Bouvet Security Champion
Why “Security Champion”
The term “Security Champion” has become an established concept to encompass people who do not necessarily work directly with security but who can act as a bridge between formal security roles and development teams.
There are many ways to implement a Security Champion program; OWASP has a relatively comprehensive list of points for a program where Security Champions have a more formal role. At Bouvet, we have chosen a slightly different solution inspired by NAV and Equinor where it is more informal.
What does a Security Champion do?
This will vary between regions, units, and teams, but a typical Security Champion will raise issues or ask questions related to security, and help the team focus on- and prioritize issues related to security with everything else. The Slack channel #security-champions is used to announce events, share useful information and anything else related to Security Champions in Bouvet. Every month there is a virtual gathering for all Security Champions, typically with a summary of relevant news, a talk related to security and a quiz with a symbolic prize.
In addition, many use the Slack channel #sikkerhet to share news, ask questions, or post tips and tricks. Some regions also have regular meetings for all Security Champions, in addition to arranging courses, meetups, lectures, and much more.
Bouvet is becoming a large company with a wide range of projects we work on, and security is a vast area where everyone has something new to learn every day. We love sharing knowledge, so it’s great if YOU want to get involved and share what you know with others - no matter how low or high the threshold for understanding might be.
And most importantly, we primarily sell competence, and more engaged Security Champions is never a negative thing. If you are unsure about what you are allowed to do or not, talk to your nearest manager and other Security Champions in the region, and you will surely find a solution.
More information
- OWASP: Security Culture
- Bouvet: Sikkerhet i oppdrag (BLS) (Requires Bouvet user)
- NAV: Security Champion
- Equinor: Security Champion