CultureAndOrganization -> Education and Guidance: Ad-Hoc Security trainings for software developers
Risk and Opportunity
Risk: Understanding security is hard and personnel needs to be trained on it. Otherwise, flaws like an SQL Injection might be introduced into the software which might get exploited.
Opportunity: Provide security awareness training for all personnel involved in software development Ad-Hoc.
Usefulness and Requirements of this Activitiy
Required knowledge: Low (one discipline)
Required time: Very Low
Required resources (systems): Very Low
- OWASP JuiceShop, Link, Tags:
- OWASP Cheatsheet Series, Link, Tags: secure coding
OWASP SAMM VERSION 2