Chapter 2. Pragmatic Advice for Building an Application Security Program
Andres Andreu
Application security (AppSec) is a never-ending journey. The goal is to positively influence the relevant software engineering culture and stakeholders to willingly participate. A shift left approach, for instance, should become a mutually desired business enabler.
The first step of a successful AppSec program is to set up common goals and gain alignment from the engineering side. This requires tactful education, communication, and storytelling from cybersecurity leadership to engineering leaders. Therefore, getting their buy-in on how the security team is trying to achieve the common goals while enabling them to produce software becomes the key.
Ideally, application security is just silently there. This is ultimately the goal of security as a business enabler. The challenge is that security hurts and it costs (time, money, effort, etc.). As such, many organizations see security as a necessary evil. Weaving a security-first mindset into an organization’s culture is foundational. It will take time, but it is the secret sauce of success.
A key area for positive impact will be the software development life cycle (SDLC). This needs to be transformed into a secure SDLC (SSDLC). Depending on resources, a great approach is to embed AppSec talent or champions into the engineering teams/squads. This ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access