--- title: "Dag Flachet -- Kaizen for your Appsec Program" url: https://appsecpodcast.com/dag-flachet-kaizen-for-your-appsec-program/ date: 2025-06-17 duration_seconds: 2154 season: 12 episode: 9 guests: ["Dag Flachet"] topics: ["Building an AppSec Program", "Privacy and Compliance"] audio: https://www.buzzsprout.com/1730684/episodes/17352051-dag-flachet-kaizen-for-your-appsec-program.mp3 video: https://www.youtube.com/watch?v=3FncL6gC8R4 transcript: true --- # Dag Flachet -- Kaizen for your Appsec Program *June 17, 2025 · 36 min · Season 12, episode 9* with [Dag Flachet](https://appsecpodcast.com/guests/dag-flachet/) on [Building an AppSec Program](https://appsecpodcast.com/topics/appsec-programs/), [Privacy and Compliance](https://appsecpodcast.com/topics/privacy-and-compliance/) [Audio](https://www.buzzsprout.com/1730684/episodes/17352051-dag-flachet-kaizen-for-your-appsec-program.mp3) · [Video](https://www.youtube.com/watch?v=3FncL6gC8R4) ## Show notes Dag Flachet joins us to discuss the concept of Kaizen and its application in improving application security. Dag shares his journey into the world of security, emphasizing the importance of iterative, small-step improvements. The conversation delves into how organizations can effectively implement maturity models to enhance their security programs, the limitations of compliance-focused frameworks like ISO 27,000 and SOC 2, and the practical application of Kaizen principles. They also explore the evolution and future updates of OWASP SAM, and the importance of empowering development teams through a bottom-up approach in security enhancement. Dag is the co-founder of Codific, a professor and board member at the Geneva Business School, and an active member of the OWASP Barcelona Chapter and the OWASP SAMM community. The Application Security Podcast is brought to you by [Security Journey](https://www.securityjourney.com/). About Security Journey Our training includes theory and immersive learning that teaches the skills and knowledge needed to create a security-first mindset across your organization. → [Learn more about Security Journey](https://www.securityjourney.com/) Connect with Dag Flachet: → [Codific](https://codific.com/) → [OWASP SAMM](https://owaspsamm.org/) Mentioned in this episode: → [Codific](https://codific.com/) → [OWASP SAMM](https://owaspsamm.org/) → [OWASP SAMM](https://owasp.org/www-project-samm/) → [OWASP DevSecOps Maturity Model (DSOMM)](https://owasp.org/www-project-devsecops-maturity-model/) → [openCRE.org](http://opencre.org/) → [EU Cyber Resilience Act](https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act) Chapters: 00:00 Meet Dag Flachet: Kaizen for your Appsec Program 01:39 The thing that we love. Well, uh, we're joined by Dag 06:54 That'd be funny if she sent a message yet. Like, hey 13:20 Yeah, very cool. Well, as we mentioned, we're going to be 17:08 Which is, is DSOM part of SAM now or are they 22:08 This is an interesting thing, but maturity models have also evolved 24:44 Let's wrap this whole thing together now. We introduced Kaizen. We've 27:00 If we were to kind of dive a little bit deeper ## Transcript *5,881 words · assemblyai* **0:00 Chris Romeo:** Dag Flachet has a doctorate degree in business administration, specialized in organizational psychology. He's co-founder of Codific and a professor and board member at the Geneva Business School. Dag's an active member of the OWASP Barcelona chapter and the OWASP SAM community. Dag joins us to discuss Kaizen in an AppSec program. Don't worry, we start by defining what Kaizen means. And after that, we explore how, together with maturity models, Kaizen provides focus towards improving The Application Security Podcast is brought to you by Security Journey. Our training includes theory and immersive learning that teaches the skills and knowledge needed to create a security-first mindset across your organization. Learn more at securityjourney.com. Hey folks, welcome to another episode of the Application Security Podcast. This is Chris Romeo. And also joined by my co-host of almost 10 years, as we were just, uh, doing some math here behind the scenes to figure out how long we've actually been doing the Application Security Podcast. And it's been almost 10 years. We're in our 9th year now, but Robert Hurlbut is here as well. **1:16 Robert Hurlbut:** Hey, Chris. Yeah, Robert Hurlbut and, uh, Principal Product Security Architect and Threat Modeling Trainer at Torion, which is Nude. to say. **1:25 Chris Romeo:** Yeah, it's a new role. **1:26 Robert Hurlbut:** New role, new, new things going on. Uh, but yeah, great, great to be here for a new season. **1:32 Chris Romeo:** I have a feeling new role and probably doing the same thing that you've been doing for 20 years. **1:37 Robert Hurlbut:** Yeah, a lot of threat modeling, right? **1:39 Chris Romeo:** The thing that we love. Well, uh, we're joined by Dag today and, uh, let's just jump right into your security origin story because I'm curious to see how'd you get involved in the world of security? **1:52 Dag Flachet:** Hello. First of all, thank you very much for having me. I'm very excited to be here. As I mentioned in the pre-conversation, I'm a big fan of your podcast, and I've listened to many, many