Skip to content

Commit 9932b92

Browse files
authored
add security champion maturity model
1 parent dce823b commit 9932b92

1 file changed

Lines changed: 4 additions & 2 deletions

File tree

data/CultureandOrg.yml

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -118,16 +118,18 @@ Education and Guidance:
118118
level: 4
119119
Reward of good communication:
120120
risk: Employees are not getting excited about security.
121-
measure: Good communication and transparency encourages cross-organisational support. Gamification of security is also known to help, examples include T-Shirts, giftcards and 'High-Fives'.
121+
measure: Good communication and transparency encourages cross-organisational support. Gamification of security is also known to help, examples include T-Shirts, mugs, cups, giftcards and 'High-Fives'.
122122
difficultyOfImplementation:
123123
knowledge: 3
124124
time: 2
125125
resources: 1
126126
usefulness: 3
127127
level: 2
128-
implementation: One example is the distribution of buttons as a reward, see <a
128+
implementation:
129+
- Enhance motivation can be performed with the distribution of pins as a reward, see <a
129130
href='https://www.owasp.org/index.php/OWASP_Security_Buttons_Project'>OWASP
130131
Security Buttons Project</a>
132+
- https://owaspsamm.org/presentations/OWASP_Top_10_Maturity_Categories_for_Security_Champions.pptx
131133
Aligning security in teams:
132134
risk: The concept of Security Champions might suggest that only he/she is responsible for security. However, everyone in the project team should be responsible for security.
133135
measure: By aligning security SME with project teams, a higher security standard can be achieved.

0 commit comments

Comments
 (0)