<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/index.php?action=history&amp;feed=atom&amp;title=Joel_Test_for_AppSec</id>
		<title>Joel Test for AppSec - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/index.php?action=history&amp;feed=atom&amp;title=Joel_Test_for_AppSec"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Joel_Test_for_AppSec&amp;action=history"/>
		<updated>2026-04-04T15:36:55Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Joel_Test_for_AppSec&amp;diff=237898&amp;oldid=prev</id>
		<title>Avi Douglen: Created page with &quot;At the [https://owaspsummit.org/ OWASP Summit 2017], there was held a session on [https://owaspsummit.org/Outcomes/Education/Recruiting-AppSec-Talent.html Recruiting AppSec Ta...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Joel_Test_for_AppSec&amp;diff=237898&amp;oldid=prev"/>
				<updated>2018-02-19T23:51:38Z</updated>
		
		<summary type="html">&lt;p&gt;Created page with &amp;quot;At the [https://owaspsummit.org/ OWASP Summit 2017], there was held a session on [https://owaspsummit.org/Outcomes/Education/Recruiting-AppSec-Talent.html Recruiting AppSec Ta...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;At the [https://owaspsummit.org/ OWASP Summit 2017], there was held a session on [https://owaspsummit.org/Outcomes/Education/Recruiting-AppSec-Talent.html Recruiting AppSec Talent] with the purpose of improving the recruitment cycle, including improving job postings and suggested next steps for AppSec Managers looking for long-term growth of their team. &lt;br /&gt;
&lt;br /&gt;
We discussed the gap between companies’ needs to recruit talented AppSec people, and attracting the best AppSec people to work at their company. The [https://www.joelonsoftware.com/2000/08/09/the-joel-test-12-steps-to-better-code/ Joel Test] is a quick indicator of Development culture: an irresponsible, sloppy test to rate the quality of a software team. We adapted the Joel Test to be a quick indicator of a company’s AppSec culture. The test’s purpose is to help companies attract the right talent and help talent to find the right company&lt;br /&gt;
&lt;br /&gt;
First draft of the AppSec Joel Test (in no specific order):&lt;br /&gt;
* Does the company fund ongoing education for AppSec hires?&lt;br /&gt;
* Do developers undergo periodic AppSec training?&lt;br /&gt;
* Do AppSec people have a quiet working environment?&lt;br /&gt;
* Are there both offense and defense teams; do they work together?&lt;br /&gt;
* Can the AppSec team delay release (or fix) a new version or product?&lt;br /&gt;
* Is the AppSec team involved throughout the development lifecycle process?&lt;br /&gt;
* Can I access developers directly?&lt;br /&gt;
* Are security bugs treated like functional bugs?&lt;br /&gt;
* Is there some form of SDL / Maturity model / or other process in place?&lt;br /&gt;
* Can AppSec people choose their own tools (paid for by the company)?&lt;br /&gt;
* Is there a dedicated Incident Response team?&lt;br /&gt;
* Does the company contribute to Open Source and community efforts (or support personal contributions)?&lt;/div&gt;</summary>
		<author><name>Avi Douglen</name></author>	</entry>

	</feed>