Blog

セキュア・コード・トレーニングがうまくいかない理由 (そしてそれに対してできること)

April 8, 2021
セキュア・コード・ウォリアー

つまらない、つまらない、つまらない!これは、セキュア・コード・トレーニングについて言及されるたびに、開発者からよく聞く回答の 1 つです。Secure Code Warriorでは、もっと良い方法があるはずだと考えているため、安全なコーディング、安全なコード慣行、およびセキュリティ運用に対する開発者の態度を調査するために、Evans Data Corp. と協力して一次調査を行いました(ホワイトペーパーをダウンロード)。 ここに)。

間もなくリリースされる予定の 対応から予防への移行:アプリケーションセキュリティの様相の変化、開発者に現在のセキュアコードトレーニングの主な問題について尋ねたところ、答えは明らかでした。

開発者を失望させるトレーニング

Current secure code training, that companies provide does not stack up.
企業が提供している現在のセキュアコードトレーニングは、実践的でも仕事にも適していないと見なされています。

調査対象開発者の 40% セキュアコーディングは真空中で教えられているように感じました。別の40%は、トレーニングが理論的すぎて、仕事とは関係がなく、「実践的」では不十分だと感じていました。30% は、毎日取り組んでいる言語、フレームワークのトレーニングが不足していると回答しました。これは深刻です。というのも、現在のセキュア・コード・トレーニングは文脈的に無関係であり、開発者が日常的に行っていることと意味のある関係がないことを教えてくれるからです。

多くの開発者にとって、彼らの主な課題は、気が遠くなるようなハンズオフのアクティビティの間、目を覚まし続けることです。これらのアクティビティは、効果的でもなく、セキュリティを最優先に考えようともしません。

孤立した環境でトレーニングを行うと、開発者は研究室と現実の世界との間を認知的に結びつけることができなくなります。

開発者がセキュア・コード・トレーニングに求める3つのこと:

  1. 圧倒的に、開発者は、より実践的で、より状況に応じた日常業務に役立つトレーニングを求めていると答えています。
  2. 開発者の 65% が、より多くのトレーニングが必要だと答えています 言語固有の脆弱性OWASP トップ10
  3. 調査対象の開発者の 75% は、体系的な実地研修を希望しています。

開発者を元気づけるトレーニング

OJT(実地研修)に関しては、開発者はある程度の経験と既存の知識を持ち合わせています。これは、「足場に基づいた」学習が必要であることを示しています。これは、開発者がすでに知っている内容に基づいて構築された、つまり足場のあるトレーニングです。足場型教育は、これまでの経験を活気づけ、向上させると同時に、新しいスキルを少しずつ身につけ続けます。そのため、実地学習に最適な手段となります。

定着するスキルの伝達

開発者のセキュリティトレーニングに関しては、開発者は理論に基づいた静的学習という骨の折れる作業よりも、実践による学習方法を好むことがわかっています。その意味では、関連性が高く、状況に応じた環境で安全にコーディングする方法を学ぶことが重要です。セキュア・コーディングにおける変革の推進者として、Secure Code Warriorは、開発者が現実世界で直面しているような課題について、関連するプログラミング言語とフレームワークについて、状況に応じた実践的な教育を行っています。学習コンテンツには、重要なOWASPトップ10、OWASPモバイルトップ10、OWASP APIセキュリティトップ10、CWE/SANSトップ25など、147種類以上の異なる脆弱性タイプを対象とした5,500を超える課題とミッションが含まれています。

チームへの潜在的な影響と、安全なコードをより迅速に提供する能力を確認したい場合は、 デモを予約 今。


キャッチフレーズ

Govern AI-driven development before it ships

Measure AI-assisted risk, enforce secure coding policy at commit, and accelerate secure delivery across your SDLC.

book a demo
キャッチフレーズ

Explore more blogs

これは、オーラが射手と鼻の穴を広げることによって、腸管を熱的に発芽させ、臭いを帯びていることを防ぐためのものです。

browse all
Case Study
Filter Label
This is some text inside of a div block.

Supercharged Security Awareness: How Tournaments are Inspiring Developers at Erste Group

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
Case Study
Filter Label
This is some text inside of a div block.

Security as culture: How Blue Prism cultivates world-class secure developers

Learn how Blue Prism, the global leader in intelligent automation for the enterprise, used Secure Code Warrior's agile learning platform to create a security-first culture with their developers, achieve their business goals, and ship secure code at speed

Learn More
Case Study
Filter Label
This is some text inside of a div block.

One Culture of Security: How Sage built their security champions program with agile secure code learning

Discover how Sage enhanced security with a flexible, relationship-focused approach, creating 200+ security champions and achieving measurable risk reduction.

Learn More
Blog
Filter Label
This is some text inside of a div block.

Are you a CISO or Engineering Leader worried about the Security and Cost of LLM code generation?

Review the SCW AI Trust Index, our proprietary LLM benchmarking data, before going all-in on an AI model.

Learn More
Blog
Filter Label
This is some text inside of a div block.

Enabler 6: Regular Reporting to Leadership

Executive buy-in doesn't sustain itself. Enabler 6 shows how regular reporting keeps leadership engaged, informed, and invested in program success.

Learn More
Blog
Filter Label
This is some text inside of a div block.

The Future of AI Software Governance Is Built on Strong Partnerships

Discover why Secure Code Warrior is becoming a channel-first company and how trusted partners help organizations adopt AI Software Governance securely and at scale.

Learn More

Secure AI-driven development before it ships

See developer risk, enforce policy, and prevent vulnerabilities across your software development lifecycle.

Book a demo