episodes, and they've helped me grow in my career as well. And to jump into the security origin story, I have some bad news. I don't have a background in software development. I know that's frowned upon. I've heard that many times. **2:20 Chris Romeo:** No, not frowned upon at all. I don't, I don't either. So that's, there's two-thirds of the people in this interview right now do not have a software development background. **2:29 Dag Flachet:** Okay. So we're, we're the majority now. **2:30 Chris Romeo:** Good, good. **2:31 Dag Flachet:** We're, we're the new generation here. No, um, I think I was lucky that my, uh, from young, from a very young age, my dad was very much into gadgets and technology, so he would always have a computer very early on in the '80s. Yes, that kind of carbon dates me a little bit. Um, and, um, whenever he would get a new one, I would get the old one and I would always be tinkering with it and playing with it and mostly playing games. That was of course what interested me the most, but then also figuring out how things worked and tearing it apart and building it back together and these kind of things. Um, and one of the things I came across while copying games, when copying games was still not a crime, uh, was, uh, floppy disks with viruses, uh, or with, I don't know if they were real viruses or just some autorun scripts that were doing funny things to your computer, whatever it was. But I had like a little bit of a collection of these things, uh, that I had collected. And then at some point, I'm from Belgium, uh, we moved to Argentina, uh, other side of the world, uh, when I was 12 or 13 years old. And, um, around the time I also dabbled into trying to learn to program. I tried to build a game in C once, uh, but that was a nightmare and I very quickly gave up. I also have a, a strong case of dyslexia, so I get hopelessly confused with symbols and syntax and all these things. Um, and I had really bad memories from language classes. Specifically French language classes in Belgium. Everybody has to learn French and the classes were really painful. So I figured out, uh, going to Argentina, I was going to learn Spanish from friends, but I'm, was going to keep up the charade that I don't speak Spanish for my classes so that I don't get too much work. So my, my classmates were in on it and for a year I pretended not to speak a word of French, uh, Spanish while I was quite fluent at it. And because I have dyslexia, I'm allowed to hand in my, do my homework on a computer. So I was in a boarding school. I had a computer in my room, well, this old computer. Um, and then of course my print, I pretended my printer was broken and then I said, okay, just hand it in on a floppy disk. And you can see where this is going. Uh, I handed in that floppy disk and she puts it in her computer and she goes, Oh, mi ordenador. And I said, oh, mi homework. Gonna take a very long time to make all of that again. And yeah, that's kind of how it started. There was a boarding school in Buenos Aires where we were also playing Duke Nukem. I don't know if you remember Duke Nukem and Command and Conquer: Red Alert, but we didn't have internet cables yet. There was no internet there. So we We were kind of just trial and error trying to connect computers with each other with serial cables and eventually got things working. So playing Duke Nukem with serial cables connected to each other. And then later on when I moved back to Belgium to go to university, that was the time that, um, internet started coming, uh, broadband internet. Well, they called it broadband. It was mostly ADSL, started becoming very popular. Uh, But it rarely worked out of the box. It was also the time, initially the time that Windows Millennial, the very short time that Windows Millennial was cool. Uh, and then, uh, yeah, so people would generally come to me to make things work. So that's where I started my first company, which was kind of like what in the States is Geek Squad. So we had like the, the Belgian equivalent of that. That's where I met Aram and that's how I got Started fixing computers and viruses and so on. And that was the beginning of the story, I would say. **6:19 Robert Hurlbut:** Very cool. **6:21 Chris Romeo:** Very cool. So you've been all over the world sharing viruses with people across multiple continents. That's great though, that it deleted the homework assignment. It's like, oh no, my homework's empty. This is empty. Come on. Yeah. **6:37 Dag Flachet:** Well, it, it crashed her computer. Her computer didn't start anymore. So. There was no evidence of any homework ever. **6:44 Chris Romeo:** Evidence as well. **6:46 Robert Hurlbut:** Even worse. Yeah, but even better, maybe. **6:49 Dag Flachet:** I don't know if she listens to this. I don't think she listens to the podcast, so I don't think I'm going to get in trouble. **6:54 Chris Romeo:** That'd be funny if she sent a message yet. Like, hey, wait a minute, come back and repeat that class because we're taking all your academic achievements away. So, all right. Well, the title of this episode is Kaizen for AppSec Programs. And so I thought a good place to start would be What does that word mean? What is kaizen as a word? **7:15 Dag