<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Security Awareness Training - On-Site and Program Development in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/Security-Awareness-Training-On-Site-and-Program-Development/m-p/23530#M1375</link>
    <description>&lt;P&gt;I know that this has been asked in various forms before, but not many answers were provided.&amp;nbsp; &amp;nbsp;We are looking for security and best practice computer based training specifically geared towards our development staff.&amp;nbsp; I know about Wombat, KnowBe4 etc. but they want to charge us for all of our staff and not just our development staff.&amp;nbsp; &amp;nbsp;Any help would be appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Barry Silbiger&lt;/P&gt;</description>
    <pubDate>Mon, 09 Oct 2023 09:13:54 GMT</pubDate>
    <dc:creator>bsilbiger</dc:creator>
    <dc:date>2023-10-09T09:13:54Z</dc:date>
    <item>
      <title>Security Awareness Training - On-Site and Program Development</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Security-Awareness-Training-On-Site-and-Program-Development/m-p/23530#M1375</link>
      <description>&lt;P&gt;I know that this has been asked in various forms before, but not many answers were provided.&amp;nbsp; &amp;nbsp;We are looking for security and best practice computer based training specifically geared towards our development staff.&amp;nbsp; I know about Wombat, KnowBe4 etc. but they want to charge us for all of our staff and not just our development staff.&amp;nbsp; &amp;nbsp;Any help would be appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Barry Silbiger&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 09:13:54 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Security-Awareness-Training-On-Site-and-Program-Development/m-p/23530#M1375</guid>
      <dc:creator>bsilbiger</dc:creator>
      <dc:date>2023-10-09T09:13:54Z</dc:date>
    </item>
    <item>
      <title>Re: Security Awareness Training - On-Site and Program Development</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Security-Awareness-Training-On-Site-and-Program-Development/m-p/23536#M1376</link>
      <description>&lt;P&gt;So in one company that I worked at, we developed our own materials.&amp;nbsp; Maybe not the same quality as Wombat or others but it worked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Some sites offer free information that you can use:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.owasp.org/index.php/Security_by_Design_Principles" target="_blank"&gt;https://www.owasp.org/index.php/Security_by_Design_Principles&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://resources.infosecinstitute.com/7-security-awareness-tips-for-developers-in-your-organization/" target="_blank"&gt;https://resources.infosecinstitute.com/7-security-awareness-tips-for-developers-in-your-organization/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://resources.infosecinstitute.com/category/enterprise/securityawareness/security-awareness-fundamentals/top-20-security-awareness-tips-tricks/#gref" target="_blank"&gt;https://resources.infosecinstitute.com/category/enterprise/securityawareness/security-awareness-fundamentals/top-20-security-awareness-tips-tricks/#gref&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So downsides to this, like everything if a contractor says it, it's gospel, if you say it, it can be ignored.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not sure the pricing model for this one but SANS has a decent program for developers:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.sans.org/security-awareness-training/products/developer" target="_blank"&gt;https://www.sans.org/security-awareness-training/products/developer&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope some of this helps&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Diana&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2019 15:54:15 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Security-Awareness-Training-On-Site-and-Program-Development/m-p/23536#M1376</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2019-06-11T15:54:15Z</dc:date>
    </item>
    <item>
      <title>Re: Security Awareness Training - On-Site and Program Development</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Security-Awareness-Training-On-Site-and-Program-Development/m-p/23559#M1382</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/303948305"&gt;@bsilbiger&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;I... &amp;nbsp;I know about Wombat, KnowBe4 etc. but they want to charge us for all of our staff and not just our development staff.\&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Barry, I realize there will be a cost differential, but think of the advantage of having the entire company understand your core business framework! Also, I expect you have support staff who would like to cross-train into developer roles. This initial awareness training is a nice entry point.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Finally, your entire company is subject to phishing, and many non-developers have access to parts of your program. ALL of the staff has access to the network that your developers use for general admin work. A breach of your general use network can most easily move into your development network by rather simple actions on the part of developers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Therefore, please reconsider your plan to limit security awareness training only to the developers. You may be in a classic teeny wise, pound foolish decision cycle.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good luck,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2019 19:14:09 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Security-Awareness-Training-On-Site-and-Program-Development/m-p/23559#M1382</guid>
      <dc:creator>CraginS</dc:creator>
      <dc:date>2019-06-11T19:14:09Z</dc:date>
    </item>
