Skip to content
This repository has been archived by the owner on Nov 14, 2023. It is now read-only.

Update Security-Guild-vs-Security-Champions.md #1587

Open
wants to merge 2 commits into
base: master
Choose a base branch
from
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -1,62 +1,52 @@
---
layout : blocks/page-content
layout : blocks/outcome
title : Security Guild vs Security Champions
---
## Outcomes

Security Champions are a key element of an AppSec team, since they create a cross-functional team focused on Application Security.

What is a Security Champion?
**What is a Security Champion?**

- Security Champions are active members of a team with a dotted line to the central Security Team
- Act as the "voice" of security for the given product or team
- Security Champions provide visilibity to the central security

Comments
**Comments**

- Security Champions are a model that has been used succesfully
- A group of Security Champions could be a Security Guild
- Security Champions network need energy from the central Security Team

Follow up:
**Follow up:**

- Request on the model present above
- Create a survey that maps the current Security Champions structure (in the Summit)

## Who

The target audience for this Working Session is:

- Security Champions
- CISOs
- Agile practitioners

---

## Working materials

Here are the current 'work in progress' materials for this session (please add as much information as possible before the sessions)

### Content

OWASP [definition](https://www.owasp.org/index.php/Security_Champions) of security champions:

Security Champions are a key element of an AppSec team, since they create a cross-functional team focused on Application Security.

What is a Security Champion?
**What is a Security Champion?**

- Security Champions are active members of a team with a dotted line to the central Security Team
- Act as the "voice" of security for the given product or team
- Security Champions provide visilibity to the central security

Recommendation
**Recommendation**

- Security Champions are a model that has been used succesfully
- A group of Security Champions could be a Security Guild
- Security Champions network need energy from the central Security Team

**What do they do?**

What do they do?
- Assist in the triage of security issues for their team or area
- Actively participate in the AppSec JIRA and WIKI
- Collaborate with other security champions
Expand All @@ -74,6 +64,6 @@ What do they do?
- Write Tests (from Unit Tests to Integration tests)
- Help with development of CI (Continuous Integration) environments

What is a Security Guild?
**What is a Security Guild?**

"A guild is a community of members with shared interests. These are a group of people across the organization who want to share knowledge, tools, code, and practices." [Spotify](http://www.full-stackagile.com/2016/02/14/team-organisation-squads-chapters-tribes-and-guilds)