Fork me on GitHub

Culture and Org. -> Education and Guidance: Ad-Hoc Security trainings for software developers

Risk and Opportunity

Risk: Understanding security is hard and personnel needs to be trained on it. Otherwise, flaws like an SQL Injection might be introduced into the software which might get exploited.
Opportunity: Provide security awareness training for all personnel involved in software development Ad-Hoc.

Exploit details

Usefullness: Medium
Required knowledge: Low (one discipline)
Required time: Very Low
Required resources (systems): Very Low

OWASP SAMM 1 Mapping: EG1-A - In case you do not have the budget to hire an external security expert, an option is to use the OWASP Juice Shop on a "hacking Friday" - https://cheatsheetseries.owasp.org/
ISO27001:2017 Controls Mapping: