text":"

Let\u2019s talk, see where we can help, and most importantly, if you used anything from us, let us know if that worked for you! If you have a platform where we can discuss our Security Champions Program and would like to offer a collaboration or publication, reach out, too! This helps drive the message.

Contact us on LinkedIn to get involved!

"},{"location":"Get_involved.html#updates","title":"Updates","text":"

Follow us on LinkedIn to get instantly notified of news and publications!

"},{"location":"Invest_in_your_champions.html","title":"Principles","text":""},{"location":"Invest_in_your_champions.html#what","title":"What","text":"

Invest in the personal growth and development of your Security Champions.

"},{"location":"Invest_in_your_champions.html#why","title":"Why","text":"

Security doesn't come for free and requires investments. These investments also show the organization that security is taken seriously and boost the morale of the Security Champions. Without proper investments, the security program and security culture can quickly degrade.

Security Champions spend a lot of effort in learning, sharing and promoting security in the organization and play an important role in the security culture of a company. Don\u2019t take the motivation of the Security Champions for granted. The organization should invest in them to make sure they feel appreciated and facilitate their development. This ensures the Security Champions community stays healthy and continues to drive the security program.

"},{"location":"Invest_in_your_champions.html#how","title":"How","text":"

By formally allocating time for security activities the Security Champions can combine security work with their other responsibilities. This investment will increase the quality and reduce the amount of rework and incidents.

Allocate budget for webinars, conferences and training to ensure Security Champions can develop and gain new knowledge. These new insights can uncover vulnerabilities and will most likely improve the quality and throughput time of the deliverables. Internal workshops, sessions, training and events are a great way to share knowledge within the organization and get new people excited for security.

Introduce job titles/specialized roles to give recognition to the Security Champions. Bonuses and promotion can be an additional incentive for employees to take security seriously and walk that extra mile.

"},{"location":"Manifesto.html","title":"Manifesto","text":"

The OWASP Security Champions Manifesto is a set of guiding principles crucial to any successful program!!!!

The principles have been drawn from an initial series of in-depth interviews with Application Security leaders from across the globe as part of our wider goal to provide a comprehensive Security Champions playbook.

Go to the \u2018Principles\u2019 tab to find out more about these key principles and how to put them into practice.

The Ten Key Principles for a Successful Security Champions Program

  1. Be passionate about security
  2. Start with a clear vision for your program
  3. Secure management support
  4. Nominate a dedicated captain
  5. Trust your champions
  6. Create a community
  7. Promote knowledge sharing
  8. Reward responsibility
  9. Invest in your champions
  10. Anticipate personnel changes

Prefer a visual? Download your copy of our principles infographic

"},{"location":"Nominate_a_dedicated_captain.html","title":"Principles","text":""},{"location":"Nominate_a_dedicated_captain.html#what","title":"What","text":"

Ensure you have a dedicated Captain to lead the development, implementation and continuous success of a Security Champions Program.

"},{"location":"Nominate_a_dedicated_captain.html#why","title":"Why","text":"

Having a dedicated Captain for a Security Champions Program is important to ensure that the program has a clear strategy and roadmap and is well-organized on a continuous basis. Lack of a dedicated role for this task may lead to people doing it \u201con the side\u201d while our experience and research shows that building and maintaining a Security Champion program is one that requires continuous attention.

Focus points for the dedicated Captain are:

"},{"location":"Nominate_a_dedicated_captain.html#how","title":"How","text":"

The projects teams\u2019 personal experience and interviews we have conducted with organizations that have Security Champions Programs have shown that leading a Security Champions program is a full-time job. In bigger organizations this may even require a small team. It is recommended to \u201cnominate\u201d or hire dedicated people that are passionate about this role and have the right skills set to drive it to ensure success. Having this as an \u201con the side job\u201d takes away from the momentum and dedication needed to launch a successful program. Similarly, persons with security knowledge but lacking the right communication and organizational skills to drive such a program can be a factor in its lack of success.

"},{"location":"Nominate_a_dedicated_captain.html#artefacts","title":"Artefacts","text":"

This job vacancy can be used when looking to hire a dedicated Security Champion Captain.

"},{"location":"Promote_knowledge_sharing.html","title":"Principles","text":""},{"location":"Promote_knowledge_sharing.html#what","title":"What","text":"

Invest in the education of your Security Champions and encourage knowledge sharing within and outside the company.

"},{"location":"Promote_knowledge_sharing.html#why","title":"Why","text":"

Security and technology are continuously evolving. Keeping up with developments requires a mindset of continuously learning. As Security Champions are the security front-runners in their teams and departments they are naturally interested in security related topics and want to learn more. They also know exactly what\u2019s needed to improve their teams. By sharing their knowledge they can improve people, processes and technology. Any feedback during the knowledge sharing sessions can give valuable insights and strengthen the whole community. Additionally, it also ensures the security team is aware of the technology used within the organization and the (security) challenge it incorporates.

"},{"location":"Promote_knowledge_sharing.html#how","title":"How","text":"

Promote a knowledge sharing culture, this is a mindset that values and rewards knowledge sharing among employees. Formal training programs can be rolled out using existing sharing and learning strategies within the company when available. Informal knowledge sharing via lunch sessions and pizza evenings can also be very valuable. Combine this with internal & external events to trigger the interest of your employees but make sure to rotate the speakers and topics to attract the biggest audience. Keep in mind that development teams are more likely to connect to the Security Champions that share something that\u2019s relevant to daily activities.

Gamification can be used to introduce a competitive element in the training and sharing knowledge. Capture the flag events are a great way to trigger the curiosity of your development teams.

"},{"location":"Reward_responsibility.html","title":"Principles","text":""},{"location":"Reward_responsibility.html#what","title":"What","text":"

The principle of \"Reward Responsibility\" involves establishing a system within an organization to recognize and reward the efforts of Security Champions. This system is designed to encompass both tangible and intangible forms of recognition and rewards. It aims to acknowledge the contributions that Security Champions make in enhancing the security posture of the organization, including their dedication, innovations, and proactive measures in managing security-related issues.

"},{"location":"Reward_responsibility.html#why","title":"Why","text":"

Acknowledging and rewarding Security Champions is crucial for several reasons. Firstly, it serves as a significant motivator, encouraging continued enthusiasm and dedication in their roles. When individuals see their efforts being recognized, they are more likely to take ownership and be proactive in their security responsibilities. Additionally, a reward system contributes to the overall effectiveness of the Security Champions program by fostering a positive and encouraging environment. It also plays a key role in talent retention within the program, as it demonstrates the organization's appreciation and value for the commitment and efforts of its Security Champions.

"},{"location":"Reward_responsibility.html#how","title":"How","text":"

To effectively implement this principle, organizations should develop a system that regularly recognizes the efforts of Security Champions. This could include setting up formal recognition programs, offering tangible rewards such as bonuses or professional development opportunities, and providing career advancement possibilities for effective champions. Additionally, regular feedback and expressions of appreciation are essential. Tailoring rewards to individual motivations is also key; some Champions might value public recognition, while others might appreciate personal development opportunities. The system should be designed to align with the organization's culture and policies, ensuring that it is meaningful and sustainable. Please refer to The Star Model \u2122or the PDF for more information on the theory of reward systems.

Supporting Artifacts: * Recognition Certificate Templates: Create customizable certificate templates to formally recognize the contributions of Security Champions. These certificates can be awarded for various achievements, like leading a successful security initiative, completing a significant amount of training, or significantly improving the security posture of a project.

"},{"location":"Secure_management_support.html","title":"Principles","text":""},{"location":"Secure_management_support.html#what","title":"What","text":"

Ensure your security champion program is recognized as a formal program with a set purpose within your organization. This is achieved when you secure management support for the program.

"},{"location":"Secure_management_support.html#why","title":"Why","text":"

A successful security champions program brings unmatchable security benefits to the table. It scales your security mindset and your security organization to the IT Department. Security Champions means that IT engineers are championing security. Doing so requires the IT department and other relevant departments to spend time, effort, and budget to create, nurture and enable the security champions. And this priority will conflict with other IT and Business priorities. Out of experience, we know that when priorities conflict, formalized priorities win the battle. Even the most passionate security champion will struggle to prioritize security over the expected workload. This can lead to frustrations within your security champions and will harm your security champions program.

That is WHY we strongly advise securing management support for your security champion program. This makes the program a formalized priority for the IT Department and thus for the security champions. Security Champions can spend the needed time to improve security without the constant distraction of explaining to IT Leads, Product Owners, and middle management why time is spent on security activities.

"},{"location":"Secure_management_support.html#how","title":"How","text":"

Setting up a Security Champion program requires a thorough analysis of the stakeholders to get the program approved and supported. The Head of IT, to whom the security champions report, is a key stakeholder. This can be the IT department doing Application Development, the IT Department doing Infrastructure Development, or both. Besides the Head of IT, if there is a Security or CISO department, management from that department is also a stakeholder as they set the direction of security and the Security organization. There are views that Security Champions are an extension of that Security Organization. Therefore, the manager of the Security Organization is a key stakeholder in securing management support for your security champions program. Another dimension to consider is when your vision of the security champion program states that being a security champion should be included in the job description of IT Engineers. It is advised to identify HR as a stakeholder.

Once the right stakeholders are identified, it is advised to understand what is essential for them and build your security champion program case around them. For the Head of IT, this would be in the direction of utilizing IT resources optimally, delivering IT fast and with adequate security/risk levels. For the Security Organization (CISO), what makes them tick is that security processes, expectations, and governance are embedded in the champion\u2019s model and a clear articulation of the benefits of having such a Security Champions program on top of the existing organization. Per stakeholders, the benefits should be articulated, including addressing the potential risks they see for their objectives.

Finally, the proposal of the program should be approved by each identified stakeholder, making the program a formal program.

