Skip to content

Commit a0b9ceb

Browse files
committed
fix remaining files.
1 parent bc7643b commit a0b9ceb

File tree

1 file changed

+42
-18
lines changed

1 file changed

+42
-18
lines changed

data-new/CultureAndOrganization/EducationAndGuidance.yaml

Lines changed: 42 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -14,10 +14,15 @@ Education and Guidance:
1414
level: 1
1515
samm: EG1-A
1616
implementation:
17-
- In case you do not have the budget to hire an external security expert, an option
18-
is to use the <a href="https://github.com/bkimminich/juice-shop">OWASP Juice
19-
Shop</a> on a "hacking Friday"
20-
- https://cheatsheetseries.owasp.org/
17+
- name: OWASP JuiceShop
18+
tags: []
19+
url: https://github.com/bkimminich/juice-shop
20+
description: "In case you do not have the budget to hire an external security\
21+
\ expert, an option\nis to use the [OWASP JuiceShop](https://github.com/bkimminich/juice-shop)\
22+
\ on a \"hacking Friday\""
23+
- name: https://cheatsheetseries.owasp.org/
24+
tags: []
25+
url: https://cheatsheetseries.owasp.org/
2126
iso27001-2017:
2227
- 7.2.2
2328
Regular security training for all:
@@ -35,10 +40,15 @@ Education and Guidance:
3540
iso27001-2017:
3641
- 7.2.2
3742
implementation:
38-
- In case you do not have the budget to hire an external security expert, an option
39-
is to use the <a href="https://github.com/bkimminich/juice-shop">OWASP Juice
40-
Shop</a> on a "hacking Friday"
41-
- https://cheatsheetseries.owasp.org/
43+
- name: OWASP JuiceShop
44+
tags: []
45+
url: https://github.com/bkimminich/juice-shop
46+
description: "In case you do not have the budget to hire an external security\
47+
\ expert, an option\nis to use the [OWASP JuiceShop](https://github.com/bkimminich/juice-shop)\
48+
\ on a \"hacking Friday\""
49+
- name: https://cheatsheetseries.owasp.org/
50+
tags: []
51+
url: https://cheatsheetseries.owasp.org/
4252
Security consulting on request:
4353
risk:
4454
- Not asking a security expert when questions regarding security appear might
@@ -90,9 +100,11 @@ Education and Guidance:
90100
iso27001-2017:
91101
- 7.2.2
92102
implementation:
93-
- Often, external employees are not invited for internal trainings. This activity focuses
94-
on providing security trainings to internal as well as external employees. It
95-
is conducted every two weeks for around one hour.
103+
- name: Train internal and external resources
104+
tags: []
105+
description: Often, external employees are not invited for internal trainings.
106+
This activity focuses on providing security trainings to internal as well
107+
as external employees. It is conducted every two weeks for around one hour.
96108
Each team has a security champion:
97109
risk:
98110
- No one feels directly responsible for security and the security champion does
@@ -111,7 +123,9 @@ Education and Guidance:
111123
- 7.2.1
112124
- 7.2.2
113125
implementation:
114-
- OWASP Security Champions Playbook: https://github.com/c0rdis/security-champions-playbook
126+
- name: 'OWASP Security Champions Playbook'
127+
tags: []
128+
url: https://github.com/c0rdis/security-champions-playbook
115129
Security-Lessoned-Learned:
116130
risk:
117131
- After an incident, a similar incident might reoccur.
@@ -181,7 +195,9 @@ Education and Guidance:
181195
iso27001-2017:
182196
- 7.2.2
183197
implementation:
184-
- https://builditbreakit.org/
198+
- name: https://builditbreakit.org/
199+
tags: []
200+
url: https://builditbreakit.org/
185201
Conduction of war games:
186202
risk:
187203
- Understanding incident response plans during an incident is hard and ineffective.
@@ -217,10 +233,15 @@ Education and Guidance:
217233
- interestingly enough A7.2.3 is requiring a process to handle misconduct but
218234
nothing to promote good behavior.
219235
implementation:
220-
- Enhance motivation can be performed with the distribution of pins as a reward,
221-
see <a href='https://github.com/wurstbrot/security-pins'>OWASP Security Pins
222-
Project</a>
223-
- https://owaspsamm.org/presentations/OWASP_Top_10_Maturity_Categories_for_Security_Champions.pptx
236+
- name: Motivate people
237+
tags: []
238+
url: https://github.com/wurstbrot/security-pins
239+
description: |-
240+
Enhance motivation can be performed with the distribution of pins
241+
as a reward, see [OWASP Security Pins Project](https://github.com/wurstbrot/security-pins)
242+
- name: OWASP_Top_10_Maturity_Categories_for_Security_Champions
243+
tags: []
244+
url: https://owaspsamm.org/presentations/OWASP_Top_10_Maturity_Categories_for_Security_Champions.pptx
224245
Aligning security in teams:
225246
risk:
226247
- The concept of Security Champions might suggest that only he/she is responsible
@@ -233,7 +254,10 @@ Education and Guidance:
233254
time: 5
234255
resources: 1
235256
implementation:
236-
- Security SME are involved in discussion for requirements analysis, software design and sprint planning to provide guidance and suggestions.
257+
- name: Involve Security SME
258+
tags: []
259+
description: Security SME are involved in discussion for requirements analysis,
260+
software design and sprint planning to provide guidance and suggestions.
237261
usefulness: 5
238262
level: 4
239263
samm: EG2-B

0 commit comments

Comments
 (0)