Essential Factors for Successful Software Security Awareness Training

  • Authors:
  • Kenneth R. van Wyk;John Steven

  • Affiliations:
  • KRvW Associates;Cigital

  • Venue:
  • IEEE Security and Privacy
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

As organizations flesh out their enterprise software security framework (ESSF), they quicklyspot an overwhelming gap between their current state of practice and their eventual goals forbuilding secure applications. To address this gap, the application security group must bring ESSFplans to other parts of the organization: corporate, engineering, business, training, and IT groups,to name a few. Such socialization helps organizational participants understand their role inframework adoption and roll out, and it should cover what tools people will need, how they'llinteract with each other, and what levels of effort they can expect to put forth.