Please see this artifact used by a financial company (bank) to build its case for formalizing the security champion program.

(p.s. In the included artifacts, clear disclaimers are included of the organization's context and why re-consideration is needed when copying and pasting the model to the user\u2019s organization).

"},{"location":"Start_with_a_clear_vision_for_your_program.html","title":"Principles","text":""},{"location":"Start_with_a_clear_vision_for_your_program.html#what","title":"What","text":"

A vision is defined as, \u201cthe act of power of imagination.\u201d When you apply vision to the future, you can create a mental picture that can be used to direct your and your organization\u2019s actions toward achieving security. A vision of security champions program serves as a guide in achieving security in your organization and can be used to provide a sense of purpose for IT engineers doing security.

"},{"location":"Start_with_a_clear_vision_for_your_program.html#why","title":"Why","text":"

Having a vision is critical for your decision-making and the long-term success of your program. It gives your program purpose, and clearly articulates the \u2018why\u2019 and \u2018what\u2019 that you want to see happen and the change you want to achieve. Without a clear end goal or destination from the outset, it will be difficult to create meaningful goals and strategies and make effective decisions.

There are several angles for defining a vision for security champions. The most common angle is that of democratizing security knowledge in the development teams, removing dependencies on the central security team, and governing security in development teams.

"},{"location":"Start_with_a_clear_vision_for_your_program.html#how","title":"How","text":"

A successful vision must be: * Imaginable: Convey a clear picture of what the future will look like. Translating this to your security champions program, you can consider drawing a security operating model with the roles and responsibilities of the security champions, dev(ops) engineers, IT Leads, Product Owner, and security organizations. * Desirable: Appeal to the long-term interest of those who have a stake in the Enterprise. Translating this to your security champions program, you should consider describing the benefits of embedding security in the development team through a security champion, with mandate, knowledge, and skills to do security. * Feasible: Describe realistic and attainable goals. For your security champions program include goals like \u201chours spent on security by the champion\u201d, \u201ctraining objectives of the champion\u201d, \u201d the number of security champions meet-ups\u201d, \u201cthe decrease of security risk\u201d, etc. * Focused: The vision should be clear enough to provide guidance in decision-making. What are the boundaries of security champions, what are commitments towards the program by senior management and what are expectations towards security champions? Is the scope of security champions to secure the entire enterprise? What is their role within the development team? What is their role compared to that of the Security Organization? * Communicable: A vision is easy to communicate and can be explained quickly. Don\u2019t write several pages of vision. A picture showing how security champions are enabling your goals in security and IT development will go a long way.

Please note that it is not advised to create your vision in isolation. By involving as many key stakeholders as possible, you\u2019ll enable people to take greater ownership of the vision and increase commitment. Think about IT Leads, POs, senior developers, and security leaders to be part of this vision creation process. Once the vision is in a good draft, give it a try by explaining and selling to within your organization (senior management, developer community etc).

"},{"location":"Trust_your_champions.html","title":"Principles","text":""},{"location":"Trust_your_champions.html#what","title":"What","text":"

Trusting your champions is key to a successful Security Champions program. They are the eyes and ears of the organization and know exactly what their department\u2019s security needs are.

"},{"location":"Trust_your_champions.html#why","title":"Why","text":"

The Security Champions are the experts in their working area. A security team can never achieve that level of knowledge of the applications as they are not involved in the operational work. Using their expertise to set up the Security Champions program will increase the likelihood of success.

When making people responsible, it is key to allow them to understand and act according to the defined role. It will increase speed, but also increase involvement. Ideally the Security Champions co-own the program and strongly influence the direction and content. They can identify shortcomings and propose changes or give practical feedback on the matter.

Teams are more likely to trust their own champions as they are \u201cone of their own\u201d and not an \u201coutsider\u201d from the Security Team. They speak the same language and understand the context. This will lead to more effective communication, better collaboration and reduced resistance to change.

In summary, trust is the glue that holds a Security Champions Program together.

"},{"location":"Trust_your_champions.html#how","title":"How","text":"

Trust is all about setting clear expectations. It should be clear to everyone involved what the Security Champions\u2019 role is about and what their mandate is. Don\u2019t be afraid to let your champions experiment with different approaches. Their lessons learned can be a valuable input to other departments, sharing is caring!

Give your Security Champions the mandate to make decisions on security within the risk appetite of your organization. By being in control and removing inefficiencies, they can add a lot of value to their teams and increase the security adoption & awareness. Do make sure they share their approach and reasoning to make sure the Security Champions can learn from each other and give constructive feedback.This way the organization can improve security related initiatives, decision making and processes..

Also involve the security champions in the processes of the core security team. Seek their input and opinions on security initiatives, policies, and practices to make them feel valued as active contributors. Use their feedback to improve the program, processes, and procedures.

Measure and showcase the impact that the Security Champions and the program make. Demonstrate how their efforts have positively influenced security outcomes, highlighting the value they bring to the organization. This will build up the Security Champions\u2019 trustworthiness and boost morale.

"},{"location":"blog/index.html","title":"Blog","text":""},{"location":"blog/2024/05/01/the-first-blog-post.html","title":"The first blog post!","text":"

Our very own blog post on the OWASP Security Champions guide!

","tags":["blog","guide"]},{"location":"blog/2024/06/04/the-second-blog-post.html","title":"The second blog post!","text":"

And another blog post on the OWASP Security Champions guide!

Check out the new artefacts for principle X!

","tags":["blog","guide"]},{"location":"blog/archive/2024.html","title":"June 2024","text":""},{"location":"blog/category/news.html","title":"News","text":""},{"location":"blog/category/welcome.html","title":"Welcome","text":""}]} \ No newline at end of file +var __index = {"config":{"lang":["en"],"separator":"[\\s\\-]+","pipeline":["stopWordFilter"]},"docs":[{"location":"index.html","title":"OWASP Security Champions Guide","text":"

Welcome to the home of the OWASP Security Champions Guide Project! Our goal is to create an open-source, vendor-neutral guidebook for AppSec professionals to help them build and improve their own successful Security Champion programs.

One size will not fit all \u2013 so this playbook is designed for you to pick and choose the elements your organization can adopt or leverage to create your own customized program. We will provide customizable artifacts that can be used to start or improve your program. It doesn\u2019t stop there! As your program matures, the playbook will provide you with next steps and new factors for consideration to further empower your program and your champions.

To make this happen, our project team is interviewing security leaders, program coordinators, and security champions to establish what makes a successful program. Participants represent a range of company sizes, industries, geographies, and also different levels of security program maturity. We want to know what works, what doesn\u2019t work, what promotes success, and what leads to failure.

We are looking for more participants to take part in this exciting project. Whatever your experience of Security Champions programs \u2013 good or bad \u2013 we want to hear from you! Especially if you are/have been:

Watch our project launch video here.

We\u2019d love to hear your feedback and ideas. Check out the \u2018Get Involved\u2019 tab for more details.

"},{"location":"Anticipate_personnel_changes.html","title":"Principles","text":""},{"location":"Anticipate_personnel_changes.html#what","title":"What","text":"

The field of information security staffing has undergone significant changes over the last decade. The increased reliance on technology has made Information security skills essential in many industries, leading to a high demand for information security talent and a lot of job opportunities. This high demand and abundance of opportunities has impacted the turn-over rate of staff significantly and companies find it harder to retain information security talent. Therefore, organizations need to anticipate these personnel changes in their organization and their security champions program as they are unavoidable.

"},{"location":"Anticipate_personnel_changes.html#why","title":"Why","text":"

Placing too high of a demand on a limited number of individuals as Security Champions increases the risk of a Security Champions program failing when certain, key, individuals leave the organization or change role within the organization.. Organizations need to acknowledge that people will leave, and ensure this does not bring the continuity of their Security Champions program in danger.

"},{"location":"Anticipate_personnel_changes.html#how","title":"How","text":"

In order to ensure consistency and continuity in the Security Champions the following, complementary, recommendations can be made:

"},{"location":"Be_passionate_about_security.html","title":"Principles","text":""},{"location":"Be_passionate_about_security.html#what","title":"What","text":"

Ensure the people involved in your security champion program are passionate about security. This passion helps to drive the program further and boost the security culture.

"},{"location":"Be_passionate_about_security.html#why","title":"Why","text":"

Being passionate about security is crucial because it creates a mindset where security is not just a compliance requirement, but a fundamental part of how an organization operates. When employees are passionate about security, they are more likely to take ownership of security issues, be proactive about identifying potential risks, and advocate for security best practices throughout the organization.

"},{"location":"Be_passionate_about_security.html#how","title":"How","text":"

Promote security top down and on all levels within your organization. Show security is taken seriously by management and is a key element of the DNA of the company. Then explain the importance of the security champions program within your organization. It should be clear what the program brings and what is expected of the people involved. The employees with passion for security should naturally be attracted to the program and raise their voice. Start with recruiting those volunteers and avoid assigning security champions when possible.

Be sure to enable passionate champions and invest in keeping them onboard. Trigger their curiosity and offer opportunities to keep on growing no matter what level they are on. Ideally, they also drive the program forward and make sure it covers their needs.

Don\u2019t limit yourself to internal recruitment. Highlight the importance of security in your vacancies to attract passionate people that can boost the security culture. Ask candidates about their security experience and see if you can find that spark.

There are lots of opportunities to spark the passion of security champions. This checklist can be used to discover possible touch points and opportunities to do so.

"},{"location":"Create_a_community.html","title":"Principles","text":""},{"location":"Create_a_community.html#what","title":"What","text":"

A community provides a platform for security champions to share knowledge, experiences, challenges, and best practices with each other. A community furthermore helps to foster a culture of security awareness, collaboration, and continuous learning among the security champions and their teams. A community can provide recognition, feedback, and support for the security champions.

