Skip to content

Commit cd76d11

Browse files
authored
Update EducationAndGuidance.yaml
Changing the description of security champion section to markdown to resolve build issues.
1 parent c492e8a commit cd76d11

File tree

1 file changed

+6
-20
lines changed

1 file changed

+6
-20
lines changed

src/assets/YAML/default/CultureAndOrganization/EducationAndGuidance.yaml

Lines changed: 6 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -211,26 +211,12 @@ Culture and Organization:
211211
resources: 1
212212
usefulness: 4
213213
level: 2
214-
description:
215-
"Implement a program where each software development team has a
216-
member considered a \u201CSecurity Champion\u201D who is the liaison between
217-
Information Security and developers. Depending on the size and structure of
218-
the team the \u201CSecurity Champion\u201D may be a software developer, tester,
219-
or a product manager. The \u201CSecurity Champion\u201D has a set number of
220-
hours per week for Information Security related activities. They participate
221-
in periodic briefings to increase awareness and expertise in different security
222-
disciplines. \u201CSecurity Champions\u201D have additional training to help
223-
develop these roles as Software Security subject-matter experts. You may need
224-
to customize the way you create and support \u201CSecurity Champions\u201D
225-
for cultural reasons.\n\nThe goals of the position are to increase effectiveness
226-
and efficiency of application security and compliance and to strengthen the
227-
relationship between various teams and Information Security. To achieve these
228-
objectives, \u201CSecurity Champions\u201D assist with researching, verifying,
229-
and prioritizing security and compliance related software defects. They are
230-
involved in all Risk Assessments, Threat Assessments, and Architectural Reviews
231-
to help identify opportunities to remediate security defects by making the
232-
architecture of the application more resilient and reducing the attack threat
233-
surface.\nSource: [OWASP SAMM](https://owaspsamm.org/model/governance/education-and-guidance/stream-b/)\n"
214+
description: |
215+
Implement a program where each software development team has a member considered a "Security Champion" who is the liaison between Information Security and developers. Depending on the size and structure of the team the "Security Champion" may be a software developer, tester, or a product manager. The "Security Champion" has a set number of hours per week for Information Security related activities. They participate in periodic briefings to increase awareness and expertise in different security disciplines. "Security Champions" have additional training to help develop these roles as Software Security subject-matter experts. You may need to customize the way you create and support "Security Champions" for cultural reasons.
216+
217+
The goals of the position are to increase effectiveness and efficiency of application security and compliance and to strengthen the relationship between various teams and Information Security. To achieve these objectives, "Security Champions" assist with researching, verifying, and prioritizing security and compliance related software defects. They are involved in all Risk Assessments, Threat Assessments, and Architectural Reviews to help identify opportunities to remediate security defects by making the architecture of the application more resilient and reducing the attack threat surface.
218+
219+
[Source: OWASP SAMM](https://owaspsamm.org/model/governance/education-and-guidance/stream-b/)
234220
implementation:
235221
- $ref: src/assets/YAML/default/implementations.yaml#/implementations/owasp-security-champ
236222
references:

0 commit comments

Comments
 (0)