Flachet:** Right. So specifically the word, it's Japanese and it means, it's a combination of kai and zen and it means change good. And it means good change. And the context in which it exists is the context of quality control systems. So iterations on product quality. kind of do, plan, act, check cycle. And it is, it was a topic of my talk at the OWASP Barcelona conference because the principles of Kaizen are being used in the industry now in combination with OWASP SAM and OWASP BSOM. These concepts are probably familiar to you. I'm not sure if all the audience. all of the audience, but basically it was about, um, yeah, the, um, turning assessment models into quality control systems and thereby implementing the principles of Kaizen. The fun anecdote there was that, um, I'm a very messy person. Yeah, I'm aiming my camera up now so you don't see all the mess below me. **8:25 Chris Romeo:** Patrick. **8:26 Dag Flachet:** Uh, and I was preparing for a course I teach at the, at the Swiss Business School sometimes. And I was preparing some material for lean methodologies and I came across Kaizen and there's this one thing that's called the 5S. I don't know if you ever heard about it. The 5S are 5 things. They're Japanese terms. They come down to sword, shine, let me grab my cheat notes. Sort, set in order, shine, standardize, and sustain. Those are the 5 S's, but actually the original ones are Japanese words, obviously. But the idea is that you take half an hour before you start working or 15 minutes before you start working, and you're not allowed to do any work, but you're in charge of organizing your workspace. And you're only allowed to do that, and you're only allowed to make systems to make your workspace more optimized. For example, What do you have on your desktop? Why do you have those things there? Does it make sense to have those things? Does it make sense what's in the first shelf? Should it really be there? When was the last time you used those things? But you don't do a lot of things at once because if you have a very messy house or place, it becomes very daunting to try to fix that. So it's kind of like a big task you put off. So instead of doing the very big task all at once, you pick off, one shell, one box, one something, and that you really optimize. You do it really, really well. You do it really, really tidy, tidy and really, really logical. And I started using that for myself to organize myself. So I do this every morning, 15 minutes, try to organize things, structure things. And then I figured, you know, it's the same thing we are doing in our AppSec programs with the maturity models. We break things down into tiny pieces. And then instead of trying to boil the ocean, we are strategically identifying specific things that we can optimize in one cycle. And then the, the big daunting task of everything you should be doing or everything that's, you know, all the drawers you're afraid to look in slowly gets resolved. **10:40 Chris Romeo:** That's where it comes from. **10:40 Robert Hurlbut:** Good. **10:41 Chris Romeo:** That, it resonates with me as a concept as you're describing it. Because one of the challenges that people have with AppSec programs, especially when they're starting from scratch, is trying to do everything all at once, trying to say, well, we need to do various tools we need to implement and put into build pipelines. We need to figure out secure by design and threat modeling. We need to get a pen test vendor. Uh, we need to look at runtime security. We need to look at the latest AI thing, because maybe that could solve all of our problems. **11:14 Robert Hurlbut:** Yeah. **11:16 Dag Flachet:** All right. And the topic, the thing they often say then is, if I had the resources in order to do things properly, I would do this, this, this, this, this, and that. But I have limited resources. So, you know, there's a few drawers I'm not touching right now. I'm picking my battles. But, um, what Kaizen, uh, teaches you is that independent of the amount of resources you have, even if you have only 15 minutes, if you keep it into like a systematic small steps of improvements, but keep track that everything else isn't drifting away. That's why a maturity model like OWASP SAM is really good because it keeps track of everything, the state of everything, and then you try to move the lever somewhere a little bit. And then the excuse of, if I had the resources to really address that problem, kind of goes away because it's just more time you need to iterate on it, let's say. **12:12 Chris Romeo:** So you're focusing on one small problem at a time versus getting wrapped up in the universe of we have 100 different things and challenges and we can't, we don't have time to solve them. And so you end up getting into that analysis paralysis is the term that people use sometimes. **12:30 Dag Flachet:** Exactly. **12:30 Chris Romeo:** Yeah. Because you get caught up in this moment of I can't do anything because I've got so many things and I don't know what to do. So it sounds like Kaizen is a Is a, an approach that helps me to focus at the end of the day. **12:44 Dag Flachet:** Yes, exactly. And then you need sum or desum in order to break things down into an exhaustive set of