"},{"location":"Create_a_community.html#why","title":"Why","text":"

Creating an active and vibrant community of Security Champions is vital to the success of any Security Champions Program and provides an additional channel to scale the security program.

"},{"location":"Create_a_community.html#how","title":"How","text":"

To create a community for a security champions program, the following should be considered:

"},{"location":"Get_involved.html","title":"getinvolved","text":"

If you are running a Security Champions Program, or starting one, contact us via LinkedIn message!

"},{"location":"Get_involved.html#call-for-security-champions-artifacts","title":"Call for Security Champions Artifacts!","text":"

The OWASP SCG Committee is looking for contributions in the form of artifacts and interviews. These can be (anonymized) presentations, program documents, or whatever tools have been useful to your organization.

For example:

We\u2019re collecting data from companies worldwide that have Security Champions Programs at any stage of maturity (including wishful thinking!). Please contact us (Irfaan Santoe, Marisa Fagan, Aleksandra Kornecka) to set up a time to meet and donate.

"},{"location":"Get_involved.html#collaborate","title":"Collaborate","text":"

Let\u2019s talk, see where we can help, and most importantly, if you used anything from us, let us know if that worked for you! If you have a platform where we can discuss our Security Champions Program and would like to offer a collaboration or publication, reach out, too! This helps drive the message.

Contact us on LinkedIn to get involved!

"},{"location":"Get_involved.html#updates","title":"Updates","text":"

Follow us on LinkedIn to get instantly notified of news and publications!

"},{"location":"Invest_in_your_champions.html","title":"Principles","text":""},{"location":"Invest_in_your_champions.html#what","title":"What","text":"

Invest in the personal growth and development of your Security Champions.

"},{"location":"Invest_in_your_champions.html#why","title":"Why","text":"

Security doesn't come for free and requires investments. These investments also show the organization that security is taken seriously and boost the morale of the Security Champions. Without proper investments, the security program and security culture can quickly degrade.

Security Champions spend a lot of effort in learning, sharing and promoting security in the organization and play an important role in the security culture of a company. Don\u2019t take the motivation of the Security Champions for granted. The organization should invest in them to make sure they feel appreciated and facilitate their development. This ensures the Security Champions community stays healthy and continues to drive the security program.

"},{"location":"Invest_in_your_champions.html#how","title":"How","text":"

By formally allocating time for security activities the Security Champions can combine security work with their other responsibilities. This investment will increase the quality and reduce the amount of rework and incidents.

Allocate budget for webinars, conferences and training to ensure Security Champions can develop and gain new knowledge. These new insights can uncover vulnerabilities and will most likely improve the quality and throughput time of the deliverables. Internal workshops, sessions, training and events are a great way to share knowledge within the organization and get new people excited for security.

Introduce job titles/specialized roles to give recognition to the Security Champions. Bonuses and promotion can be an additional incentive for employees to take security seriously and walk that extra mile.

"},{"location":"Manifesto.html","title":"Manifesto","text":"

The OWASP Security Champions Manifesto is a set of guiding principles crucial to any successful program!!!!

The principles have been drawn from an initial series of in-depth interviews with Application Security leaders from across the globe as part of our wider goal to provide a comprehensive Security Champions playbook.

Go to the \u2018Principles\u2019 tab to find out more about these key principles and how to put them into practice.

The Ten Key Principles for a Successful Security Champions Program

  1. Be passionate about security
  2. Start with a clear vision for your program
  3. Secure management support
  4. Nominate a dedicated captain
  5. Trust your champions
  6. Create a community
  7. Promote knowledge sharing
  8. Reward responsibility
  9. Invest in your champions
  10. Anticipate personnel changes

Prefer a visual? Download your copy of our principles infographic

"},{"location":"Nominate_a_dedicated_captain.html","title":"Principles","text":""},{"location":"Nominate_a_dedicated_captain.html#what","title":"What","text":"

Ensure you have a dedicated Captain to lead the development, implementation and continuous success of a Security Champions Program.

"},{"location":"Nominate_a_dedicated_captain.html#why","title":"Why","text":"

Having a dedicated Captain for a Security Champions Program is important to ensure that the program has a clear strategy and roadmap and is well-organized on a continuous basis. Lack of a dedicated role for this task may lead to people doing it \u201con the side\u201d while our experience and research shows that building and maintaining a Security Champion program is one that requires continuous attention.

Focus points for the dedicated Captain are:

"},{"location":"Nominate_a_dedicated_captain.html#how","title":"How","text":"

The projects teams\u2019 personal experience and interviews we have conducted with organizations that have Security Champions Programs have shown that leading a Security Champions program is a full-time job. In bigger organizations this may even require a small team. It is recommended to \u201cnominate\u201d or hire dedicated people that are passionate about this role and have the right skills set to drive it to ensure success. Having this as an \u201con the side job\u201d takes away from the momentum and dedication needed to launch a successful program. Similarly, persons with security knowledge but lacking the right communication and organizational skills to drive such a program can be a factor in its lack of success.

"},{"location":"Nominate_a_dedicated_captain.html#artefacts","title":"Artefacts","text":"

This job vacancy can be used when looking to hire a dedicated Security Champion Captain.

"},{"location":"Promote_knowledge_sharing.html","title":"Principles","text":""},{"location":"Promote_knowledge_sharing.html#what","title":"What","text":"

Invest in the education of your Security Champions and encourage knowledge sharing within and outside the company.

"},{"location":"Promote_knowledge_sharing.html#why","title":"Why","text":"

Security and technology are continuously evolving. Keeping up with developments requires a mindset of continuously learning. As Security Champions are the security front-runners in their teams and departments they are naturally interested in security related topics and want to learn more. They also know exactly what\u2019s needed to improve their teams. By sharing their knowledge they can improve people, processes and technology. Any feedback during the knowledge sharing sessions can give valuable insights and strengthen the whole community. Additionally, it also ensures the security team is aware of the technology used within the organization and the (security) challenge it incorporates.

"},{"location":"Promote_knowledge_sharing.html#how","title":"How","text":"

Promote a knowledge sharing culture, this is a mindset that values and rewards knowledge sharing among employees. Formal training programs can be rolled out using existing sharing and learning strategies within the company when available. Informal knowledge sharing via lunch sessions and pizza evenings can also be very valuable. Combine this with internal & external events to trigger the interest of your employees but make sure to rotate the speakers and topics to attract the biggest audience. Keep in mind that development teams are more likely to connect to the Security Champions that share something that\u2019s relevant to daily activities.

Gamification can be used to introduce a competitive element in the training and sharing knowledge. Capture the flag events are a great way to trigger the curiosity of your development teams.

"},{"location":"Reward_responsibility.html","title":"Principles","text":""},{"location":"Reward_responsibility.html#what","title":"What","text":"

The principle of \"Reward Responsibility\" involves establishing a system within an organization to recognize and reward the efforts of Security Champions. This system is designed to encompass both tangible and intangible forms of recognition and rewards. It aims to acknowledge the contributions that Security Champions make in enhancing the security posture of the organization, including their dedication, innovations, and proactive measures in managing security-related issues.

"},{"location":"Reward_responsibility.html#why","title":"Why","text":"

Acknowledging and rewarding Security Champions is crucial for several reasons. Firstly, it serves as a significant motivator, encouraging continued enthusiasm and dedication in their roles. When individuals see their efforts being recognized, they are more likely to take ownership and be proactive in their security responsibilities. Additionally, a reward system contributes to the overall effectiveness of the Security Champions program by fostering a positive and encouraging environment. It also plays a key role in talent retention within the program, as it demonstrates the organization's appreciation and value for the commitment and efforts of its Security Champions.

"},{"location":"Reward_responsibility.html#how","title":"How","text":"

To effectively implement this principle, organizations should develop a system that regularly recognizes the efforts of Security Champions. This could include setting up formal recognition programs, offering tangible rewards such as bonuses or professional development opportunities, and providing career advancement possibilities for effective champions. Additionally, regular feedback and expressions of appreciation are essential. Tailoring rewards to individual motivations is also key; some Champions might value public recognition, while others might appreciate personal development opportunities. The system should be designed to align with the organization's culture and policies, ensuring that it is meaningful and sustainable. Please refer to The Star Model \u2122or the PDF for more information on the theory of reward systems.

Supporting Artifacts: * Recognition Certificate Templates: Create customizable certificate templates to formally recognize the contributions of Security Champions. These certificates can be awarded for various achievements, like leading a successful security initiative, completing a significant amount of training, or significantly improving the security posture of a project.

"},{"location":"Secure_management_support.html","title":"Principles","text":""},{"location":"Secure_management_support.html#what","title":"What","text":"

Ensure your security champion program is recognized as a formal program with a set purpose within your organization. This is achieved when you secure management support for the program.

"},{"location":"Secure_management_support.html#why","title":"Why","text":"

A successful security champions program brings unmatchable security benefits to the table. It scales your security mindset and your security organization to the IT Department. Security Champions means that IT engineers are championing security. Doing so requires the IT department and other relevant departments to spend time, effort, and budget to create, nurture and enable the security champions. And this priority will conflict with other IT and Business priorities. Out of experience, we know that when priorities conflict, formalized priorities win the battle. Even the most passionate security champion will struggle to prioritize security over the expected workload. This can lead to frustrations within your security champions and will harm your security champions program.

That is WHY we strongly advise securing management support for your security champion program. This makes the program a formalized priority for the IT Department and thus for the security champions. Security Champions can spend the needed time to improve security without the constant distraction of explaining to IT Leads, Product Owners, and middle management why time is spent on security activities.

