John, the CSO of a cloud software application provider, is planning the security team structure in an organization. The existing security team consists of a secure design team, a secure coding team, and a testing team. The secure design team is in charge of threat modeling, the secure framework, and secure design guidelines. The secure coding team is providing secure coding tools and a checklist for development teams. The secure testing team is doing security verification for every service release. On the other hand, the CSO, Peter, manages the software development team (including developers, QA, and operation members).
Both Peter and John know security is an expert knowledge and that is better to have a dedicated security team to allow the security knowledge to apply across projects and also to enable members to...