buckets or tasks. So you have 30 activities and each activity has 3 maturity levels and each one has quality criteria as to how you get to the next maturity level. And instead of being paralyzed by the enormity of all the things that you're missing, you just pick one every cycle and you try to address that together with your team. And that's the idea behind that. **13:19 Robert Hurlbut:** Yeah, very cool. Well, as we mentioned, we're going to be also looking at some maturity models and you talked about one in particular, but what are maturity models in AppSec? **13:35 Dag Flachet:** The way I see SAM, it's kind of like an inventory of all the best practices generated by OWASP or the community at large. So I don't think they claim to invent any new best practice, but you put everything together, everything that you should be doing, and then categorize it into the things you do, but not just yes or no, but different levels of maturity. Because what you need to do at Devegy or what you need to do at Torion is not exactly the same from each other, or is not the same as what Bank of America has to do or what Bayer has to do. You know, depending on your situation, you have different objectives, different thresholds you should reach. And maturity models are really good in that because it gives you, for each one of these practices, it gives you the quality criteria of the different maturity levels. So then it allows you to, with this taxonomy of the maturity model, allow you to create a strategy that is very specific for your organization, or what we see in very large organizations is that there are different, we call them target postures. So these are the kind of scoring on the different activities that are requested from different teams in different contexts. So that might be if you're customer-facing web apps or your embedded devices or your IoT or your internal IT, then you will have a different kind of target posture, and it allows you to manage that effectively. It's particularly useful if the organization is mature enough to really care about security. If you just want to get compliance and get it over with, like ISO 27000 or SOC 2, probably SAM is not going to be that great for you. But if— what I hear very often, so in my role, I'm usually the first point of contact when talking to to our organization, and I talk to a lot of AppSec program leaders, that's where I got information for my talk as well. What I hear very often is that they need to keep track of how things are internally, and they need to communicate upwards to the board, to the executives, to whoever is the first, maybe less technical or less AppSec-related role, but they need to report on the state of AppSec in the organization. And, you know, we got an ISO 27001 certification. What do we say next quarter? We still have it. Whereas with the maturity model, you can say, look, we are here, here, and here, and here. And the small steps we're planning for next quarter are here and here. And then these are the targets we have, and teams are 85% from target, 90% from target. **16:39 Chris Romeo:** I want to stop for a second and just ensure that we define a couple of things that you said. SAM, Software Assurance Maturity Model, right? That's, that's focused for folks in case they haven't dove into the maturity model space within the OWASP universe. So, SAM is Software Assurance Maturity Model. You mentioned DSOM as well, which is the DevSecOps Maturity Model. **17:07 Dag Flachet:** Right. **17:07 Chris Romeo:** Which is, is DSOM part of SAM now or are they 2 separate things? **17:11 Dag Flachet:** No, no, it's not. So there are 2 separate models. There are some mappings that exist, but we'll get into that maybe a little bit later. But there are 2 different models and SAM is a little bit wider because SAM includes also governance and operations, whereas DSOM is very much SDLC-oriented. So, what we see in some large organizations that they will have on the team level, application teams will have a DSOM assessment, and then the business units will have a SAM assessment. And then they will translate the scores from the DSOM teams into the central 3 practices, which are design, implement, and verify. Those come kind of mapped to these relatively well. And then the other 2 are filled out separately. But those are often also other people in the organization that do governance and that do operations. **18:10 Chris Romeo:** Let's touch for a moment, you mentioned ISO 27000 and SOC 2. And you kind of already led us a bit of a bit down a path as far as what I think your conclusion is going to be. But I'd love to just dive into a little bit deeper. I certainly have my own thoughts on ISO and SOC 2 certifications and the value they provide. But why a maturity model instead of just doing ISO or doing a SOC 2 and getting my certificate that I can wave around? **18:45 Dag Flachet:** Yes, coincidentally, this morning, I had an interview with a researcher that was preparing for Cyber Resilience Act, the CRA. I don't know if you've heard of this. There's a lot of regulation coming out of Europe these years that require a certain level of cybersecurity across all digital products. And the question she posed me is like, okay, is this really