"},{"location":"Secure_management_support.html#how","title":"How","text":"

Setting up a Security Champion program requires a thorough analysis of the stakeholders to get the program approved and supported. The Head of IT, to whom the security champions report, is a key stakeholder. This can be the IT department doing Application Development, the IT Department doing Infrastructure Development, or both. Besides the Head of IT, if there is a Security or CISO department, management from that department is also a stakeholder as they set the direction of security and the Security organization. There are views that Security Champions are an extension of that Security Organization. Therefore, the manager of the Security Organization is a key stakeholder in securing management support for your security champions program. Another dimension to consider is when your vision of the security champion program states that being a security champion should be included in the job description of IT Engineers. It is advised to identify HR as a stakeholder.

Once the right stakeholders are identified, it is advised to understand what is essential for them and build your security champion program case around them. For the Head of IT, this would be in the direction of utilizing IT resources optimally, delivering IT fast and with adequate security/risk levels. For the Security Organization (CISO), what makes them tick is that security processes, expectations, and governance are embedded in the champion\u2019s model and a clear articulation of the benefits of having such a Security Champions program on top of the existing organization. Per stakeholders, the benefits should be articulated, including addressing the potential risks they see for their objectives.

Finally, the proposal of the program should be approved by each identified stakeholder, making the program a formal program.

Please see this artifact used by a financial company (bank) to build its case for formalizing the security champion program.

(p.s. In the included artifacts, clear disclaimers are included of the organization's context and why re-consideration is needed when copying and pasting the model to the user\u2019s organization).

"},{"location":"Start_with_a_clear_vision_for_your_program.html","title":"Principles","text":""},{"location":"Start_with_a_clear_vision_for_your_program.html#what","title":"What","text":"

A vision is defined as, \u201cthe act of power of imagination.\u201d When you apply vision to the future, you can create a mental picture that can be used to direct your and your organization\u2019s actions toward achieving security. A vision of security champions program serves as a guide in achieving security in your organization and can be used to provide a sense of purpose for IT engineers doing security.

"},{"location":"Start_with_a_clear_vision_for_your_program.html#why","title":"Why","text":"

Having a vision is critical for your decision-making and the long-term success of your program. It gives your program purpose, and clearly articulates the \u2018why\u2019 and \u2018what\u2019 that you want to see happen and the change you want to achieve. Without a clear end goal or destination from the outset, it will be difficult to create meaningful goals and strategies and make effective decisions.

There are several angles for defining a vision for security champions. The most common angle is that of democratizing security knowledge in the development teams, removing dependencies on the central security team, and governing security in development teams.

"},{"location":"Start_with_a_clear_vision_for_your_program.html#how","title":"How","text":"

A successful vision must be: * Imaginable: Convey a clear picture of what the future will look like. Translating this to your security champions program, you can consider drawing a security operating model with the roles and responsibilities of the security champions, dev(ops) engineers, IT Leads, Product Owner, and security organizations. * Desirable: Appeal to the long-term interest of those who have a stake in the Enterprise. Translating this to your security champions program, you should consider describing the benefits of embedding security in the development team through a security champion, with mandate, knowledge, and skills to do security. * Feasible: Describe realistic and attainable goals. For your security champions program include goals like \u201chours spent on security by the champion\u201d, \u201ctraining objectives of the champion\u201d, \u201d the number of security champions meet-ups\u201d, \u201cthe decrease of security risk\u201d, etc. * Focused: The vision should be clear enough to provide guidance in decision-making. What are the boundaries of security champions, what are commitments towards the program by senior management and what are expectations towards security champions? Is the scope of security champions to secure the entire enterprise? What is their role within the development team? What is their role compared to that of the Security Organization? * Communicable: A vision is easy to communicate and can be explained quickly. Don\u2019t write several pages of vision. A picture showing how security champions are enabling your goals in security and IT development will go a long way.

Please note that it is not advised to create your vision in isolation. By involving as many key stakeholders as possible, you\u2019ll enable people to take greater ownership of the vision and increase commitment. Think about IT Leads, POs, senior developers, and security leaders to be part of this vision creation process. Once the vision is in a good draft, give it a try by explaining and selling to within your organization (senior management, developer community etc).

"},{"location":"Trust_your_champions.html","title":"Principles","text":""},{"location":"Trust_your_champions.html#what","title":"What","text":"

Trusting your champions is key to a successful Security Champions program. They are the eyes and ears of the organization and know exactly what their department\u2019s security needs are.

"},{"location":"Trust_your_champions.html#why","title":"Why","text":"

The Security Champions are the experts in their working area. A security team can never achieve that level of knowledge of the applications as they are not involved in the operational work. Using their expertise to set up the Security Champions program will increase the likelihood of success.

When making people responsible, it is key to allow them to understand and act according to the defined role. It will increase speed, but also increase involvement. Ideally the Security Champions co-own the program and strongly influence the direction and content. They can identify shortcomings and propose changes or give practical feedback on the matter.

Teams are more likely to trust their own champions as they are \u201cone of their own\u201d and not an \u201coutsider\u201d from the Security Team. They speak the same language and understand the context. This will lead to more effective communication, better collaboration and reduced resistance to change.

In summary, trust is the glue that holds a Security Champions Program together.

"},{"location":"Trust_your_champions.html#how","title":"How","text":"

Trust is all about setting clear expectations. It should be clear to everyone involved what the Security Champions\u2019 role is about and what their mandate is. Don\u2019t be afraid to let your champions experiment with different approaches. Their lessons learned can be a valuable input to other departments, sharing is caring!

Give your Security Champions the mandate to make decisions on security within the risk appetite of your organization. By being in control and removing inefficiencies, they can add a lot of value to their teams and increase the security adoption & awareness. Do make sure they share their approach and reasoning to make sure the Security Champions can learn from each other and give constructive feedback.This way the organization can improve security related initiatives, decision making and processes..

Also involve the security champions in the processes of the core security team. Seek their input and opinions on security initiatives, policies, and practices to make them feel valued as active contributors. Use their feedback to improve the program, processes, and procedures.

Measure and showcase the impact that the Security Champions and the program make. Demonstrate how their efforts have positively influenced security outcomes, highlighting the value they bring to the organization. This will build up the Security Champions\u2019 trustworthiness and boost morale.

"},{"location":"blog/index.html","title":"Blog","text":""},{"location":"blog/2024/05/01/the-first-blog-post.html","title":"The first blog post!","text":"

Our very own blog post on the OWASP Security Champions guide!

","tags":["blog","guide"]},{"location":"blog/2024/06/04/the-second-blog-post.html","title":"The second blog post!","text":"

And another blog post on the OWASP Security Champions guide!

Check out the new artefacts for principle X!

","tags":["blog","guide"]},{"location":"blog/archive/2024.html","title":"June 2024","text":""},{"location":"blog/category/news.html","title":"News","text":""},{"location":"blog/category/welcome.html","title":"Welcome","text":""}]} \ No newline at end of file diff --git a/POC/MKDocs/site/search/search_index.json b/POC/MKDocs/site/search/search_index.json index 8f7e613..82c7ab2 100644 --- a/POC/MKDocs/site/search/search_index.json +++ b/POC/MKDocs/site/search/search_index.json @@ -1 +1 @@ -{"config":{"lang":["en"],"separator":"[\\s\\-]+","pipeline":["stopWordFilter"]},"docs":[{"location":"index.html","title":"OWASP Security Champions Guide","text":"

Welcome to the home of the OWASP Security Champions Guide Project! Our goal is to create an open-source, vendor-neutral guidebook for AppSec professionals to help them build and improve their own successful Security Champion programs.

One size will not fit all \u2013 so this playbook is designed for you to pick and choose the elements your organization can adopt or leverage to create your own customized program. We will provide customizable artifacts that can be used to start or improve your program. It doesn\u2019t stop there! As your program matures, the playbook will provide you with next steps and new factors for consideration to further empower your program and your champions.

To make this happen, our project team is interviewing security leaders, program coordinators, and security champions to establish what makes a successful program. Participants represent a range of company sizes, industries, geographies, and also different levels of security program maturity. We want to know what works, what doesn\u2019t work, what promotes success, and what leads to failure.

We are looking for more participants to take part in this exciting project. Whatever your experience of Security Champions programs \u2013 good or bad \u2013 we want to hear from you! Especially if you are/have been:

Watch our project launch video here.

We\u2019d love to hear your feedback and ideas. Check out the \u2018Get Involved\u2019 tab for more details.

"},{"location":"Anticipate_personnel_changes.html","title":"Principles","text":""},{"location":"Anticipate_personnel_changes.html#what","title":"What","text":"

The field of information security staffing has undergone significant changes over the last decade. The increased reliance on technology has made Information security skills essential in many industries, leading to a high demand for information security talent and a lot of job opportunities. This high demand and abundance of opportunities has impacted the turn-over rate of staff significantly and companies find it harder to retain information security talent. Therefore, organizations need to anticipate these personnel changes in their organization and their security champions program as they are unavoidable.

"},{"location":"Anticipate_personnel_changes.html#why","title":"Why","text":"

Placing too high of a demand on a limited number of individuals as Security Champions increases the risk of a Security Champions program failing when certain, key, individuals leave the organization or change role within the organization.. Organizations need to acknowledge that people will leave, and ensure this does not bring the continuity of their Security Champions program in danger.

"},{"location":"Anticipate_personnel_changes.html#how","title":"How","text":"

In order to ensure consistency and continuity in the Security Champions the following, complementary, recommendations can be made:

"},{"location":"Be_passionate_about_security.html","title":"Principles","text":""},{"location":"Be_passionate_about_security.html#what","title":"What","text":"

Ensure the people involved in your security champion program are passionate about security. This passion helps to drive the program further and boost the security culture.

"},{"location":"Be_passionate_about_security.html#why","title":"Why","text":"

Being passionate about security is crucial because it creates a mindset where security is not just a compliance requirement, but a fundamental part of how an organization operates. When employees are passionate about security, they are more likely to take ownership of security issues, be proactive about identifying potential risks, and advocate for security best practices throughout the organization.

