Analyzing Software Security Practices with Synopsys’ iMan Louis
BSIMM14 is the latest edition of the annual Building Security in Maturity Model (BSIMM) report analyzing the software security practices across 130 organizations, including some of the most advanced companies in cloud, financial services, FinTech, ISV, insurance, IoT, healthcare, and technology industries. This year’s findings revealed a clear trend of firms increasingly taking advantage of security automation to replace manual, subject matter expert–driven security activities to reduce cost and improve effectiveness. Greater automation has enabled organizations to embrace the shift everywhere philosophy, with automated, event-driven security testing increasing by 200% over the last two years.
Transcript
This is Textron tv. Hey everyone, welcome back here to techron tv. I'm happy to have a a, it's first time here on Textron tv.
So let's welcome Iman Lewis. Iman is a managing security consultant with the Synopsis Software Integrity Group. Im, and welcome, welcome to Text Drunk tv.
It's great to have you on here. Thanks, Alan. It's my honor to be here.
So, uh, it really is ours, but Im, you know what, I always like to give people a sense of who they're talking to. I mentioned you with the managing security consultant at, at Synopsis Software Integrity Group, but why don't you give people a little bit of a peek into your journey, your career? Happy to, Alan.
So I, my earlier background in, uh, software development, I worked for RBC 14 for 13 years on, uh, designing and developing software. And then near the end, I helped bootstrap the application security program there. And then the last 13 years I've been with Synopsis, the software integrity group, and I've been a, in the beginning I was, uh, doing penetration testing, code reviews, and quickly move to, uh, management consulting where I help, uh, our clients, various organizations of various sizes and verticals build their application security programs, measure its success, and take it to the next level.
So, and finally, I'm a certified B Bcim assessor, and I think that's gonna be the focus of our chat today. Absolutely. Before we jump into BS IMM though, you know, synopsis is a, I mean, there's many different parts, tentacles to the Synopsis family of, of products and services.
Some of our audience may be familiar with synopsis, like with open source software and, and other, some of it around security. Why don't you, if you don't mind, for people who aren't sure, maybe aren't clear, give us an overview of Synopsis that, you know, in general in Synopsis. Happy to.
So Synopsis is probably best known for chip design software, the, the EDA side. I'm from the software integrity group where it's focused on software security. Uh, this is a group that is focused on innovating security tools, but also a, a whole set of professional services, uh, for application and software security.
Think of management consulting, program level consulting, as well as penetration testing, threat modeling code review. And that's the part I've always been with. Excellent.
Um, look, I personally, you know, spent a lot of time with the synopsis, had acquired a company Black Duck. Right, right. A lot of open source and, uh, kind of software security and licensing, and that was a big part of my involvement.
But you're right, it is best known for, you know, hardware chip design. I mean, it's, there's a lot of pieces to the Synopsis family. Yeah, for sure.
Even, even the sig, the software integrity group, uh, is also has, has many parts, as you mentioned, black doc, um, the White Hat acquisition, I came from the S acquisition Right. Was the largest, uh, security consulting firm at the time. Absolutely.
Very, very cool. Um, so we mentioned BS I, right? Again, some of our audience might be familiar with bs i, some don't.
Right. And just for those who aren't bs I is B-S-I-M-M and I'm in, why don't you tell us, if you don't mind, what, what, what, what's the deal with bss? Im, what does it stand for and what is it about?
Sure. So, BS IMM is an observation based model that tries to describe what companies do to build security into their software. It's started in 2008 as a science experiment, and in a few years grew to be the defacto measuring stick for application security.
It's, uh, as I mentioned, it's it's real world observation. So it's not supposed to tell you what you should do to secure your, so your software tells you what everybody does. So in this 14th iteration of bss, IM for example, we have 130 companies, uh, participated and we talk to them.
We gather the data through interviews. So we talk to them about everything they do, and we have 126 distinct activities or controls, if you wish, uh, that they tell us they do. And, and these companies have, um, about 11,000 security professionals helping 270,000 developers develop about 97,000 applications.
So it's a lot of data. It gives us great insights and trends into what folks do. You can measure yourself with bs, imm, and then see this is how everybody does software security, this is how we do it, and you judge whether this is good or bad.
