1- ---
21Education and Guidance :
32 Ad-Hoc Security trainings for software developers :
4- risk : Understanding security is hard and personnel needs to be trained on it.
5- Otherwise, flaws like an SQL Injection might be introduced into the software
6- which might get exploited.
3+ risk :
4+ - Understanding security is hard and personnel needs to be trained on it. Otherwise,
5+ flaws like an SQL Injection might be introduced into the software which might
6+ get exploited.
77 measure : Provide security awareness training for all personnel involved in software
88 development Ad-Hoc.
99 difficultyOfImplementation :
@@ -21,7 +21,8 @@ Education and Guidance:
2121 iso27001-2017 :
2222 - 7.2.2
2323 Regular security training for all :
24- risk : Understanding security is hard.
24+ risk :
25+ - Understanding security is hard.
2526 measure : Provide security awareness training for all personnel involved in software
2627 development on a regular basis like twice in a year for 1-3 days.
2728 difficultyOfImplementation :
@@ -39,7 +40,8 @@ Education and Guidance:
3940 Shop</a> on a "hacking Friday"
4041 - https://cheatsheetseries.owasp.org/
4142 Security consulting on request :
42- risk : Not asking a security expert when questions regarding security appear might
43+ risk :
44+ - Not asking a security expert when questions regarding security appear might
4345 lead to flaws.
4446 measure : Security consulting to teams is given on request. The security consultants
4547 can be internal or external.
@@ -55,8 +57,10 @@ Education and Guidance:
5557 - 6.1.1
5658 - 6.1.4
5759 - 6.1.5
60+ implementation : []
5861 Regular security training of security champions :
59- risk : Understanding security is hard, even for security champions.
62+ risk :
63+ - Understanding security is hard, even for security champions.
6064 measure : Regular security training of security champions.
6165 evidence : |
6266 - Process Documentation: TODO
@@ -71,8 +75,10 @@ Education and Guidance:
7175 iso27001-2017 :
7276 - security champions are missing in ISO 27001
7377 - 7.2.2
78+ implementation : []
7479 Regular security training for everyone :
75- risk : Understanding security is hard, for internal as well as external employees.
80+ risk :
81+ - Understanding security is hard, for internal as well as external employees.
7682 measure : Regular security training for everyone.
7783 difficultyOfImplementation :
7884 knowledge : 3
@@ -83,12 +89,14 @@ Education and Guidance:
8389 samm : EG2-B
8490 iso27001-2017 :
8591 - 7.2.2
86- implementation : Often, external employees are not invited for internal trainings.
87- This activity focuses on providing security trainings to internal as well as
88- external employees. It is conducted every two weeks for around one hour.
92+ implementation :
93+ - Often, external employees are not invited for internal trainings. This activity focuses
94+ on providing security trainings to internal as well as external employees. It
95+ is conducted every two weeks for around one hour.
8996 Each team has a security champion :
90- risk : No one feels directly responsible for security and the security champion
91- does not have enough time to allocate to each team.
97+ risk :
98+ - No one feels directly responsible for security and the security champion does
99+ not have enough time to allocate to each team.
92100 measure : Each team defines an individual to be responsible for security. These
93101 individuals are often referred to as 'security champions'
94102 difficultyOfImplementation :
@@ -102,10 +110,11 @@ Education and Guidance:
102110 - security champions are missing in ISO 27001 most likely
103111 - 7.2.1
104112 - 7.2.2
105- implementation :
113+ implementation :
106114 - OWASP Security Champions Playbook : https://github.com/c0rdis/security-champions-playbook
107115 Security-Lessoned-Learned :
108- risk : After an incident, a similar incident might reoccur.
116+ risk :
117+ - After an incident, a similar incident might reoccur.
109118 measure : Running a 'lessons learned' session after an incident helps drive continuous
110119 improvement. Regular meetings with security champions are a good place to share
111120 and discuss lessons learned.