gonna, is this really gonna move the meter on cybersecurity or is this gonna be a lot of window dressing? And I think that's where a maturity model like SAM comes in. If, and there's nothing wrong with that, but if you are at an organization who's, let's say you're a startup and you're moving fast and breaking things and cash is tight and you don't have the bandwidth to really do security fundamentally, but you just need to get your ISO certificate, 'cause otherwise your customers will not buy from you. then probably OWASP SAM is not the way to go for you. Probably you're just gonna do an ISO compliance exercise. And there are a lot of platforms out there also that promise you compliance without much effort, which is kind of an oxymoron. **20:04 Chris Romeo:** Yes. **20:06 Dag Flachet:** But yeah, what the maturity models are really good at is fundamentally doing the processes, which is why it is the organizations that are a little bit more mature, and that care about growing the, the pro— the fundamental processes are more interested in, in the SAMs and less interested in the ISO and the SOCs. Well, they, they'll have ISO and SOC probably. The next problem that arises then is, okay, but let's say I'm, I'm, I'm in one of the teams and now I have to fill out a questionnaire for SAM, and next month I have to fill out a questionnaire for ISO 27000. And then we're doing a SOC and then we're doing something else. It's kind of always the similar questions phrased differently, and it's quite annoying. So I think the wet dream of the community is to find a solution to that, which we haven't fully found, but there's some really cool projects like OpenCRE. I don't know if you've heard of this project that is trying to map the different frameworks together. And that is something which I think in the coming years will, will be fascinating to see how it develops. It's really hard because the, the level of abstraction between the different frameworks is sometimes different. The coverage of the questions is different. So you can't just say, ah, you answered 2 on some here, that means you're compliant with this ISO control. Um, it doesn't always fully map it. We're trying to find a solution to that so that SAM can be the backbone of your application security program because it's the most fundamentally oriented about your security processes. And then having everything nicely documented in SAM should make compliance towards ISO, towards CRA, towards other legislations out there, hopefully very easy. **22:08 Robert Hurlbut:** This is an interesting thing, but maturity models have also evolved or even matured, if I could use that word, over time. But how would you say that has happened in terms of the use of those evolved or matured over time? **22:23 Dag Flachet:** Yes. Maybe people Uh, and OWASP are gonna get upset at me for saying this, but, um, you know how in, in certain movies there is warp speed? Uh, that's very fast. Well, then there is OWASP speed, which is sometimes the opposite of warp speed. Sometimes things go very, very slowly, but that's also because, you know, it's volunteer-based and people have to find the time after their hours to do things. **22:54 Robert Hurlbut:** Yeah. **22:55 Dag Flachet:** But in the spaSAM team, with whom I have a lot of contact, there's a lot of very bright minds that are working, working hard and are very motivated building it. But version 2 has been around for quite a long time. There have been minor updates, but I don't know when this is going out, but this may be new to many of the listeners. There's a version 3 in the works, which is a major update to the OWASP-SAM framework. And for the moment, they're collecting user stories or feedback or anything that they can use to see which things have to change. And in OWA speed time, there will be a version 3 coming out very soon. **23:37 Chris Romeo:** Okay. **23:38 Dag Flachet:** There's a GitHub repository. I don't have the link, but I can get it to you and can put it in the show notes of the issues. So there's a list of issues of things we think may be wrong with the model or maybe have— maybe wrong is not the right word, but may have room for improvement. And people can contribute, people can share their expertise. As it covers everything AppSec, you know, we need a wide range of people with expertise. And then there will be the newest version of SAM 3.0, of course. **24:08 Chris Romeo:** Nice. Nice. **24:10 Dag Flachet:** SAM 2.0 is used very, very widely across the world. A lot of very big organizations are using it and, uh, we probably make some breaking changes going to 3. Uh, so that has its own world of issues there. Yeah. **24:26 Chris Romeo:** And just, just a tip, if anybody gets mad at you for the warp speed joke, just tell them I said, oh, they had to say, I think Chris said that. I don't remember saying that. It was probably, it sounds like something I would've said anyway. So yeah, you'll be off the hook and people will just be like, oh yeah, that makes total sense that he said that. **24:43 Dag Flachet:** Okay. **24:44 Chris Romeo:** So, let's wrap this whole thing together now. We introduced Kaizen. We've gone through talking about some of the maturity models, and then why ISO and SOC 2 