This project aims to help organizations tailor their security efforts so developers can consistently build secure software. Version 2 introduces SECUR-E, an open framework based on COM-B and DASP research, to identify whether barriers to secure development stem from capability, opportunity, or motivation. Users can then select targeted interventions. Features include self-assessment, scoring, persona guidance, team visualizations, playbooks, and progress tracking to support better security culture. Personas reflect current conditions, not fixed identities. Results should never be used for hiring, performance, or disciplinary decisions. The framework is under expert review and community testing.
You do not need to read every deliverable before SECUR-E becomes useful. Start with your question, complete one bounded step, then decide whether to go further.
This website has dedicated tabs for each path that fits better your role and intention to use SECUR-E:
If you're leading an engineering team
→ Follow the Engineering Manager path.
-
If you're a developer or security champion
→ Follow the Developer path.
-
If you run an AppSec or security culture program
→ Follow the Security Practitioner path.
-
If you're evaluating to run a pilot
→ Follow the Pilot Organization path.
-
If you're a researcher who studies human behavior or software teams
→ Follow the Researcher path.
-
If you want to helps us improving the OWASP project
→ Follow the Contributor path.