@@ -14,10 +14,15 @@ Education and Guidance:
1414 level : 1
1515 samm : EG1-A
1616 implementation :
17- - In case you do not have the budget to hire an external security expert, an option
18- is to use the <a href="https://github.com/bkimminich/juice-shop">OWASP Juice
19- Shop</a> on a "hacking Friday"
20- - https://cheatsheetseries.owasp.org/
17+ - name : OWASP JuiceShop
18+ tags : []
19+ url : https://github.com/bkimminich/juice-shop
20+ description : " In case you do not have the budget to hire an external security\
21+ \ expert, an option\n is to use the [OWASP JuiceShop](https://github.com/bkimminich/juice-shop)\
22+ \ on a \" hacking Friday\" "
23+ - name : https://cheatsheetseries.owasp.org/
24+ tags : []
25+ url : https://cheatsheetseries.owasp.org/
2126 iso27001-2017 :
2227 - 7.2.2
2328 Regular security training for all :
@@ -35,10 +40,15 @@ Education and Guidance:
3540 iso27001-2017 :
3641 - 7.2.2
3742 implementation :
38- - In case you do not have the budget to hire an external security expert, an option
39- is to use the <a href="https://github.com/bkimminich/juice-shop">OWASP Juice
40- Shop</a> on a "hacking Friday"
41- - https://cheatsheetseries.owasp.org/
43+ - name : OWASP JuiceShop
44+ tags : []
45+ url : https://github.com/bkimminich/juice-shop
46+ description : " In case you do not have the budget to hire an external security\
47+ \ expert, an option\n is to use the [OWASP JuiceShop](https://github.com/bkimminich/juice-shop)\
48+ \ on a \" hacking Friday\" "
49+ - name : https://cheatsheetseries.owasp.org/
50+ tags : []
51+ url : https://cheatsheetseries.owasp.org/
4252 Security consulting on request :
4353 risk :
4454 - Not asking a security expert when questions regarding security appear might
@@ -90,9 +100,11 @@ Education and Guidance:
90100 iso27001-2017 :
91101 - 7.2.2
92102 implementation :
93- - Often, external employees are not invited for internal trainings. This activity focuses
94- on providing security trainings to internal as well as external employees. It
95- is conducted every two weeks for around one hour.
103+ - name : Train internal and external resources
104+ tags : []
105+ description : Often, external employees are not invited for internal trainings.
106+ This activity focuses on providing security trainings to internal as well
107+ as external employees. It is conducted every two weeks for around one hour.
96108 Each team has a security champion :
97109 risk :
98110 - No one feels directly responsible for security and the security champion does
@@ -111,7 +123,9 @@ Education and Guidance:
111123 - 7.2.1
112124 - 7.2.2
113125 implementation :
114- - OWASP Security Champions Playbook : https://github.com/c0rdis/security-champions-playbook
126+ - name : ' OWASP Security Champions Playbook'
127+ tags : []
128+ url : https://github.com/c0rdis/security-champions-playbook
115129 Security-Lessoned-Learned :
116130 risk :
117131 - After an incident, a similar incident might reoccur.
@@ -181,7 +195,9 @@ Education and Guidance:
181195 iso27001-2017 :
182196 - 7.2.2
183197 implementation :
184- - https://builditbreakit.org/
198+ - name : https://builditbreakit.org/
199+ tags : []
200+ url : https://builditbreakit.org/
185201 Conduction of war games :
186202 risk :
187203 - Understanding incident response plans during an incident is hard and ineffective.
@@ -217,10 +233,15 @@ Education and Guidance:
217233 - interestingly enough A7.2.3 is requiring a process to handle misconduct but
218234 nothing to promote good behavior.
219235 implementation :
220- - Enhance motivation can be performed with the distribution of pins as a reward,
221- see <a href='https://github.com/wurstbrot/security-pins'>OWASP Security Pins
222- Project</a>
223- - https://owaspsamm.org/presentations/OWASP_Top_10_Maturity_Categories_for_Security_Champions.pptx
236+ - name : Motivate people
237+ tags : []
238+ url : https://github.com/wurstbrot/security-pins
239+ description : |-
240+ Enhance motivation can be performed with the distribution of pins
241+ as a reward, see [OWASP Security Pins Project](https://github.com/wurstbrot/security-pins)
242+ - name : OWASP_Top_10_Maturity_Categories_for_Security_Champions
243+ tags : []
244+ url : https://owaspsamm.org/presentations/OWASP_Top_10_Maturity_Categories_for_Security_Champions.pptx
224245 Aligning security in teams :
225246 risk :
226247 - The concept of Security Champions might suggest that only he/she is responsible
@@ -233,7 +254,10 @@ Education and Guidance:
233254 time : 5
234255 resources : 1
235256 implementation :
236- - Security SME are involved in discussion for requirements analysis, software design and sprint planning to provide guidance and suggestions.
257+ - name : Involve Security SME
258+ tags : []
259+ description : Security SME are involved in discussion for requirements analysis,
260+ software design and sprint planning to provide guidance and suggestions.
237261 usefulness : 5
238262 level : 4
239263 samm : EG2-B
0 commit comments