devsec-building-security-programs

Assess security maturity with OWASP SAMM and plan security roadmaps.

Updated Aug 27, 2026
One-click install
npx skills add https://github.com/wizeline/sdlc-agents --skill devsec-building-security-programs
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: devsec-building-security-programs
Source: https://github.com/wizeline/sdlc-agents/tree/main/aicores/security-agent/skills/devsec-building-security-programs
Command: npx skills add https://github.com/wizeline/sdlc-agents --skill devsec-building-security-programs

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) and assets (resource) components.

What problem does it solve?

This Skill helps organizations build, mature, and sustain a security program that integrates seamlessly with their engineering processes, addressing challenges in program development, maturity assessment, and security culture integration.

Core Features & Use Cases

  • Maturity Assessment: Evaluate your current security program using frameworks like OWASP SAMM.
  • Program Design: Plan and launch initiatives like Security Champions programs and security roadmaps.
  • Culture Integration: Embed security awareness and practices across the engineering organization.
  • Use Case: An engineering leader wants to understand how mature their current application security program is and needs a plan to improve it over the next year. This Skill can provide a SAMM assessment, identify gaps, and propose a phased roadmap.

Quick Start

Act as an application security program advisor to help build and mature our security program.

Frequently Asked Questions about devsec-building-security-programs

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I assess my application security program maturity using OWASP SAMM?

Assess application security program maturity using OWASP SAMM by evaluating current practices across governance, design, implementation, verification, and operations domains to identify gaps and propose a phased security roadmap for improvement.

What is the best way to build a security champions program for engineering teams?

Build a security champions program by embedding security advocates within engineering teams to integrate security culture, drive vulnerability disclosure awareness, and bridge the gap between development and security operations.

Can I use this to create a phased security roadmap for my organization?

Create a phased security roadmap by combining OWASP SAMM maturity assessment results with NIST SSDF practices to prioritize initiatives like security champions programs and vulnerability disclosure policies over a multi-year timeline.

What frameworks does this use to evaluate and mature security programs?

This uses OWASP SAMM for maturity assessment and NIST SSDF for organizational secure software development practices to evaluate, design, and mature application security programs across engineering organizations.

How do I integrate security culture into my engineering organization?

Integrate security culture by launching security champions programs, establishing vulnerability disclosure processes, and embedding security practices directly into engineering workflows using NIST SSDF organizational practices.

Does this support vulnerability disclosure program implementation?

Yes, this provides guidance on implementing vulnerability disclosure programs as part of building and maturing organizational security programs, integrating them with engineering processes and security culture initiatives.