are, you know, not necessarily complementary to those maturity models. But let's bring this thing back around full circle now. How does Kaizen, in how you implement this, how does this relate to the maturity models? How do I get value? out of this Kaizen concept applied to maturity models? **25:11 Dag Flachet:** Well, the first thing organizations typically do when they start implementing OWASP SAM is to do an OWASP SAM assessment, and they can do it themselves. They can bring in some consultants from the OWASP community, and then they will assess the different business units, different teams, however they're scoping it. And then they get a report. Initially, this would be like a PDF report, which this is the situation of things. The problem with these kinds of reports is as soon as they hit the desk, they're pretty much outdated because, you know, things evolve and things move on. So the way this is evolving now is instead of just having a one-time assessment, you do a continuous A continuous evaluation. So instead of saying, okay, this is done, there are some tools like the OWASP SAM Toolkit or the OpenSAMI project, which is a tool, an OWASP project, which is a tool to manage these cycles. And then you have a dashboard that keeps track of everything that's going on, and you have the incremental changes, and you have expiration of evaluations or artifacts or scores. So that your dashboard is continuously up to date and you're using principles of Kaizen to make small iterative improvements every cycle time, which can be a quarter, which can be a month, which, whatever makes sense. And that's how really the philosophy of Kaizen is brought into what used to be an assessment methodology. But now it's really the backbone and the structure of an application security program. **27:00 Chris Romeo:** So, if we were to kind of dive a little bit deeper into an example, how would I apply Kaizen? Let's just take our fictitious AppSec program person out there. They've gone through the assessment process as their first step. What would be some tips that you would offer them? to then apply this Kaizen approach to their AppSec program? **27:24 Dag Flachet:** Yes. So, one of the first things that you would do is to do the assessments. Some of the questions that come up when you do the assessments is, who does the assessment? Does the central AppSec team go interview the different business units? And do they fill out the assessments? Do you send the questionnaire to the teams and do they self-assess? Or do you bring in external consultants and they assess everybody? Everything has its advantages and disadvantages. People who are best informed about the situation is the team itself. So the sweet spot we see is typically some kind of self-assessment, which is then checked by the central AppSec team that is going to validate, check over the documentation they provided, and check if they agree with the scoring they gave. This is specifically important if there's different teams and there is going to show up somewhere in their performance metrics, their SAM score, and then one team was very lenient on themselves and the other team was more strict, then we need to make sure that's fair. Once we have fair scoring across the teams, then the next problem which may arise is that it's kind of like a game and we all like playing games. We wanna score quick points in the game. And that, that's where SAM intrinsically is maybe not psychologically perfect because the easiest way to score points may not actually be the best investment of your time and money because you might be doing something which in your context is not super relevant, but it gives you 2 points very quickly, whereas something which is a really big job. Like making sure you're doing proper threat modeling across the organization. It's a big time investment. It's, it's a big job. It's also only 2 more points, but maybe those 2 points are worth more than the other ones. So then there's a, a job for, uh, the central team to start creating the roadmap and the roadmap or those little steps saying, okay, what are we gonna focus on now and what are our priorities? Okay, we're gonna get one more point in threat modeling, and then we're gonna get one more point over there next quarter. And this roadmap can then be different for different teams, and then it really breaks down, but it also gives people visibility on what is going on. Whereas if you, I don't know if you ever experienced this, but if you go to a team and you say, you know what, you guys need to do this, this, and that in order to have good security. They do A, B, and C, and then next quarter you go back and you say, no, what you should do F, G, and H as well. They're like, wait, wait, but I thought you said we need to do A, B, and C to have good security. Now we do need to do these other 3 things, which you never mentioned to us before. Whereas if you have the same framework and they can see this, they can see the map and they can see the roadmap, they have more buy-in and more visibility of why more things are popping up all the time. And you're taking little steps going forward in the process. So, who's— **30:32 Chris Romeo:** so, it sounds like it's the security team that's really controlling