“Security is a process, not a product” -- Bruce Schneier.

Slides:



Advertisements
Similar presentations
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Advertisements

Summit 2011 Outcomes PRESENTED BY __________. About the Summit Over 180 application security experts from over 120 companies, 30 different countries,
OWASP Overview Germany 2008 Conference
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation.
1 International Partner Program by EuroCloud Europe EuroCloud Star Audit Based on European Quality Values for a Worldwide Usage.
Line Efficiency     Percentage Month Today’s Date
The OWASP Foundation ABC About me MOSHIUL ISLAM, CISA A: Information System Auditor B: Currently working for a Bank – EBL, IT Security.
Distributing and Monetizing Applications through the Windows® Marketplace for Mobile Daniel Bouie & John Bruno Microsoft.
Copyright © The OWASP Foundation This work is available under the Creative Commons SA 3.0 license The OWASP Foundation OWASP
SAP Student Interest Group
Microsoft Confidential Source: Crimson Consulting, July 2008 Note: Adobe Flash Lite is available to Windows Mobile licensees as an.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the Creative Commons Attribution-ShareAlike.
Safety Driven Performance Conference 2013 The future of managing asset-intensive businesses John Keefe APM/RBMI Technical Manager Asset Integrity Services.
OWASP Intra- Governmental Affairs David Campbell Denver Chapter Puneet Mehta Delhi Chapter.
The OWASP Foundation AppSecEU11 Where we are.. Where we are going Tom Brennan, Eoin Keary, Seba Deleersnyder, Dave Wichers, Jeff Williams,
Copyright 2008 © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
The OWASP Foundation OWASP The Open Web Application Security Project Join the application security community for free, unbiased, open.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the Creative Commons Attribution-ShareAlike.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
The OWASP Foundation OWASP Belgium Chapter OWASP Update Sebastien Deleersnyder Foundation Board, Zenitel Belgium
The OWASP Foundation OWASP Belgium Chapter OWASP Update Sebastien Deleersnyder Foundation Board, Zenitel Belgium
The OWASP Foundation Where we are Where we are going Seba DeleersnyderEoin Keary OWASP Foundation Board.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the Creative Commons Attribution-ShareAlike.
Copyright 2007 © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Copyright © The OWASP Foundation This work is available under the Creative Commons SA 2.5 license The OWASP Foundation OWASP AppSec India Aug 2008.
Copyright © The OWASP Foundation This work is available under the Creative Commons SA 2.5 license The OWASP Foundation OWASP AppSec India Aug 2008.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the Creative Commons Attribution-ShareAlike.
Getting Started with OWASP The Top 10, ASVS, and the Guides Dave Wichers COO, Aspect Security OWASP Board Member OWASP Top 10 and ASVS Projects Lead.
Chapter 27 Chapter 27 Geographic Variability in Hip and Vertebral Fractures Copyright © 2013 Elsevier Inc. All rights reserved.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation.
This is an example text TIMELINE PROJECT PLANNING DecOctSepAugJulyJuneAprilMarchFebJanMayNov 12 Months Example text Go ahead and replace it with your own.
The OWASP Foundation OWASP Global Update Seba Deleersnyder OWASP Foundation Board Member.
OWASP Foundation OWASP Where we are.. Where we are going.
INFORMATION ABOUT FPA RESOURCES AND FPA MEMBERS Financial Planning Association 1.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Best Sustainable Development Practices for Food Security UV-B radiation: A Specific Regulator of Plant Growth and Food Quality in a Changing Climate The.
OWASP Leeds OWASP Leeds Chapter OWASP Leeds
Introduction to The Open Group
Finding and Fighting the Causes of Insecure Applications
2018 Safety Group 1 – 5 Year Program Timeline Guide


OWASP in favor of a more secure world
2017 Safety Group 1 – 5 Year Program Timeline Guide
Canberra OWASP Chapter meeting
Tour of OWASP’s projects
Organizing and Delivering the World’s AppSec Information
Flags of Countries.
2009 TIMELINE PROJECT PLANNING 12 Months Example text Jan Feb March
2018 Advantage Program Timeline Guide
“Integrating Microbial Knowledge into Human Life”

Finding and Fighting the Causes of Insecure Applications
Safety Group Program Timeline
2014 Advantage Program Timeline Guide *** Progress Visits ***
2014 Advantage Program Timeline Guide *** Progress Visits ***
PLANNING LOOKING AHEAD…. Long Term Goals (Assigned to…)
2017 Advantage Program Timeline Guide
Flags of Countries.
Digital transformation of tax administration
2016 Safety Group 1 – 5 Year Program Timeline Guide
Safety Group Program Timeline
2012 Safety Group 1 – 5 Year Program Timeline Guide
2012 Safety Group Advantage Program Timeline
2012 Safety Group Advantage Program Timeline
2009 TIMELINE PROJECT PLANNING 12 Months Example text Jan Feb March
2013 Safety Group Advantage Program Timeline
Electrification business
2016 Advantage Program Timeline Guide
Presentation transcript:

“Security is a process, not a product” -- Bruce Schneier

What if the software world was only… 100 apps written by 100 developers at 100 companies

Why?

“Don’t hate the playa Hate the game” -- Ice T

We Trust We Blame We Hide Toxic?

AppSec Visibility Cycle Audit Developers Infosec Legal Architects Users Research Business Monitor Threat Create Security Architecture Define Security Requirements Implement Controls Share Findings Understand Laws Verify Compliance Understand Stakeholders Our Mission: Visibility

Growing Ecosystems

OWASP Foundation (OWASP Board) Projects Membership Education Conferences Industry Chapters Connections OWASP Leaders (Chapters and Project) OWASP Meritocracy OWASP MembersOWASP Users and Participants

DC Sep 2009 Nov 2010 DC Sep 2009 Nov 2010 Brussels May 2008 Brussels May 2008 Poland May 2009 Poland May 2009 Taiwan Oct Taiwan Oct Portugal Nov 2008 Portugal Nov 2008 Israel Sep Israel Sep India Aug 2008 Nov 2009 India Aug 2008 Nov 2009 Australia Feb Australia Feb Minnesota Oct Minnesota Oct Denver Spring Denver Spring Sweden June 2010 Sweden June 2010 Ireland Sept June 2011 Ireland Sept June 2011 Greece June 2012 Greece June 2012 New York Nov 2008 Oct 2012 New York Nov 2008 Oct 2012 China Oct 2010 China Oct 2010 New Zealand July New Zealand July Brazil Oct Brazil Oct Germany Oct Germany Oct 08-10

Today Getting Started with OWASP T10 and Guides Building a Software Assurance Program Using the OWASP Live CD =====LUNCH===== OWASP Enterprise Security API (ESAPI) OWASP O2 The DISA AppSec STIG and OWASP Tools Discussion