Checkmarx Codebashing Training
Applications are the digital coalface for many workers. Security is critical when developing applications for in-house use, and also for those destined for release on the web and app stores. DevOps, agile, and other workflows have transformed application development cycles and reduced time to release for new application code. The need to incorporate security at the core of all application development has become important and is being realised and promoted via DevSecOps workflow processes.
This is due to the realisation that security needs to be built into development workflows from the start. Not thought about after the code has been written and has passed testing. Transforming development and operations teams to have security foremost in their minds can be tough. Both groups have a lot to think about already, and they work in an ever-changing landscape when it comes to development practices and technologies.
Providing developers and operations professionals with security training annually and hoping that they incorporate what they learn into their daily activities ignores the reality of both human nature and most DevOps team workloads.
Checkmarx Codebashing has been designed from first principles to allow security awareness to be inserted into, and used, at every stage of the software development lifecycle. Codebashing uses open communication, ongoing engagement, gamified training, and on-the-spot remediation. It allows the Chief Security Officer (CSO), or other security managers tasked with ensuring application and data security, to cultivate and deliver a culture that has application security at its core. Codebashing’s gamified approach provides fun, interactive, and scalable content to train developers in-app security knowledge and best practices. Built for developers by developers, Codebashing is security training that your development team will want to complete.
Being an integral part of Checkmarx, Codebashing makes use of real-world examples and best practices gained from years of experience from 1400+ customers. If you want to give your developers the training they need to be security-focused, then contact Renaissance to find out more.
Codebashing Content
Codebashing provides easy to digest snippets for application developers. As they progress through the training, examples are presented of real-world issues and vulnerabilities in real environments for developers to troubleshoot and solve. Over time they will become aware of how to spot common security errors in their code. Plus, they will be taught how risky code is developed in the first place and how to avoid repeating common mistakes.
Unlike traditional classroom or video-based training, Codebashing is a hands-on, interactive solution that fits into developers’ daily routines. Rather than spending a whole day learning about security vulnerabilities out-of-context, developers receive bite-size, on-demand sessions that are relevant to the specific challenges they are facing in their code. Ongoing training campaigns that target particular security goals can be presented to developers throughout the year. The philosophy behind this training approach is to empower developers over the long term and to make application security coding integral to how they work. By changing their mindset on how to code securely, the goal is to reduce code issues over time.
Codebashing Tracking
The Codebashing self-service management portal makes it easy for individual developers to track their progress. The analytics engine makes it easy for security managers to highlight gaps in training, track progress, and provide an overall picture of all developer’s security training.
While the training is gamified to help developers retain the knowledge, Codebashing is not just for fun. The training techniques combined with the comprehensive tracking and analytics deliver results in better application security and more skilled staff.
Some regulatory standards, such as PCI-DSS that govern organisations that process credit card information and transactions, need to demonstrate that their developers are getting “role-based security training” and “developer security training”. The Codebashing tracking and analytics engine helps organisations demonstrate compliance.
Codebashing Integration
Codebashing integrates with the Checkmarx Static Application Security Testing (CAST) solution. CAST does static analysis on custom code and highlights security vulnerabilities. As well as providing actionable insights on how to fix any issues found, CAST will also link to the relevant training sessions in Codebashing to allow developers who wrote the code to review the corresponding content on why the code is a security issue, and how to prevent them in future.

