1- ---
21Education and Guidance :
32 Ad-Hoc Security trainings for software developers :
4- risk : Understanding security is hard and personnel needs to be trained on it.
5- Otherwise, flaws like an SQL Injection might be introduced into the software
6- which might get exploited.
3+ risk :
4+ - Understanding security is hard and personnel needs to be trained on it. Otherwise,
5+ flaws like an SQL Injection might be introduced into the software which might
6+ get exploited.
77 measure : Provide security awareness training for all personnel involved in software
88 development Ad-Hoc.
99 difficultyOfImplementation :
@@ -21,7 +21,8 @@ Education and Guidance:
2121 iso27001-2017 :
2222 - 7.2.2
2323 Regular security training for all :
24- risk : Understanding security is hard.
24+ risk :
25+ - Understanding security is hard.
2526 measure : Provide security awareness training for all personnel involved in software
2627 development on a regular basis like twice in a year for 1-3 days.
2728 difficultyOfImplementation :
@@ -39,7 +40,8 @@ Education and Guidance:
3940 Shop</a> on a "hacking Friday"
4041 - https://cheatsheetseries.owasp.org/
4142 Security consulting on request :
42- risk : Not asking a security expert when questions regarding security appear might
43+ risk :
44+ - Not asking a security expert when questions regarding security appear might
4345 lead to flaws.
4446 measure : Security consulting to teams is given on request. The security consultants
4547 can be internal or external.
@@ -55,8 +57,10 @@ Education and Guidance:
5557 - 6.1.1
5658 - 6.1.4
5759 - 6.1.5
60+ implementation : []
5861 Regular security training of security champions :
59- risk : Understanding security is hard, even for security champions.
62+ risk :
63+ - Understanding security is hard, even for security champions.
6064 measure : Regular security training of security champions.
6165 evidence : |
6266 - Process Documentation: TODO
@@ -71,8 +75,10 @@ Education and Guidance:
7175 iso27001-2017 :
7276 - security champions are missing in ISO 27001
7377 - 7.2.2
78+ implementation : []
7479 Regular security training for everyone :
75- risk : Understanding security is hard, for internal as well as external employees.
80+ risk :
81+ - Understanding security is hard, for internal as well as external employees.
7682 measure : Regular security training for everyone.
7783 difficultyOfImplementation :
7884 knowledge : 3
@@ -83,12 +89,15 @@ Education and Guidance:
8389 samm : EG2-B
8490 iso27001-2017 :
8591 - 7.2.2
86- implementation : Often, external employees are not invited for internal trainings.
87- This activity focuses on providing security trainings to internal as well as
88- external employees. It is conducted every two weeks for around one hour.
92+ implementation :
93+ - Often
94+ - ' external employees are not invited for internal trainings. This activity focuses
95+ on providing security trainings to internal as well as external employees. It
96+ is conducted every two weeks for around one hour.'
8997 Each team has a security champion :
90- risk : No one feels directly responsible for security and the security champion
91- does not have enough time to allocate to each team.
98+ risk :
99+ - No one feels directly responsible for security and the security champion does
100+ not have enough time to allocate to each team.
92101 measure : Each team defines an individual to be responsible for security. These
93102 individuals are often referred to as 'security champions'
94103 difficultyOfImplementation :
@@ -102,10 +111,11 @@ Education and Guidance:
102111 - security champions are missing in ISO 27001 most likely
103112 - 7.2.1
104113 - 7.2.2
105- implementation :
114+ implementation :
106115 - OWASP Security Champions Playbook : https://github.com/c0rdis/security-champions-playbook
107116 Security-Lessoned-Learned :
108- risk : After an incident, a similar incident might reoccur.
117+ risk :
118+ - After an incident, a similar incident might reoccur.
109119 measure : Running a 'lessons learned' session after an incident helps drive continuous
110120 improvement. Regular meetings with security champions are a good place to share
111121 and discuss lessons learned.
