Activision Blizzard

An Oft Overlooked Item During Security Awareness Month

October is cybersecurity awareness month in the United States, filled with events and trainings focused on traditional security concerns such as phishing, strong passwords, privacy protection, ransomware prevention, etc. Empowering employees to do their part in protecting the company is crucial. I don’t mean to downplay the importance of enterprise IT security training. There’s an important part of security awareness most companies miss: secure software development. Rarely have I seen companies include it in their general security curriculum.

It’s been said every business is a software business. Most companies have some modicum of custom software development or it’s a primary product of theirs. What if your company doesn’t make software? or starters, it does in an oft overlooked place: outsourced custom software development. It may not seem the training is needed internally; it will benefit your company if the vendors you depend on have.

Secure development training is specialized education for those making software. To be clear, I’m referring to anyone at your company who designs, programs, builds, or deploys software. Not only do they need to be familiar with how to avoid being phished, but also the importance of good input validation on that web API they’re designing. Training may take the form of teaching an architect to threat model, inviting developers to compete in a secure coding tournament, or instructing a DevOps engineer how to use available tools to reduce the production environment’s attack surface.

Getting educational content to those who need it is easy today. A plethora of videos that demonstrate common problems and how to avoid them are freely available. MOOCs and university courses exist for those who want something more formal. There are tons of technical books on secure coding, threat modeling (one of my favorite subjects), attacking your own code, or application security. IT Security training companies now have entire curricula in the subject, complete with practical exams, progress reporting, and statistical analysis for their customers. Speaking of threat modeling, secure development engineering knowledge could even be gained from having a group of employees build a threat model of what they created.

“Ensure the vendors who make the software that your company uses are training their employees in the subject matter. Check that your vendors make efforts to train their development staff in the subject matter”

The primary benefit of secure software development is defense in depth, included throughout the project from early design or coding through to production operations. When all project members have a basic level of secure DevOps knowledge, the whole project gets more secure. Team members will call out faults and suggest improvements before a single line of code is written. Developers will write input filtering for that new API. Operations teams will recommend compensating controls that provide a back stop. Combined, those little security improvements reduce the severity or success rate of an attempted attack.

For those few who truly do not make software in-house and are merely consuming pre-made programs from others with customized configurations on top: don’t forget your vendors. Ensure the vendors who make the software that your company uses are training their employees in the subject matter. Check that your vendors make efforts to train their development staff in the subject matter. Add contractual language requiring them to do so. Oblige them to fix any security issues at their expense. Their insecurity becomes your insecurity (just look at patching) so make them participate in improving yours.

In closing, secure development training is readily available at a variety of price points and can take on many forms. Videos only cost viewing time. Books are cheap. Courses can be very cost-effective. Quite simply, there’s no good reason not to educate your staff on the subject when they are in the target demographic. Educating them is cheaper than an incident.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.