@@ -118,9 +127,11 @@ Education and Guidance:
118127 samm : IM-3, ST-3, SR2-B
119128 iso27001-2017 :
120129 - 16.1.6
130+ implementation : []
121131 Conduction of collaborative security checks with developers and system administrators :
122- risk : Security checks by external companies do not increase the understanding
123- of an application/system for internal employees.
132+ risk :
133+ - Security checks by external companies do not increase the understanding of an
134+ application/system for internal employees.
124135 measure : Periodically security reviews of source code (SCA), in which security
125136 SME, developers and operations are involved, are effective at increasing the
126137 robustness of software and the security knowledge of the teams involved.
@@ -136,8 +147,10 @@ Education and Guidance:
136147 - 7.2.2
137148 - 12.6.1
138149 - 12.7.1
150+ implementation : []
139151 Conduction of collaborative team security checks :
140- risk : Development teams limited insight over security practices.
152+ risk :
153+ - Development teams limited insight over security practices.
141154 measure : Mutual security testing the security of other teams project enhances
142155 security awareness and knowledge.
143156 difficultyOfImplementation :
@@ -150,8 +163,10 @@ Education and Guidance:
150163 iso27001-2017 :
151164 - Mutual security testing is not explicitly required in ISO 27001 may be
152165 - 7.2.2
166+ implementation : []
153167 Conduction of build-it, break-it, fix-it contests :
154- risk : Understanding security is hard, even for security champions and the conduction
168+ risk :
169+ - Understanding security is hard, even for security champions and the conduction
155170 of security training often focuses on breaking a component instead of building
156171 a component secure.
157172 measure : The build-it, break-it, fix-it contest allows to train people with security
@@ -165,9 +180,11 @@ Education and Guidance:
165180 level : 3
166181 iso27001-2017 :
167182 - 7.2.2
168- implementation : https://builditbreakit.org/
183+ implementation :
184+ - https://builditbreakit.org/
169185 Conduction of war games :
170- risk : Understanding incident response plans during an incident is hard and ineffective.
186+ risk :
187+ - Understanding incident response plans during an incident is hard and ineffective.
171188 measure : War Games like activities help train for incidents. Security SMEs create
172189 attack scenarios in a testing environment enabling the trainees to learn how
173190 to react in case of an incident.
@@ -180,10 +197,12 @@ Education and Guidance:
180197 iso27001-2017 :
181198 - ware games are not explicitly required in ISO 27001 may be
182199 - 7.2.2
183- - " 16.1"
200+ - ' 16.1'
184201 - 16.1.5
202+ implementation : []
185203 Reward of good communication :
186- risk : Employees are not getting excited about security.
204+ risk :
205+ - Employees are not getting excited about security.
187206 measure : Good communication and transparency encourages cross-organizational support.
188207 Gamification of security is also known to help, examples include T-Shirts, mugs,
189208 cups, giftcards and 'High-Fives'.
@@ -203,7 +222,8 @@ Education and Guidance:
203222 Project</a>
204223 - https://owaspsamm.org/presentations/OWASP_Top_10_Maturity_Categories_for_Security_Champions.pptx
205224 Aligning security in teams :
206- risk : The concept of Security Champions might suggest that only he/she is responsible
225+ risk :
226+ - The concept of Security Champions might suggest that only he/she is responsible
207227 for security. However, everyone in the project team should be responsible for
208228 security.
209229 measure : By aligning security SME with project teams, a higher security standard
@@ -212,11 +232,10 @@ Education and Guidance:
212232 knowledge : 4
213233 time : 5
214234 resources : 1
215- implementation : Security SME are involved in discussion for requirements analysis,
216- software design and sprint planning to provide guidance and suggestions.
235+ implementation :
236+ - Security SME are involved in discussion for requirements analysis, software design and sprint planning to provide guidance and suggestions.
217237 usefulness : 5
218238 level : 4
219239 samm : EG2-B
220240 iso27001-2017 :
221241 - 7.1.1
222- ...
0 commit comments