"},{"location":"Be_passionate_about_security.html#how","title":"How","text":"

Promote security top down and on all levels within your organization. Show security is taken seriously by management and is a key element of the DNA of the company. Then explain the importance of the security champions program within your organization. It should be clear what the program brings and what is expected of the people involved. The employees with passion for security should naturally be attracted to the program and raise their voice. Start with recruiting those volunteers and avoid assigning security champions when possible.

Be sure to enable passionate champions and invest in keeping them onboard. Trigger their curiosity and offer opportunities to keep on growing no matter what level they are on. Ideally, they also drive the program forward and make sure it covers their needs.

Don\u2019t limit yourself to internal recruitment. Highlight the importance of security in your vacancies to attract passionate people that can boost the security culture. Ask candidates about their security experience and see if you can find that spark.

There are lots of opportunities to spark the passion of security champions. This checklist can be used to discover possible touch points and opportunities to do so.

"},{"location":"Create_a_community.html","title":"Principles","text":""},{"location":"Create_a_community.html#what","title":"What","text":"

A community provides a platform for security champions to share knowledge, experiences, challenges, and best practices with each other. A community furthermore helps to foster a culture of security awareness, collaboration, and continuous learning among the security champions and their teams. A community can provide recognition, feedback, and support for the security champions.

"},{"location":"Create_a_community.html#why","title":"Why","text":"

Creating an active and vibrant community of Security Champions is vital to the success of any Security Champions Program and provides an additional channel to scale the security program.

"},{"location":"Create_a_community.html#how","title":"How","text":"

To create a community for a security champions program, the following should be considered:

"},{"location":"Get_involved.html","title":"getinvolved","text":"

If you are running a Security Champions Program, or starting one, contact us via LinkedIn message!

"},{"location":"Get_involved.html#call-for-security-champions-artifacts","title":"Call for Security Champions Artifacts!","text":"

The OWASP SCG Committee is looking for contributions in the form of artifacts and interviews. These can be (anonymized) presentations, program documents, or whatever tools have been useful to your organization.

For example: * Program Charters * KPIs & Metrics * Training Materials * Guidelines & Best Practices * Success Stories & Case Studies * See more artifact types and their descriptions here!

We\u2019re collecting data from companies worldwide that have Security Champions Programs at any stage of maturity (including wishful thinking!). Please contact us (Irfaan Santoe, Marisa Fagan, Aleksandra Kornecka) to set up a time to meet and donate.

"},{"location":"Get_involved.html#collaborate","title":"Collaborate","text":"

Let\u2019s talk, see where we can help, and most importantly, if you used anything from us, let us know if that worked for you! If you have a platform where we can discuss our Security Champions Program and would like to offer a collaboration or publication, reach out, too! This helps drive the message.

Contact us on LinkedIn to get involved!

"},{"location":"Get_involved.html#updates","title":"Updates","text":"

Follow us on LinkedIn to get instantly notified of news and publications!

"},{"location":"Invest_in_your_champions.html","title":"Principles","text":""},{"location":"Invest_in_your_champions.html#what","title":"What","text":"

Invest in the personal growth and development of your Security Champions.

"},{"location":"Invest_in_your_champions.html#why","title":"Why","text":"

Security doesn't come for free and requires investments. These investments also show the organization that security is taken seriously and boost the morale of the Security Champions. Without proper investments, the security program and security culture can quickly degrade.

Security Champions spend a lot of effort in learning, sharing and promoting security in the organization and play an important role in the security culture of a company. Don\u2019t take the motivation of the Security Champions for granted. The organization should invest in them to make sure they feel appreciated and facilitate their development. This ensures the Security Champions community stays healthy and continues to drive the security program.

"},{"location":"Invest_in_your_champions.html#how","title":"How","text":"

By formally allocating time for security activities the Security Champions can combine security work with their other responsibilities. This investment will increase the quality and reduce the amount of rework and incidents.

Allocate budget for webinars, conferences and training to ensure Security Champions can develop and gain new knowledge. These new insights can uncover vulnerabilities and will most likely improve the quality and throughput time of the deliverables. Internal workshops, sessions, training and events are a great way to share knowledge within the organization and get new people excited for security.

Introduce job titles/specialized roles to give recognition to the Security Champions. Bonuses and promotion can be an additional incentive for employees to take security seriously and walk that extra mile.

"},{"location":"Manifesto.html","title":"Manifesto","text":"

The OWASP Security Champions Manifesto is a set of guiding principles crucial to any successful program!!!!

The principles have been drawn from an initial series of in-depth interviews with Application Security leaders from across the globe as part of our wider goal to provide a comprehensive Security Champions playbook.

Go to the \u2018Principles\u2019 tab to find out more about these key principles and how to put them into practice.

The Ten Key Principles for a Successful Security Champions Program

  1. Be passionate about security
  2. Start with a clear vision for your program
  3. Secure management support
  4. Nominate a dedicated captain
  5. Trust your champions
  6. Create a community
  7. Promote knowledge sharing
  8. Reward responsibility
  9. Invest in your champions
  10. Anticipate personnel changes

Prefer a visual? Download your copy of our principles infographic

"},{"location":"Nominate_a_dedicated_captain.html","title":"Principles","text":""},{"location":"Nominate_a_dedicated_captain.html#what","title":"What","text":"

Ensure you have a dedicated Captain to lead the development, implementation and continuous success of a Security Champions Program.

"},{"location":"Nominate_a_dedicated_captain.html#why","title":"Why","text":"

Having a dedicated Captain for a Security Champions Program is important to ensure that the program has a clear strategy and roadmap and is well-organized on a continuous basis. Lack of a dedicated role for this task may lead to people doing it \u201con the side\u201d while our experience and research shows that building and maintaining a Security Champion program is one that requires continuous attention.

Focus points for the dedicated Captain are:

"},{"location":"Nominate_a_dedicated_captain.html#how","title":"How","text":"

The projects teams\u2019 personal experience and interviews we have conducted with organizations that have Security Champions Programs have shown that leading a Security Champions program is a full-time job. In bigger organizations this may even require a small team. It is recommended to \u201cnominate\u201d or hire dedicated people that are passionate about this role and have the right skills set to drive it to ensure success. Having this as an \u201con the side job\u201d takes away from the momentum and dedication needed to launch a successful program. Similarly, persons with security knowledge but lacking the right communication and organizational skills to drive such a program can be a factor in its lack of success.

"},{"location":"Nominate_a_dedicated_captain.html#artefacts","title":"Artefacts","text":"

This job vacancy can be used when looking to hire a dedicated Security Champion Captain.

"},{"location":"Promote_knowledge_sharing.html","title":"Principles","text":""},{"location":"Promote_knowledge_sharing.html#what","title":"What","text":"

Invest in the education of your Security Champions and encourage knowledge sharing within and outside the company.

"},{"location":"Promote_knowledge_sharing.html#why","title":"Why","text":"

Security and technology are continuously evolving. Keeping up with developments requires a mindset of continuously learning. As Security Champions are the security front-runners in their teams and departments they are naturally interested in security related topics and want to learn more. They also know exactly what\u2019s needed to improve their teams. By sharing their knowledge they can improve people, processes and technology. Any feedback during the knowledge sharing sessions can give valuable insights and strengthen the whole community. Additionally, it also ensures the security team is aware of the technology used within the organization and the (security) challenge it incorporates.

"},{"location":"Promote_knowledge_sharing.html#how","title":"How","text":"

Promote a knowledge sharing culture, this is a mindset that values and rewards knowledge sharing among employees. Formal training programs can be rolled out using existing sharing and learning strategies within the company when available. Informal knowledge sharing via lunch sessions and pizza evenings can also be very valuable. Combine this with internal & external events to trigger the interest of your employees but make sure to rotate the speakers and topics to attract the biggest audience. Keep in mind that development teams are more likely to connect to the Security Champions that share something that\u2019s relevant to daily activities.

Gamification can be used to introduce a competitive element in the training and sharing knowledge. Capture the flag events are a great way to trigger the curiosity of your development teams.

"},{"location":"Reward_responsibility.html","title":"Principles","text":""},{"location":"Reward_responsibility.html#what","title":"What","text":"

The principle of \"Reward Responsibility\" involves establishing a system within an organization to recognize and reward the efforts of Security Champions. This system is designed to encompass both tangible and intangible forms of recognition and rewards. It aims to acknowledge the contributions that Security Champions make in enhancing the security posture of the organization, including their dedication, innovations, and proactive measures in managing security-related issues.

"},{"location":"Reward_responsibility.html#why","title":"Why","text":"

Acknowledging and rewarding Security Champions is crucial for several reasons. Firstly, it serves as a significant motivator, encouraging continued enthusiasm and dedication in their roles. When individuals see their efforts being recognized, they are more likely to take ownership and be proactive in their security responsibilities. Additionally, a reward system contributes to the overall effectiveness of the Security Champions program by fostering a positive and encouraging environment. It also plays a key role in talent retention within the program, as it demonstrates the organization's appreciation and value for the commitment and efforts of its Security Champions.

"},{"location":"Reward_responsibility.html#how","title":"How","text":"

To effectively implement this principle, organizations should develop a system that regularly recognizes the efforts of Security Champions. This could include setting up formal recognition programs, offering tangible rewards such as bonuses or professional development opportunities, and providing career advancement possibilities for effective champions. Additionally, regular feedback and expressions of appreciation are essential. Tailoring rewards to individual motivations is also key; some Champions might value public recognition, while others might appreciate personal development opportunities. The system should be designed to align with the organization's culture and policies, ensuring that it is meaningful and sustainable. Please refer to The Star Model \u2122or the PDF for more information on the theory of reward systems.

