3 ms·
In my roughly 10 years of experience at megacorps, security related work towards products is generally treated like a compliance matter for the company, for bet
by pseudoramble 5y ago
In my roughly 10 years of experience at megacorps, security related work towards products is generally treated like a compliance matter for the company, for better or worse. My experience in summary:
Testing: the security team run a few ad hoc tests, or only run the app team's automated security tests, or not at all.
Models: Once I built a threat model interactively with a security team member, but most times they'd ask the app team to put it together and send it to them. Usually would be reviewed with a few questions.
Paperwork: most of the is spent filling out forms, looking at automated tool results and addressing as needed, providing spreadsheets with new features or changes and their security requirements.
Code analysis: I don't think I've ever had a security team member read source code. Maybe I'm not remembering, but I genuinely can't think of one. I would love to have this happen though.
So, I guess I haven't had a good experience with security teams overall. I don't generally attribute that to the team itself though. They're often way over taxed and trying to oversee upwards of 10 projects with tons of reporting requirements and deadlines for releases. There's really no way in their structure or funding they _could_ do more than this. It's kinda amazing they even get this much stuff done now that I think about it! But yeah, I've never had an experience like you describe.
- v-erne 5y ago> Code analysis: I don't think I've ever had a security team member read source code. Maybe I'm not remembering, but I genuinely can't think of one. I would love to have this happen though. I think this is cost prohibitive - You would need person that knows a lot about security and can program (and what is more a programmer that can read code to find vulnerabilities - this is whole another level). Running tools and building models requires a lot cheaper personnel and I suspects that megacorps security starts from bottom line up.
- pseudoramble 5y agoYeah fully agree. It's a big ask. Reading my comments again today, I made it sound more negative than I should have. It would be awesome to have that, but often unrealistic. About bottom up training, I'd also love to have some extensive training on app security too. I know some basics, but learning some more systematic security testing would be cool.