What’s CSEC up to?
What’s CSEC up to?
Better would be constructing a system where government-paid appsec teams are granted access to cloud source control repos for all projects + ability to randomly pentest whatever they desire.
If a breach is found (in release candidate stage or prod), the offender's contract is reduced by the prize amount, and that amount goes into the appsec team's budget.
The only way to make people care about appsec is to (1) increase the likelihood and frequency of exploits & (2) ensure exploits have direct budgetary impact on the teams developing the software.
It's easy to say "Our systems are secure and follow all standards" when they aren't and they don't.
It's harder to explain why projects keep coming up with multiple successful pentests or security flags.
Increasing visibility of risk and aligning incentives, with a credible and independent validation party, is the solution.
The biggest gotcha: payment must be for a successful penetration, and must not be for some paperwork flagging of minutiae.
What's not so secret is that CSEC pays low and kills your career growth.
Are there any wider implications whete security doesn't get taken like we expect it to as a result?