Supporting Artifacts: * Recognition Certificate Templates: Create customizable certificate templates to formally recognize the contributions of Security Champions. These certificates can be awarded for various achievements, like leading a successful security initiative, completing a significant amount of training, or significantly improving the security posture of a project.

"},{"location":"Secure_management_support.html","title":"Principles","text":""},{"location":"Secure_management_support.html#what","title":"What","text":"

Ensure your security champion program is recognized as a formal program with a set purpose within your organization. This is achieved when you secure management support for the program.

"},{"location":"Secure_management_support.html#why","title":"Why","text":"

A successful security champions program brings unmatchable security benefits to the table. It scales your security mindset and your security organization to the IT Department. Security Champions means that IT engineers are championing security. Doing so requires the IT department and other relevant departments to spend time, effort, and budget to create, nurture and enable the security champions. And this priority will conflict with other IT and Business priorities. Out of experience, we know that when priorities conflict, formalized priorities win the battle. Even the most passionate security champion will struggle to prioritize security over the expected workload. This can lead to frustrations within your security champions and will harm your security champions program.

That is WHY we strongly advise securing management support for your security champion program. This makes the program a formalized priority for the IT Department and thus for the security champions. Security Champions can spend the needed time to improve security without the constant distraction of explaining to IT Leads, Product Owners, and middle management why time is spent on security activities.

"},{"location":"Secure_management_support.html#how","title":"How","text":"

Setting up a Security Champion program requires a thorough analysis of the stakeholders to get the program approved and supported. The Head of IT, to whom the security champions report, is a key stakeholder. This can be the IT department doing Application Development, the IT Department doing Infrastructure Development, or both. Besides the Head of IT, if there is a Security or CISO department, management from that department is also a stakeholder as they set the direction of security and the Security organization. There are views that Security Champions are an extension of that Security Organization. Therefore, the manager of the Security Organization is a key stakeholder in securing management support for your security champions program. Another dimension to consider is when your vision of the security champion program states that being a security champion should be included in the job description of IT Engineers. It is advised to identify HR as a stakeholder.

Once the right stakeholders are identified, it is advised to understand what is essential for them and build your security champion program case around them. For the Head of IT, this would be in the direction of utilizing IT resources optimally, delivering IT fast and with adequate security/risk levels. For the Security Organization (CISO), what makes them tick is that security processes, expectations, and governance are embedded in the champion\u2019s model and a clear articulation of the benefits of having such a Security Champions program on top of the existing organization. Per stakeholders, the benefits should be articulated, including addressing the potential risks they see for their objectives.

Finally, the proposal of the program should be approved by each identified stakeholder, making the program a formal program.

Please see this artifact used by a financial company (bank) to build its case for formalizing the security champion program.

(p.s. In the included artifacts, clear disclaimers are included of the organization's context and why re-consideration is needed when copying and pasting the model to the user\u2019s organization).

"},{"location":"Start_with_a_clear_vision_for_your_program.html","title":"Principles","text":""},{"location":"Start_with_a_clear_vision_for_your_program.html#what","title":"What","text":"

A vision is defined as, \u201cthe act of power of imagination.\u201d When you apply vision to the future, you can create a mental picture that can be used to direct your and your organization\u2019s actions toward achieving security. A vision of security champions program serves as a guide in achieving security in your organization and can be used to provide a sense of purpose for IT engineers doing security.

"},{"location":"Start_with_a_clear_vision_for_your_program.html#why","title":"Why","text":"

Having a vision is critical for your decision-making and the long-term success of your program. It gives your program purpose, and clearly articulates the \u2018why\u2019 and \u2018what\u2019 that you want to see happen and the change you want to achieve. Without a clear end goal or destination from the outset, it will be difficult to create meaningful goals and strategies and make effective decisions.

There are several angles for defining a vision for security champions. The most common angle is that of democratizing security knowledge in the development teams, removing dependencies on the central security team, and governing security in development teams.

"},{"location":"Start_with_a_clear_vision_for_your_program.html#how","title":"How","text":"

A successful vision must be: * Imaginable: Convey a clear picture of what the future will look like. Translating this to your security champions program, you can consider drawing a security operating model with the roles and responsibilities of the security champions, dev(ops) engineers, IT Leads, Product Owner, and security organizations. * Desirable: Appeal to the long-term interest of those who have a stake in the Enterprise. Translating this to your security champions program, you should consider describing the benefits of embedding security in the development team through a security champion, with mandate, knowledge, and skills to do security. * Feasible: Describe realistic and attainable goals. For your security champions program include goals like \u201chours spent on security by the champion\u201d, \u201ctraining objectives of the champion\u201d, \u201d the number of security champions meet-ups\u201d, \u201cthe decrease of security risk\u201d, etc. * Focused: The vision should be clear enough to provide guidance in decision-making. What are the boundaries of security champions, what are commitments towards the program by senior management and what are expectations towards security champions? Is the scope of security champions to secure the entire enterprise? What is their role within the development team? What is their role compared to that of the Security Organization? * Communicable: A vision is easy to communicate and can be explained quickly. Don\u2019t write several pages of vision. A picture showing how security champions are enabling your goals in security and IT development will go a long way.

Please note that it is not advised to create your vision in isolation. By involving as many key stakeholders as possible, you\u2019ll enable people to take greater ownership of the vision and increase commitment. Think about IT Leads, POs, senior developers, and security leaders to be part of this vision creation process. Once the vision is in a good draft, give it a try by explaining and selling to within your organization (senior management, developer community etc).

"},{"location":"Trust_your_champions.html","title":"Principles","text":""},{"location":"Trust_your_champions.html#what","title":"What","text":"

Trusting your champions is key to a successful Security Champions program. They are the eyes and ears of the organization and know exactly what their department\u2019s security needs are.

"},{"location":"Trust_your_champions.html#why","title":"Why","text":"

The Security Champions are the experts in their working area. A security team can never achieve that level of knowledge of the applications as they are not involved in the operational work. Using their expertise to set up the Security Champions program will increase the likelihood of success.

When making people responsible, it is key to allow them to understand and act according to the defined role. It will increase speed, but also increase involvement. Ideally the Security Champions co-own the program and strongly influence the direction and content. They can identify shortcomings and propose changes or give practical feedback on the matter.

Teams are more likely to trust their own champions as they are \u201cone of their own\u201d and not an \u201coutsider\u201d from the Security Team. They speak the same language and understand the context. This will lead to more effective communication, better collaboration and reduced resistance to change.

In summary, trust is the glue that holds a Security Champions Program together.

"},{"location":"Trust_your_champions.html#how","title":"How","text":"

Trust is all about setting clear expectations. It should be clear to everyone involved what the Security Champions\u2019 role is about and what their mandate is. Don\u2019t be afraid to let your champions experiment with different approaches. Their lessons learned can be a valuable input to other departments, sharing is caring!

Give your Security Champions the mandate to make decisions on security within the risk appetite of your organization. By being in control and removing inefficiencies, they can add a lot of value to their teams and increase the security adoption & awareness. Do make sure they share their approach and reasoning to make sure the Security Champions can learn from each other and give constructive feedback.This way the organization can improve security related initiatives, decision making and processes..

Also involve the security champions in the processes of the core security team. Seek their input and opinions on security initiatives, policies, and practices to make them feel valued as active contributors. Use their feedback to improve the program, processes, and procedures.

Measure and showcase the impact that the Security Champions and the program make. Demonstrate how their efforts have positively influenced security outcomes, highlighting the value they bring to the organization. This will build up the Security Champions\u2019 trustworthiness and boost morale.

"},{"location":"blog/index.html","title":"Blog","text":""},{"location":"blog/2024/05/01/the-first-blog-post.html","title":"The first blog post!","text":"

Our very own blog post on the OWASP Security Champions guide!

","tags":["blog","guide"]},{"location":"blog/2024/06/04/the-second-blog-post.html","title":"The second blog post!","text":"

And another blog post on the OWASP Security Champions guide!

Check out the new artefacts for principle X!

","tags":["blog","guide"]},{"location":"blog/archive/2024.html","title":"June 2024","text":""},{"location":"blog/category/news.html","title":"News","text":""},{"location":"blog/category/welcome.html","title":"Welcome","text":""}]} \ No newline at end of file +{"config":{"lang":["en"],"separator":"[\\s\\-]+","pipeline":["stopWordFilter"]},"docs":[{"location":"index.html","title":"OWASP Security Champions Guide","text":"

Welcome to the home of the OWASP Security Champions Guide Project! Our goal is to create an open-source, vendor-neutral guidebook for AppSec professionals to help them build and improve their own successful Security Champion programs.

One size will not fit all \u2013 so this playbook is designed for you to pick and choose the elements your organization can adopt or leverage to create your own customized program. We will provide customizable artifacts that can be used to start or improve your program. It doesn\u2019t stop there! As your program matures, the playbook will provide you with next steps and new factors for consideration to further empower your program and your champions.

To make this happen, our project team is interviewing security leaders, program coordinators, and security champions to establish what makes a successful program. Participants represent a range of company sizes, industries, geographies, and also different levels of security program maturity. We want to know what works, what doesn\u2019t work, what promotes success, and what leads to failure.

We are looking for more participants to take part in this exciting project. Whatever your experience of Security Champions programs \u2013 good or bad \u2013 we want to hear from you! Especially if you are/have been:

Watch our project launch video here.

We\u2019d love to hear your feedback and ideas. Check out the \u2018Get Involved\u2019 tab for more details.

"},{"location":"Anticipate_personnel_changes.html","title":"Principles","text":""},{"location":"Anticipate_personnel_changes.html#what","title":"What","text":"

The field of information security staffing has undergone significant changes over the last decade. The increased reliance on technology has made Information security skills essential in many industries, leading to a high demand for information security talent and a lot of job opportunities. This high demand and abundance of opportunities has impacted the turn-over rate of staff significantly and companies find it harder to retain information security talent. Therefore, organizations need to anticipate these personnel changes in their organization and their security champions program as they are unavoidable.