So we try not to heavily interpret the data, but we try to give the keys for a lot of interpretation. BSM provides a lot of opportunities for reflection, and a lot of people use it for, uh, to inform their decisions, to plan their budgets and resources. So for examples, companies would look at BS bm and uh, they say, oh, we're above the average in pen testing, but we're significantly below the average in secure design activities.
So instead of investing even more next year, they may decide to redistribute some of the funds or lobby for more funds and resources to do security testing because, you know, still pen testing is important. You know, few people can argue with pen test findings like they can with theoretical threat modeling, for example. But if you discover design flaws late in the game, it's very expensive to try and refactor the design.
So it gives you a lot of comparison. I'm just using one example. Remember there are 126 activities like that.
And then, uh, people use it not only to compare themselves to everybody, 130 firms, but also to a vertical of their choosing. So clo to closer peers. Other companies use it to compare themselves to their previous results.
So some of the CISOs that've had had, uh, be, uh, done in the past when they join a new company that one of the first things they do is they commission a bcim assessment. Not only this gives them an X-ray of their program, but also kind of takes a snapshot of the current state of the program and maybe 18 or 24 months later, they measure again and be able to see the delta and make sure that, uh, they're achieving the roadmap. So, uh, some companies will use it to differentiate themselves in the marketplace.
Um, and we'll, we'll talk about, uh, trends. So every year people follow the BAM report, because it's a real world model. It has to continue to be descriptive to describe the dynamic landscape we have.
So every year based, we drop older data from the model to keep it fresh. And, uh, if we see new activities, we consider adding it to the model. If we see, uh, an activity that is no longer observed for a few years, we consider dropping it, although this is rare.
Uh, but other than that, the bcim is broken down by levels. So level one activities are common activities. Level three are rare.
We call them rocket science. So activities may move up and down based on statistical frequency. 'cause this is how the levels are broken down.
Got it. Mm-Hmm. Yeah, so that's No, no, keep going.
Yeah, I can get into the trends. So the, the, the, this year, some of the trends, for example, Is, well hold on. Before we jump into this year's trends, we should mention this is this particular, uh, report and, and look at, you know, software security practices.
Um, is is BS M 14, right? So this is 14 years basically exactly in, in the making here. That's, that's quite a body of work.
And yes. So when we, when we talk about trends, we're seeing, we're talking about trends that we've seen developing across multiple years here, even in, in some, in some ways. But I just wanna give people the context of that.
I'm sorry. I mean, Go ahead. Thank you for that.
Yeah. So, uh, one of the trends we're seeing is because of greater automation is more accessible, now we're seeing more companies adopt, uh, shift everywhere philosophy. So not only they're shifting left, you know, doing pen testing, but also scanning code, dynamic analysis, threat modeling, defining security requirements, or even be before a project starts training their engineers on secure development practices.
So we're seeing an op tech in, in activities like making code review mandatory for all projects, uh, activities that are describe, including test automation as part of qa. So the testers that typically focused on functional testing now include security test cases. 'cause you know, security is part of quality.
You can't say we have quality software if it's not secure. So they're starting to build secure test, uh, security test cases into their queue. Automation not waiting, uh, till penetration testing, for example, but not just in the SDLC.
So shift everywhere is really about producing smart telemetry that can inform risk-based decision making, uh, for all stakeholders. So security application security is not just the responsibility of the central security group or the development team, but it's a shared responsibility with areas like legal audit compliance, vendor management, of course, infrastructure, security, cloud security, container security. So shift everywhere.
Somebody defined it as running the right test on the right object, the right time, and then given the results to the right person to make the right call. So it's, it's about putting sensors and, and tests in the old smart, uh, places to, to give, uh, those various stakeholders information to, to be able to make, uh, the right calls. So that's one trend.
Another trend we're seeing is, and this is a downward trend, uh, is the reduction of activities that require manual effort by subject matter experts. And this is no surprise, given the recent economic conditions, companies are looking to, uh, cut out expensive activities, um, and replace it with automation. So an example of such an activity that we observed last this year is using and maintaining a top and attack list.