the Kaizen portion of this by setting the scope of what development teams are going to be doing. So, it doesn't sound like as a developer in this organization, I really, I don't really even have to know what Kaizen is. It's more of a management construct that the security team is using to try to improve the maturity of the security in your organization using small bites. **31:00 Dag Flachet:** Yes. **31:01 Chris Romeo:** Small strategic bites. **31:03 Dag Flachet:** We had a, there was a SAM User Day as well at the OWASP conference, and the SAM User Days, where SAM practitioners come together, um, both professional consultants as people implementing it in their companies. And there was a bit of a discussion, um, whether the developers should be Whether some is for the developers. And the argument of somebody in the room was that it shouldn't be the AppSec team responsibility. You shouldn't make them busy with this whole map of things and everything. And personally, I strongly disagree with that because you're not giving them visibility on everything you're doing. That doesn't mean they need to understand the nuance of everything that's on there, but they need to see the general map. Uh, the Kaizen principles, I don't think they, they need to, they need to know about, but they need to kind of have access to, to the map, see where they are on the map and see how they get from point A to point B. What happens in another neighborhood on the map, they don't need to worry too much about, but it helped getting, uh, bottom-up buy-in. And very recently I was talking to a, a large railway company. a railroad managing company, national railroad managing company in Europe about their SAM implementation. And they kind of surprised me in the sense that they were more bottom-up than I've ever heard before, is that they didn't care about comparing scores. They didn't care about validating that everybody scores fairly, but what they wanted to do, it was their job to facilitate a higher level of maturity for any of the 200 teams. They had 200 application teams. any of them who want it. So they will provide the SAM assessment methodology to them. They have a catalog of tools they could be using, but they let the teams themselves pick what they want to do. And then it becomes really bottom-up. Then the team says, oh, you know what? I see these things we could be doing better. And then they ask the central security team, Can we have resources for that? And then it turns it around and makes it really bottom-up, which is, from a management perspective, the holy grail, I would say. Yeah. **33:26 Chris Romeo:** I mean, that's a brilliant approach that they've taken to empower the development teams to improve the things that they see as the biggest challenges, because Robert and I both have seen working with developers, they often have a much better perspective than the security team does on what's actually happening under the hood when you're working on an application. So, that's brilliant to turn it around and let them drive the bus in the direction that it needs to go in based on what they're seeing from that perspective. **34:01 Robert Hurlbut:** Yep. **34:02 Dag Flachet:** And then you can still guide that with, with the general objectives and the goals, but you don't go into the nitty-gritty of you need to be doing this, you need to be doing that. But you can say, look, we, we would like to get towards these kind of target postures. Um, make your roadmap. Tell us, tell us what you think you can do this year. Tell us what you think you can do next year. Tell us what, what resources you need. And hopefully then you get a lot more buying and a lot more, uh, engagement from those teams. **34:32 Chris Romeo:** Yeah. Makes sense. So where would you, what, what would you give us then just to kind of land the plane here? From a key takeaway or a call to action perspective, what would you want to leave the audience with based on the research you've done, the experience you have with maturity models and Kaizen and all the things we talked about? **34:52 Dag Flachet:** Don't be afraid of little steps as long as you have the map well laid out and the little steps may seem Quite insignificant in the big picture, but if you're consistent with little steps, you can have pristine quality and security on the long run. **35:17 Chris Romeo:** I don't think we could add anything else to that right there. Dag, thank you so much for being a guest here on the Application Security Podcast. Definitely appreciate your your insights and the way you shared your wisdom about maturity models and how these things come together. And and I'm excited to hear from folks about how they've applied this principle. So we look forward to. continuing the conversation with you in the future. **35:38 Dag Flachet:** My pleasure. And thank you guys for the amazing podcast you guys are doing. You, uh, help a lot of people along their career by going through all these topics and making it available for everybody. So keep up the good work. **35:50 Chris Romeo:** All right. **35:51 Dag Flachet:** Thank you for the kind words. **35:52 Chris Romeo:** Thank you. --- Source: https://appsecpodcast.com/dag-flachet-kaizen-for-your-appsec-program/