"},{"location":"Anticipate_personnel_changes.html#why","title":"Why","text":"

Placing too high of a demand on a limited number of individuals as Security Champions increases the risk of a Security Champions program failing when certain, key, individuals leave the organization or change role within the organization.. Organizations need to acknowledge that people will leave, and ensure this does not bring the continuity of their Security Champions program in danger.

"},{"location":"Anticipate_personnel_changes.html#how","title":"How","text":"

In order to ensure consistency and continuity in the Security Champions the following, complementary, recommendations can be made:

"},{"location":"Be_passionate_about_security.html","title":"Principles","text":""},{"location":"Be_passionate_about_security.html#what","title":"What","text":"

Ensure the people involved in your security champion program are passionate about security. This passion helps to drive the program further and boost the security culture.

"},{"location":"Be_passionate_about_security.html#why","title":"Why","text":"

Being passionate about security is crucial because it creates a mindset where security is not just a compliance requirement, but a fundamental part of how an organization operates. When employees are passionate about security, they are more likely to take ownership of security issues, be proactive about identifying potential risks, and advocate for security best practices throughout the organization.

"},{"location":"Be_passionate_about_security.html#how","title":"How","text":"

Promote security top down and on all levels within your organization. Show security is taken seriously by management and is a key element of the DNA of the company. Then explain the importance of the security champions program within your organization. It should be clear what the program brings and what is expected of the people involved. The employees with passion for security should naturally be attracted to the program and raise their voice. Start with recruiting those volunteers and avoid assigning security champions when possible.

Be sure to enable passionate champions and invest in keeping them onboard. Trigger their curiosity and offer opportunities to keep on growing no matter what level they are on. Ideally, they also drive the program forward and make sure it covers their needs.

Don\u2019t limit yourself to internal recruitment. Highlight the importance of security in your vacancies to attract passionate people that can boost the security culture. Ask candidates about their security experience and see if you can find that spark.

There are lots of opportunities to spark the passion of security champions. This checklist can be used to discover possible touch points and opportunities to do so.

"},{"location":"Create_a_community.html","title":"Principles","text":""},{"location":"Create_a_community.html#what","title":"What","text":"

A community provides a platform for security champions to share knowledge, experiences, challenges, and best practices with each other. A community furthermore helps to foster a culture of security awareness, collaboration, and continuous learning among the security champions and their teams. A community can provide recognition, feedback, and support for the security champions.

"},{"location":"Create_a_community.html#why","title":"Why","text":"

Creating an active and vibrant community of Security Champions is vital to the success of any Security Champions Program and provides an additional channel to scale the security program.

"},{"location":"Create_a_community.html#how","title":"How","text":"

To create a community for a security champions program, the following should be considered:

"},{"location":"Get_involved.html","title":"getinvolved","text":"

If you are running a Security Champions Program, or starting one, contact us via LinkedIn message!

"},{"location":"Get_involved.html#call-for-security-champions-artifacts","title":"Call for Security Champions Artifacts!","text":"

The OWASP SCG Committee is looking for contributions in the form of artifacts and interviews. These can be (anonymized) presentations, program documents, or whatever tools have been useful to your organization.

For example:

We\u2019re collecting data from companies worldwide that have Security Champions Programs at any stage of maturity (including wishful thinking!). Please contact us (Irfaan Santoe, Marisa Fagan, Aleksandra Kornecka) to set up a time to meet and donate.

"},{"location":"Get_involved.html#collaborate","title":"Collaborate","text":"

Let\u2019s talk, see where we can help, and most importantly, if you used anything from us, let us know if that worked for you! If you have a platform where we can discuss our Security Champions Program and would like to offer a collaboration or publication, reach out, too! This helps drive the message.

Contact us on LinkedIn to get involved!

"},{"location":"Get_involved.html#updates","title":"Updates","text":"

Follow us on LinkedIn to get instantly notified of news and publications!

"},{"location":"Invest_in_your_champions.html","title":"Principles","text":""},{"location":"Invest_in_your_champions.html#what","title":"What","text":"

Invest in the personal growth and development of your Security Champions.

"},{"location":"Invest_in_your_champions.html#why","title":"Why","text":"

Security doesn't come for free and requires investments. These investments also show the organization that security is taken seriously and boost the morale of the Security Champions. Without proper investments, the security program and security culture can quickly degrade.

Security Champions spend a lot of effort in learning, sharing and promoting security in the organization and play an important role in the security culture of a company. Don\u2019t take the motivation of the Security Champions for granted. The organization should invest in them to make sure they feel appreciated and facilitate their development. This ensures the Security Champions community stays healthy and continues to drive the security program.

"},{"location":"Invest_in_your_champions.html#how","title":"How","text":"

By formally allocating time for security activities the Security Champions can combine security work with their other responsibilities. This investment will increase the quality and reduce the amount of rework and incidents.

Allocate budget for webinars, conferences and training to ensure Security Champions can develop and gain new knowledge. These new insights can uncover vulnerabilities and will most likely improve the quality and throughput time of the deliverables. Internal workshops, sessions, training and events are a great way to share knowledge within the organization and get new people excited for security.

Introduce job titles/specialized roles to give recognition to the Security Champions. Bonuses and promotion can be an additional incentive for employees to take security seriously and walk that extra mile.

"},{"location":"Manifesto.html","title":"Manifesto","text":"

The OWASP Security Champions Manifesto is a set of guiding principles crucial to any successful program!!!!

The principles have been drawn from an initial series of in-depth interviews with Application Security leaders from across the globe as part of our wider goal to provide a comprehensive Security Champions playbook.

Go to the \u2018Principles\u2019 tab to find out more about these key principles and how to put them into practice.

The Ten Key Principles for a Successful Security Champions Program

  1. Be passionate about security
  2. Start with a clear vision for your program
  3. Secure management support
  4. Nominate a dedicated captain
  5. Trust your champions
  6. Create a community
  7. Promote knowledge sharing
  8. Reward responsibility
  9. Invest in your champions
  10. Anticipate personnel changes

Prefer a visual? Download your copy of our principles infographic

"},{"location":"Nominate_a_dedicated_captain.html","title":"Principles","text":""},{"location":"Nominate_a_dedicated_captain.html#what","title":"What","text":"

Ensure you have a dedicated Captain to lead the development, implementation and continuous success of a Security Champions Program.

"},{"location":"Nominate_a_dedicated_captain.html#why","title":"Why","text":"

Having a dedicated Captain for a Security Champions Program is important to ensure that the program has a clear strategy and roadmap and is well-organized on a continuous basis. Lack of a dedicated role for this task may lead to people doing it \u201con the side\u201d while our experience and research shows that building and maintaining a Security Champion program is one that requires continuous attention.

Focus points for the dedicated Captain are:

"},{"location":"Nominate_a_dedicated_captain.html#how","title":"How","text":"

The projects teams\u2019 personal experience and interviews we have conducted with organizations that have Security Champions Programs have shown that leading a Security Champions program is a full-time job. In bigger organizations this may even require a small team. It is recommended to \u201cnominate\u201d or hire dedicated people that are passionate about this role and have the right skills set to drive it to ensure success. Having this as an \u201con the side job\u201d takes away from the momentum and dedication needed to launch a successful program. Similarly, persons with security knowledge but lacking the right communication and organizational skills to drive such a program can be a factor in its lack of success.

"},{"location":"Nominate_a_dedicated_captain.html#artefacts","title":"Artefacts","text":"

This job vacancy can be used when looking to hire a dedicated Security Champion Captain.

"},{"location":"Promote_knowledge_sharing.html","title":"Principles","text":""},{"location":"Promote_knowledge_sharing.html#what","title":"What","text":"

Invest in the education of your Security Champions and encourage knowledge sharing within and outside the company.

"},{"location":"Promote_knowledge_sharing.html#why","title":"Why","text":"

Security and technology are continuously evolving. Keeping up with developments requires a mindset of continuously learning. As Security Champions are the security front-runners in their teams and departments they are naturally interested in security related topics and want to learn more. They also know exactly what\u2019s needed to improve their teams. By sharing their knowledge they can improve people, processes and technology. Any feedback during the knowledge sharing sessions can give valuable insights and strengthen the whole community. Additionally, it also ensures the security team is aware of the technology used within the organization and the (security) challenge it incorporates.

"},{"location":"Promote_knowledge_sharing.html#how","title":"How","text":"

Promote a knowledge sharing culture, this is a mindset that values and rewards knowledge sharing among employees. Formal training programs can be rolled out using existing sharing and learning strategies within the company when available. Informal knowledge sharing via lunch sessions and pizza evenings can also be very valuable. Combine this with internal & external events to trigger the interest of your employees but make sure to rotate the speakers and topics to attract the biggest audience. Keep in mind that development teams are more likely to connect to the Security Champions that share something that\u2019s relevant to daily activities.

Gamification can be used to introduce a competitive element in the training and sharing knowledge. Capture the flag events are a great way to trigger the curiosity of your development teams.

"},{"location":"Reward_responsibility.html","title":"Principles","text":""},{"location":"Reward_responsibility.html#what","title":"What","text":"

The principle of \"Reward Responsibility\" involves establishing a system within an organization to recognize and reward the efforts of Security Champions. This system is designed to encompass both tangible and intangible forms of recognition and rewards. It aims to acknowledge the contributions that Security Champions make in enhancing the security posture of the organization, including their dedication, innovations, and proactive measures in managing security-related issues.

