Scorecarding Security: A Collaborative Approach to Risk Management
In his blog post "Scorecarding Security," Rami McCarthy explores the concept of scorecarding as a strategic method to enhance security programs through collaboration and transparency. He highlights that organizations like Chime, Netflix, GitHub, and Atlassian have implemented scorecarding systems to quantify security posture, promote accountability, and foster a culture of continuous improvement. These systems often feature centralized dashboards, extensible scoring models, and gamified elements to engage engineering teams without imposing rigid controls. McCarthy emphasizes the importance of building trust between security and engineering teams, avoiding adversarial dynamics, and recognizing that security teams are not omniscient. He provides practical advice for implementing scorecarding, such as starting with high-signal data sources, allowing for risk acceptance, and celebrating incremental progress to encourage positive security behaviors.
Comments
Post a Comment