    <item>
      <title>Re: Security Awareness Training - On-Site and Program Development</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Security-Awareness-Training-On-Site-and-Program-Development/m-p/23561#M1383</link>
      <description>&lt;P&gt;We already have an overall security awareness training that covers Phishing, social engineering, best practices for end users etc.&amp;nbsp; We are looking for developer specific training to make our secure coding practices better.&amp;nbsp; We are not being foolish we are trying to enhance what we already have in place for a practice that is integral to our company growth.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2019 19:30:30 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Security-Awareness-Training-On-Site-and-Program-Development/m-p/23561#M1383</guid>
      <dc:creator>bsilbiger</dc:creator>
      <dc:date>2019-06-11T19:30:30Z</dc:date>
    </item>
    <item>
      <title>Re: Security Awareness Training - On-Site and Program Development</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Security-Awareness-Training-On-Site-and-Program-Development/m-p/23569#M1384</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/303948305"&gt;@bsilbiger&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;We already have an overall security awareness training that covers Phishing, social engineering, best practices for end users etc.&amp;nbsp; We are looking for developer specific training to make our secure coding practices better.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I think this is a common refrain. The security awareness products out there - even the quality ones - are too generic. Something is needed between them and, say, having an entire department go through a certification test/process. The challenge for a training provider is that it takes a lot of work (i.e. money) to build such a course but there isn't a guarantee of a demand for it outside a specific client. From the company standpoint, they don't want to spend too much money. You'd think there is a market, but the reality is the subject matter may be too much of a niche. It's a bit like building an electric pick-up truck (all deference to Tesla). There's a need, but maybe not a market.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2019 21:50:49 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Security-Awareness-Training-On-Site-and-Program-Development/m-p/23569#M1384</guid>
      <dc:creator>JoePete</dc:creator>
      <dc:date>2019-06-11T21:50:49Z</dc:date>
    </item>
    <item>
      <title>Re: Security Awareness Training - On-Site and Program Development</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Security-Awareness-Training-On-Site-and-Program-Development/m-p/23570#M1385</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/303948305"&gt;@bsilbiger&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;We already have an overall security awareness training that covers Phishing, social engineering, best practices for end users etc.&amp;nbsp; We are looking for developer specific training to make our secure coding practices better.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I think this is a common refrain. The security awareness products out there - even the quality ones - are too generic. Something is needed between them and, say, having an entire department go through a certification test/process. The challenge for a training provider is that it takes a lot of work (i.e. money) to build such a course but there isn't a guarantee of a demand for it outside a specific client. From the company standpoint, they don't want to spend too much money. You'd think there is a market, but the reality is the subject matter may be too much of a niche. It's a bit like building an electric pick-up truck (all deference to Tesla). There's a need, but maybe not a market.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2019 21:51:51 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Security-Awareness-Training-On-Site-and-Program-Development/m-p/23570#M1385</guid>
      <dc:creator>JoePete</dc:creator>
      <dc:date>2019-06-11T21:51:51Z</dc:date>
    </item>
    <item>
      <title>Re: Security Awareness Training - On-Site and Program Development</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Security-Awareness-Training-On-Site-and-Program-Development/m-p/23889#M1400</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/303948305"&gt;@bsilbiger&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;We already have an overall security awareness training that covers Phishing, social engineering, best practices for end users etc.&amp;nbsp; We are looking for developer specific training to make our secure coding practices better.&amp;nbsp; We are not being foolish we are trying to enhance what we already have in place for a practice that is integral to our company growth.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;AH, Barry, I was misled by use of the term "&lt;EM&gt;Security Awareness Training&lt;/EM&gt;." That term normally refers to the general e-mail, password, and phishing protection training you describe for your general employees.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think what you are looking for is not Awareness Training, but rather &lt;STRONG&gt;&lt;EM&gt;Secure Development Training.&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How about putting all of your developers through training leading to the &lt;EM&gt;&lt;STRONG&gt;Certified Secure Software Lifecycle Professional (CSSLP)&lt;/STRONG&gt;&lt;/EM&gt;, and give a bonus to those who actually achieve the certification?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2019 17:05:18 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Security-Awareness-Training-On-Site-and-Program-Development/m-p/23889#M1400</guid>
      <dc:creator>CraginS</dc:creator>
      <dc:date>2019-06-18T17:05:18Z</dc:date>
    </item>
  </channel>
</rss>