"},{"location":"Reward_responsibility.html#why","title":"Why","text":"

Acknowledging and rewarding Security Champions is crucial for several reasons. Firstly, it serves as a significant motivator, encouraging continued enthusiasm and dedication in their roles. When individuals see their efforts being recognized, they are more likely to take ownership and be proactive in their security responsibilities. Additionally, a reward system contributes to the overall effectiveness of the Security Champions program by fostering a positive and encouraging environment. It also plays a key role in talent retention within the program, as it demonstrates the organization's appreciation and value for the commitment and efforts of its Security Champions.

"},{"location":"Reward_responsibility.html#how","title":"How","text":"

To effectively implement this principle, organizations should develop a system that regularly recognizes the efforts of Security Champions. This could include setting up formal recognition programs, offering tangible rewards such as bonuses or professional development opportunities, and providing career advancement possibilities for effective champions. Additionally, regular feedback and expressions of appreciation are essential. Tailoring rewards to individual motivations is also key; some Champions might value public recognition, while others might appreciate personal development opportunities. The system should be designed to align with the organization's culture and policies, ensuring that it is meaningful and sustainable. Please refer to The Star Model \u2122or the PDF for more information on the theory of reward systems.

Supporting Artifacts: * Recognition Certificate Templates: Create customizable certificate templates to formally recognize the contributions of Security Champions. These certificates can be awarded for various achievements, like leading a successful security initiative, completing a significant amount of training, or significantly improving the security posture of a project.

"},{"location":"Secure_management_support.html","title":"Principles","text":""},{"location":"Secure_management_support.html#what","title":"What","text":"

Ensure your security champion program is recognized as a formal program with a set purpose within your organization. This is achieved when you secure management support for the program.

"},{"location":"Secure_management_support.html#why","title":"Why","text":"

A successful security champions program brings unmatchable security benefits to the table. It scales your security mindset and your security organization to the IT Department. Security Champions means that IT engineers are championing security. Doing so requires the IT department and other relevant departments to spend time, effort, and budget to create, nurture and enable the security champions. And this priority will conflict with other IT and Business priorities. Out of experience, we know that when priorities conflict, formalized priorities win the battle. Even the most passionate security champion will struggle to prioritize security over the expected workload. This can lead to frustrations within your security champions and will harm your security champions program.

That is WHY we strongly advise securing management support for your security champion program. This makes the program a formalized priority for the IT Department and thus for the security champions. Security Champions can spend the needed time to improve security without the constant distraction of explaining to IT Leads, Product Owners, and middle management why time is spent on security activities.

"},{"location":"Secure_management_support.html#how","title":"How","text":"

Setting up a Security Champion program requires a thorough analysis of the stakeholders to get the program approved and supported. The Head of IT, to whom the security champions report, is a key stakeholder. This can be the IT department doing Application Development, the IT Department doing Infrastructure Development, or both. Besides the Head of IT, if there is a Security or CISO department, management from that department is also a stakeholder as they set the direction of security and the Security organization. There are views that Security Champions are an extension of that Security Organization. Therefore, the manager of the Security Organization is a key stakeholder in securing management support for your security champions program. Another dimension to consider is when your vision of the security champion program states that being a security champion should be included in the job description of IT Engineers. It is advised to identify HR as a stakeholder.

Once the right stakeholders are identified, it is advised to understand what is essential for them and build your security champion program case around them. For the Head of IT, this would be in the direction of utilizing IT resources optimally, delivering IT fast and with adequate security/risk levels. For the Security Organization (CISO), what makes them tick is that security processes, expectations, and governance are embedded in the champion\u2019s model and a clear articulation of the benefits of having such a Security Champions program on top of the existing organization. Per stakeholders, the benefits should be articulated, including addressing the potential risks they see for their objectives.

Finally, the proposal of the program should be approved by each identified stakeholder, making the program a formal program.

Please see this artifact used by a financial company (bank) to build its case for formalizing the security champion program.

(p.s. In the included artifacts, clear disclaimers are included of the organization's context and why re-consideration is needed when copying and pasting the model to the user\u2019s organization).

"},{"location":"Start_with_a_clear_vision_for_your_program.html","title":"Principles","text":""},{"location":"Start_with_a_clear_vision_for_your_program.html#what","title":"What","text":"

A vision is defined as, \u201cthe act of power of imagination.\u201d When you apply vision to the future, you can create a mental picture that can be used to direct your and your organization\u2019s actions toward achieving security. A vision of security champions program serves as a guide in achieving security in your organization and can be used to provide a sense of purpose for IT engineers doing security.

"},{"location":"Start_with_a_clear_vision_for_your_program.html#why","title":"Why","text":"

Having a vision is critical for your decision-making and the long-term success of your program. It gives your program purpose, and clearly articulates the \u2018why\u2019 and \u2018what\u2019 that you want to see happen and the change you want to achieve. Without a clear end goal or destination from the outset, it will be difficult to create meaningful goals and strategies and make effective decisions.

There are several angles for defining a vision for security champions. The most common angle is that of democratizing security knowledge in the development teams, removing dependencies on the central security team, and governing security in development teams.

"},{"location":"Start_with_a_clear_vision_for_your_program.html#how","title":"How","text":"

A successful vision must be: * Imaginable: Convey a clear picture of what the future will look like. Translating this to your security champions program, you can consider drawing a security operating model with the roles and responsibilities of the security champions, dev(ops) engineers, IT Leads, Product Owner, and security organizations. * Desirable: Appeal to the long-term interest of those who have a stake in the Enterprise. Translating this to your security champions program, you should consider describing the benefits of embedding security in the development team through a security champion, with mandate, knowledge, and skills to do security. * Feasible: Describe realistic and attainable goals. For your security champions program include goals like \u201chours spent on security by the champion\u201d, \u201ctraining objectives of the champion\u201d, \u201d the number of security champions meet-ups\u201d, \u201cthe decrease of security risk\u201d, etc. * Focused: The vision should be clear enough to provide guidance in decision-making. What are the boundaries of security champions, what are commitments towards the program by senior management and what are expectations towards security champions? Is the scope of security champions to secure the entire enterprise? What is their role within the development team? What is their role compared to that of the Security Organization? * Communicable: A vision is easy to communicate and can be explained quickly. Don\u2019t write several pages of vision. A picture showing how security champions are enabling your goals in security and IT development will go a long way.

Please note that it is not advised to create your vision in isolation. By involving as many key stakeholders as possible, you\u2019ll enable people to take greater ownership of the vision and increase commitment. Think about IT Leads, POs, senior developers, and security leaders to be part of this vision creation process. Once the vision is in a good draft, give it a try by explaining and selling to within your organization (senior management, developer community etc).

"},{"location":"Trust_your_champions.html","title":"Principles","text":""},{"location":"Trust_your_champions.html#what","title":"What","text":"

Trusting your champions is key to a successful Security Champions program. They are the eyes and ears of the organization and know exactly what their department\u2019s security needs are.

"},{"location":"Trust_your_champions.html#why","title":"Why","text":"

The Security Champions are the experts in their working area. A security team can never achieve that level of knowledge of the applications as they are not involved in the operational work. Using their expertise to set up the Security Champions program will increase the likelihood of success.

When making people responsible, it is key to allow them to understand and act according to the defined role. It will increase speed, but also increase involvement. Ideally the Security Champions co-own the program and strongly influence the direction and content. They can identify shortcomings and propose changes or give practical feedback on the matter.

Teams are more likely to trust their own champions as they are \u201cone of their own\u201d and not an \u201coutsider\u201d from the Security Team. They speak the same language and understand the context. This will lead to more effective communication, better collaboration and reduced resistance to change.

In summary, trust is the glue that holds a Security Champions Program together.

"},{"location":"Trust_your_champions.html#how","title":"How","text":"

Trust is all about setting clear expectations. It should be clear to everyone involved what the Security Champions\u2019 role is about and what their mandate is. Don\u2019t be afraid to let your champions experiment with different approaches. Their lessons learned can be a valuable input to other departments, sharing is caring!

Give your Security Champions the mandate to make decisions on security within the risk appetite of your organization. By being in control and removing inefficiencies, they can add a lot of value to their teams and increase the security adoption & awareness. Do make sure they share their approach and reasoning to make sure the Security Champions can learn from each other and give constructive feedback.This way the organization can improve security related initiatives, decision making and processes..

Also involve the security champions in the processes of the core security team. Seek their input and opinions on security initiatives, policies, and practices to make them feel valued as active contributors. Use their feedback to improve the program, processes, and procedures.

Measure and showcase the impact that the Security Champions and the program make. Demonstrate how their efforts have positively influenced security outcomes, highlighting the value they bring to the organization. This will build up the Security Champions\u2019 trustworthiness and boost morale.

"},{"location":"blog/index.html","title":"Blog","text":""},{"location":"blog/2024/05/01/the-first-blog-post.html","title":"The first blog post!","text":"

Our very own blog post on the OWASP Security Champions guide!

","tags":["blog","guide"]},{"location":"blog/2024/06/04/the-second-blog-post.html","title":"The second blog post!","text":"

And another blog post on the OWASP Security Champions guide!

Check out the new artefacts for principle X!

","tags":["blog","guide"]},{"location":"blog/archive/2024.html","title":"June 2024","text":""},{"location":"blog/category/news.html","title":"News","text":""},{"location":"blog/category/welcome.html","title":"Welcome","text":""}]} \ No newline at end of file diff --git a/leaders.md b/leaders.md index c903196..d570419 100644 --- a/leaders.md +++ b/leaders.md @@ -6,7 +6,6 @@ ### Contributors * [Aleksandra Kornecka](https://www.linkedin.com/in/aleksandrakornecka/) -* [Brady Hawkins](https://www.linkedin.com/in/brady-hawkins/) * [Gjalt Wijma](https://www.linkedin.com/in/gtwijma/) * Jaiya "JP" Preston * [Juliane Reimann](https://www.linkedin.com/in/juliane-reimann)