In this chapter, we discussed three typical security assurance programs. The SDL focused on the security activities in each development stage. The OWASP SAMM defined security activities in four different functions. The ISO 27001 provided an overview of the security management program. These are the foundations on which we can build our own security guidelines, process, checklist, or toolkits.
As a business grows, the need and the scope of security gets complicated. We divided security growth into five stages. In stage one, we began with the basic need for security control. In stage two, an organization may build its own in-house security testing team. In stage three, the security activities apply SDL to the larger scope and shift to the left—to the development team—in the early design stage. In this stage, most security tools or automation are applied not...