Chapter 4. Democratizing Security
Imagine if every software engineer in your organization was a former attacker. They could look at their team’s feature or product and quickly brainstorm how they could benefit from compromising it and what steps they would take to most easily do so. After daydreaming this attacker fantasy for a bit, they could snap back to reality and propose design improvements that would make it harder for attackers to take the steps they imagined. While having this kind of feedback loop on each one of your engineering teams may seem like its own fantasy, it’s more easily realized than you imagine.
A distributed, democratized security program can accomplish these goals. What do we mean by making defense “democratized”? It represents a security program supported by broad, voluntary participation with benefits accessible to everyone. It means that security efforts are explicitly neither isolated nor exclusive. Like a democracy, it must serve all stakeholders and involve participation by those stakeholders. Specifically, an organization’s team of defenders can’t just consist of security people—it must also include members of product and engineering teams who are building the systems whose security the defenders must challenge.
In this chapter, we’ll explore what the critical function of defenders—alternative analysis—entails and how a democratized security program, such as a Security Champions program, fits into SCE.
What Is Alternative Analysis?
Before we dive ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access