Skip to content

Commit

Permalink
Fixed bullet points
Browse files Browse the repository at this point in the history
  • Loading branch information
robinvanloonOWASP committed Oct 21, 2024
1 parent 62cabda commit 35c59e9
Show file tree
Hide file tree
Showing 5 changed files with 22 additions and 2 deletions.
2 changes: 1 addition & 1 deletion docs/manifesto.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ The OWASP Security Champions Manifesto is a set of guiding principles crucial to
The principles have been drawn from an initial series of in-depth interviews with Application Security leaders from across the globe as part of our wider goal to provide a comprehensive Security Champions playbook.

## Key principles
The Ten Key Principles for a Successful Security Champions Program:
The Ten Key Principles of a Successful Security Champions Program:

1. [Be passionate about security](principles/01_Be_passionate_about_security.md)
2. [Start with a clear vision for your program](principles/02_Start_with_a_clear_vision_for_your_program.md)
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,7 @@ There are several angles for defining a vision for security champions. The most
## How

A successful vision must be:

* Imaginable:<br>
Convey a clear picture of what the future will look like. Translating this to your security champions program, you can consider drawing a security operating model with the roles and responsibilities of the security champions, dev(ops) engineers, IT Leads, Product Owner, and security organizations.
* Desirable:<br>
Expand Down
1 change: 1 addition & 0 deletions docs/principles/08_Reward_responsibility.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,7 @@ Acknowledging and rewarding Security Champions is crucial for several reasons. F
To effectively implement this principle, organizations should develop a system that regularly recognizes the efforts of Security Champions. This could include setting up formal recognition programs, offering tangible rewards such as bonuses or professional development opportunities, and providing career advancement possibilities for effective champions. Additionally, regular feedback and expressions of appreciation are essential. Tailoring rewards to individual motivations is also key; some Champions might value public recognition, while others might appreciate personal development opportunities. The system should be designed to align with the organization's culture and policies, ensuring that it is meaningful and sustainable. Please refer to [The Star Model ™](https://www.jaygalbraith.com/services/star-model)or the [PDF](https://jaygalbraith.com/wp-content/uploads/2024/03/StarModel.pdf) for more information on the theory of reward systems.

Supporting Artifacts:

* Recognition Certificate Templates:<br>
Create customizable certificate templates to formally recognize the contributions of Security Champions. These certificates can be awarded for various achievements, like leading a successful security initiative, completing a significant amount of training, or significantly improving the security posture of a project.

Expand Down
14 changes: 14 additions & 0 deletions docs/principles/index.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
# Principles

## The Ten Key Principles of a Successful Security Champions Program

1. [Be passionate about security](01_Be_passionate_about_security.md)
2. [Start with a clear vision for your program](02_Start_with_a_clear_vision_for_your_program.md)
3. [Secure management support](03_Secure_management_support.md)
4. [Nominate a dedicated captain](04_Nominate_a_dedicated_captain.md)
5. [Trust your champions](05_Trust_your_champions.md)
6. [Create a community](06_Create_a_community.md)
7. [Promote knowledge sharing](07_Promote_knowledge_sharing.md)
8. [Reward responsibility](08_Reward_responsibility.md)
9. [Invest in your champions](09_Invest_in_your_champions.md)
10. [Anticipate personnel changes](10_Anticipate_personnel_changes.md)
6 changes: 5 additions & 1 deletion mkdocs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -28,6 +28,9 @@ theme:
icon: material/brightness-4
name: Switch to system preference

markdown_extensions:
- def_list

nav:
- Introduction: index.md
- Manifesto: manifesto.md
Expand All @@ -41,4 +44,5 @@ nav:
- 7. Promote knowledge sharing: principles/07_Promote_knowledge_sharing.md
- 8. Reward responsibility: principles/08_Reward_responsibility.md
- 9. Invest in your champions: principles/09_Invest_in_your_champions.md
- 10. Anticipate personnel changes: principles/10_Anticipate_personnel_changes.md
- 10. Anticipate personnel changes: principles/10_Anticipate_personnel_changes.md
- Project page: https://owasp.org/www-project-security-champions-guidebook/

0 comments on commit 35c59e9

Please sign in to comment.