Chapter 10. AppSec Is a People Problem—Not a Technical One
Mark S. Merkow
Bootstrapping a new or low-maturity AppSec program using security technology alone is a guaranteed recipe for failure or suboptimal outcomes. Throwing technology into an environment that expects developers to address findings but fails to prepare them technically and psychologically with the knowledge and skills needed is a recipe for bad results.
It’s people who are responsible for all aspects of software—from inception to design to development, testing, and implementation. They’re also responsible for software security—whether they realize it or not; no one other than the person developing the software can effectively secure it. Ignoring this responsibility or ignoring the human aspects of software development when introducing new security-focused tools in developer workflow quickly leads to chaos, anger, missed deadlines, and bewildered management.
There are few more effective ways to demoralize an entire development organization than by running security scanners on their applications, throwing the results over the wall, and mandating those developers to “deal with it” somehow. Making matters worse, traditional education that prepares programmers and IT roles for new technologies, new languages, and new platforms doesn’t arm learners with the skills they need to meet the demands of organizations that ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access