@@ -118,9 +128,11 @@ Education and Guidance:
118128 samm : IM-3, ST-3, SR2-B
119129 iso27001-2017 :
120130 - 16.1.6
131+ implementation : []
121132 Conduction of collaborative security checks with developers and system administrators :
122- risk : Security checks by external companies do not increase the understanding
123- of an application/system for internal employees.
133+ risk :
134+ - Security checks by external companies do not increase the understanding of an
135+ application/system for internal employees.
124136 measure : Periodically security reviews of source code (SCA), in which security
125137 SME, developers and operations are involved, are effective at increasing the
126138 robustness of software and the security knowledge of the teams involved.
@@ -136,8 +148,10 @@ Education and Guidance:
136148 - 7.2.2
137149 - 12.6.1
138150 - 12.7.1
151+ implementation : []
139152 Conduction of collaborative team security checks :
140- risk : Development teams limited insight over security practices.
153+ risk :
154+ - Development teams limited insight over security practices.
141155 measure : Mutual security testing the security of other teams project enhances
142156 security awareness and knowledge.
143157 difficultyOfImplementation :
@@ -150,8 +164,10 @@ Education and Guidance:
150164 iso27001-2017 :
151165 - Mutual security testing is not explicitly required in ISO 27001 may be
152166 - 7.2.2
167+ implementation : []
153168 Conduction of build-it, break-it, fix-it contests :
154- risk : Understanding security is hard, even for security champions and the conduction
169+ risk :
170+ - Understanding security is hard, even for security champions and the conduction
155171 of security training often focuses on breaking a component instead of building
156172 a component secure.
157173 measure : The build-it, break-it, fix-it contest allows to train people with security
@@ -165,9 +181,11 @@ Education and Guidance:
165181 level : 3
166182 iso27001-2017 :
167183 - 7.2.2
168- implementation : https://builditbreakit.org/
184+ implementation :
185+ - https://builditbreakit.org/
169186 Conduction of war games :
170- risk : Understanding incident response plans during an incident is hard and ineffective.
187+ risk :
188+ - Understanding incident response plans during an incident is hard and ineffective.
171189 measure : War Games like activities help train for incidents. Security SMEs create
172190 attack scenarios in a testing environment enabling the trainees to learn how
173191 to react in case of an incident.
@@ -180,10 +198,12 @@ Education and Guidance:
180198 iso27001-2017 :
181199 - ware games are not explicitly required in ISO 27001 may be
182200 - 7.2.2
183- - " 16.1"
201+ - ' 16.1'
184202 - 16.1.5
203+ implementation : []
185204 Reward of good communication :
186- risk : Employees are not getting excited about security.
205+ risk :
206+ - Employees are not getting excited about security.
187207 measure : Good communication and transparency encourages cross-organizational support.
188208 Gamification of security is also known to help, examples include T-Shirts, mugs,
189209 cups, giftcards and 'High-Fives'.
@@ -203,7 +223,8 @@ Education and Guidance:
203223 Project</a>
204224 - https://owaspsamm.org/presentations/OWASP_Top_10_Maturity_Categories_for_Security_Champions.pptx
205225 Aligning security in teams :
206- risk : The concept of Security Champions might suggest that only he/she is responsible
226+ risk :
227+ - The concept of Security Champions might suggest that only he/she is responsible
207228 for security. However, everyone in the project team should be responsible for
208229 security.
209230 measure : By aligning security SME with project teams, a higher security standard
@@ -212,11 +233,11 @@ Education and Guidance:
212233 knowledge : 4
213234 time : 5
214235 resources : 1
215- implementation : Security SME are involved in discussion for requirements analysis,
216- software design and sprint planning to provide guidance and suggestions.
236+ implementation :
237+ - Security SME are involved in discussion for requirements analysis
238+ - ' software design and sprint planning to provide guidance and suggestions.'
217239 usefulness : 5
218240 level : 4
219241 samm : EG2-B
220242 iso27001-2017 :
221243 - 7.1.1
222- ...
0 commit comments