Any tips for establishing a security champions program for the software team? If you’ve done this, did you run into any internal pushback or skepticism?

210 viewscircle icon2 Comments
Sort by:
Director of Global Information Cyber Security in Manufacturing7 days ago

Executive support and buy in. It helps to have clearly defined roles.

Director of Engineering7 days ago

We have established a Product Security champion for the entire company first. This person for us sits in IT within the Infrastructure Security and Risk Management group.
Then every division has their champions and sponsors. Since my team is very large, I have appointed two champions to create a backup. This was done by asking my leaders including lead architects for nominations.
The team finds it very easy to communicate via our champions to the Company Champion.

Initially it looked like asking the IT's security champion or working via him was very cumbersome but now after a couple years, it seems great to have a non-partisan person help make decisions. They helped create a SOP on how we include Security in the product (Secure Product development Process). With them in a driver seat , it helped get it done and everyone does it. They also are responsible for Security toolsets. He has monthly meetings to review the dashboards, convey anything new he is hearing.
Quarterly the sponsors are invited to share the individual division dashboard.

Content you might like

We partner closely with design, but not with marketing28%

We partner closely with marketing, but not design49%

We partner closely with design and marketing17%

We do not partner closely with either3%

View Results

0-3 months7%

4-6 months43%

6-12 months29%

Longer than 1 year7%

Have not seen a return on our test automation investment8%

Don't know3%

View Results