The Open Source Software Security Mobilization Plan: A new hope for developer-driven security

General News

Summary

We’ve spent a long time waiting for a hero to come along and rescue us from the cybersecurity baddies that seem to hold more power than we thought possible, even 10 years ago. What is especially interesting is their focus on baseline education and certification at the developer level, and measures designed to streamline internal Software Bill of Materials (SBOM) activities. We know from experience that developers do respond well to incentives, and that tiered badging systems showing progress and skill work just as well in a learning environment as they do on something like Steam or Xbox. These alone would go a long way in decreasing the burden of yet another SDLC task for developers who are already spinning a lot of plates to create software at the speed of demand. It took a “Rebel Alliance” of some powerful players coming together, but this serves as proof that we are heading in the right direction and leaving behind the idea that the cybersecurity skills gap will magically fix itself.

Classifications

industries
Fintech & Banking
applications
Accounting and Taxes

AskAI Classifications

Labels
Enterprise Software SaaS Data Streaming Platforms

Linked Companies

IBM
$1B+
Semmle
$1M to $5M
Informix
$10M to $25M