So this is where com companies would curate top five, top seven, top 10, perhaps attacks that they wanna focus on. So similar to awas top 10, but this is a list that is specific to this company, uh, perhaps informed by their own threat intelligence, their environment, uh, metrics from their, their SDLC defect discovery mechanisms. So, uh, curating and maintaining this list requires expertise and requires manual effort.
So we're seeing such activities decrease this year. Another, uh, upward trend we're seeing is, uh, creation of SBOs. And again, due to the executive orders, more and more companies tell us now we produce software builds of material and related to that, more and more companies tell us we are scanning for open source software.
And, and in the BC model, we have two activities, uh, related to open source. One is a level one activity means it's, it's very common. It's scanning, uh, for open source.
Uh, but there is a, a higher maturity activity where companies have a holistic program to control the risk associated with, uh, use of open source. So it's not just scanning and identifying, but also addressing, mitigating, remediating, accepting the risk, but also proactive measures. So some companies tell us, we don't wanna wait till a vulnerability exists in our code base because of open source, basically finding it through a scan.
But they may, for example, this allow developers from downloading open source from the internet and give them an internal repository of vetted packages. Some companies would have categories allowed software, so, oh, you want to use the latest version of jQuery, for example, it's on the allowed list. Go ahead.
Or you want to use that other package? No, that's on the prohibited list. And maybe a middle category for conditional use, uh, packages that are not recommended.
But if you have a a business case, we'll, we'll look into it. So that's an upward trend. Another trend we're seeing is that companies now expect more from their software vendors in terms of security practices.
So they're, they have stricter, uh, expectations or demands on the supply chain. So companies now make more explicit effort not only to include security SLAs and SLOs in their software contracts, but hold the vendor's fee to the fire, so to speak. So tell it, tell me how you actually fulfill your obligation.
Uh, show me your, uh, secure SDLC practices or policies or, or standards. Uh, maybe get up and test done by a third party and share with me the results or the attestation letter. Or some companies would have their vendors to go get a decent measurement, and we have a, a lighter version of bs.
Im called BM SE for supply chain. Uh, so they tell them, you know, go get a measurement by bs Im, and share the results with me so I can gauge how mature your organization is when it comes to security practices. So that's another, uh, upward trend we're seeing.
The final, uh, trend I'm gonna mention is the Inc ongoing and increased, uh, use of security champions. And I want to take a a a second to define security champions. So we're talking about engineering folks, not security professionals, but they are trained to take the security message into their teams and they act as a first line of defense.
So think of a developer, a tester, a DevSecOps engineer, an architect, uh, a dev manager, a business analyst, and so on. These still perhaps 80%, uh, still engineers, but 20% security, um, resident experts. So, and based on their role, uh, they may be able to help with technical code remediation or something like that, but all of them, uh, raise awareness process, what, uh, checkpoints the teams need to go through for security.
What, um, and if it's a developer, for example, they may be able to provide specific remediation guidance or fix vulnerability. So the trend we're seeing is that companies that have security champions score on average 25% more that than companies that do not. And we have like six categories for That's fantastic.
Yeah. That's significant. That's very interesting.
Yeah. And, and it's, and, and we have a direct correlation, very visible. We have six categories of score.
So the highest two categories for score, over 80% of the companies in those two buckets have security champions programs. The lowest two categories, 80% don't have security champions, and the middle two categories about 50 50. So it's, it's a direct correlation, if not even causal correlation here.
That's, that's unbelievable how quick it is. I mean, we're about outta time for people who want to download and get more information, well get more information, potentially download the report, where can we send them? com/software will take them the soft to the software integrity group, uh, site.
And there is a banner for BS IM where they can download the full BIM study. Um, and, uh, and it, again, it provides a lot of information, a lot of visual, a lot of charts that are very informative. Excellent, man.
I mean, I want to thank you for coming up here on techstrong TV and, and telling our, you know, sharing with our audience the, the latest findings here in this BS Im report. My, My pleasure, Alan, thank you for having me here. Ah, it's a pleasure, man.
Keep up the great work and say hello to everyone at Synopsis. We're gonna take a break here on Tech Junk. We'll be back here in a moment.