Mapping the Software Assurance Landscape: A Guide to What’s Going On In the Community Sean Barnum.

Slides:



Advertisements
Similar presentations
What is an M and E Plan?. Organizing the Work of M and E An M and E System -- the 12 components as a whole – Sets out broad vision at national level An.
Advertisements

Succession and talent management
Identifying enablers & disablers to change
Building an Operational Enterprise Architecture and Service Oriented Architecture Best Practices Presented by: Ajay Budhraja Copyright 2006 Ajay Budhraja,
Strategy 2022: A Holistic View Tony Hayes International President ISACA © 2012, ISACA. All rights reserved.
How to Document A Business Management System
S&I Framework Provider Directories Initiative esMD Work Group October 19, 2011.
Monday, June 01, 2015 Aligning Business Strategy with IT Architecture Board & Governance- Key to Running IT as Business.
Planning and Strategic Management
8/28/2005ECEN5543 Req Elicitation1 Targets of Requirements Engineering ECEN 5543 SW Engineering of Standalone Programs University of Colorado, Boulder.
Unit 8: Tests, Training, and Exercises Unit Introduction and Overview Unit objectives:  Define and explain the terms tests, training, and exercises. 
Division of School Effectiveness1 Common Core State Standards: Transitioning from Awareness to Implementation December 1, 2011 Rutledge Conference Center.
Planning and Strategic Management
Planning and Strategic Management
Enterprise Architecture
Chicagoland IASA Spring Conference
Developing Enterprise Architecture
IMA CIM Overview. IMA Mission “Provide a knowledge-sharing platform for business professionals where proven Internet.
© 2007 Pearson Education, Inc. Publishing as Pearson Addison-Wesley 1 Context of Software Product Design.
1 SCIP Africa Summit | October , 2014 Firefighters to Futurists SCIP Africa Summit October 2014 Butterfly Effect Intelligence™: Stuart Maclachlan.
SIRS Researcher. What is SIRS? (Social Issues Resources Series) A line of focused, specially constructed online research databases. Materials selected.
Chapter 4 Interpreting the CMM. Group (3) Fahmi Alkhalifi Pam Page Pardha Mugunda.
Teaching Metadata and Networked Information Organization & Retrieval The UNT SLIS Experience William E. Moen School of Library and Information Sciences.
GEO Work Plan Symposium 2012 ID-05 Resource Mobilization for Capacity Building (individual, institutional & infrastructure)
COMPANY CONFIDENTIAL Page 1 Final Findings Briefing Client ABC Ltd CMMI (SW) – Ver 1.2 Staged Representation Conducted by: QAI India SM - CMMI is a service.
COMMUNICATION Visioning Inspiring STRATEGY Developing Enabling
Chapter 6 System Engineering - Computer-based system - System engineering process - “Business process” engineering - Product engineering (Source: Pressman,
1 Towards a Framework for the Quality Assurance of Practical Skill Ability Akira Kurematsu* Takashi Sakamoto* Yoshito Shubiki** *Accreditation Council.
Building Effective Assessments. Agenda  Brief overview of Assess2Know content development  Assessment building pre-planning  Cognitive factors  Building.
Engineering, Operations & Technology | Information TechnologyAPEX | 1 Copyright © 2009 Boeing. All rights reserved. Architecture Concept UG D- DOC UG D-
Unit 5:Elements of A Viable COOP Capability (cont.)  Define and explain the terms tests, training, and exercises (TT&E)  Explain the importance of a.
Copyright © 2011 by the McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin Planning and Strategic Management Chapter 04.
Human and Institutional Capacity Development Project in Rwanda (HICD-R) CORE TEAM KM WORKSHOP February 26, 2015 Delivered by Courtney Roberts.
Campaign Readiness Project Overview Enabling a structured, scalable approach to customer-centric campaigns.
Innovators Forum Talent Management. Agenda About the Innovators Forum Background & Perspective on the 2014 Topic The Case for Change Talent Management.
The Challenge of IT-Business Alignment
© 2015 Cengage Learning. All Rights Reserved. May not be scanned, copied or duplicated, or posted to a publicly accessible website, in whole or in part.
GUIDELINES ON CRITERIA AND STANDARDS FOR PROGRAM ACCREDITATION (AREA 1, 2, 3 AND 8)
JOINT STRATEGIC NEEDS ASSESSMENT Rebecca Cohen Policy Specialist, Chief Executive’s.
Kristiina Karjalainen, Lappeenranta University of Technology Taina Rytkönen-Suontausta, University of Kuopio E-Learn Quality Manual – Tool.
Chapter 7 Developing a Core Knowledge Framework
© 2012 Cengage Learning. All Rights Reserved. This edition is intended for use outside of the U.S. only, with content that may be different from the U.S.
© 2012 Cengage Learning. All Rights Reserved. This edition is intended for use outside of the U.S. only, with content that may be different from the U.S.
1. Housekeeping Items June 8 th and 9 th put on calendar for 2 nd round of Iowa Core ***Shenandoah participants*** Module 6 training on March 24 th will.
Illustrations and Answers for TDT4252 exam, June
Chapter 7 Developing a Core Knowledge Framework
TPEP Teacher & Principal Evaluation System Prepared from resources from WEA & AWSP & ESD 112.
Community Resources Assessment Training 4-1. Community Resources Assessment Training 4-2.
Chapter © 2012 Pearson Education, Inc. Publishing as Prentice Hall.
The Conceptual Framework: What It Is and How It Works Linda Bradley, James Madison University Monica Minor, NCATE April 2008.
Assoc. Prof. Dr. Nik Maheran Nik Muhammad, (CFP, CITM, IBBM)
The Proposal AEE 804 Spring 2002 Revised Spring 2003 Reese & Woods.
Chapter © 2012 Pearson Education, Inc. Publishing as Prentice Hall.
STS International, Inc. PERSONAL LEADERSHIP A framework for exploring and evaluating Leadership Competency for the 21 st Century. COMMUNICATION Visioning.
Presented by the GMU Win-Win Team March 17, 2004 Status Report.
A Professional Development Series from the CDC’s Division of Population Health School Health Branch Professional Development 101: The Basics – Part 1.
Enterprise Architectures Course Code : CPIS-352 King Abdul Aziz University, Jeddah Saudi Arabia.
PP 620: Public Policy and Health Administration Unit One Seminar Kris R. Foote, J.D., M.P.A., M.S.W. Kaplan University.
© PeopleAdvantage 2013 All Rights Reserved We will Show You How to Easily Conduct Effective Performance Appraisals LCSA Conference 2013.
Info-Tech Research Group1 1 Info-Tech Research Group, Inc. is a global leader in providing IT research and advice. Info-Tech’s products and services combine.
Spotlight on ‘standards’: 2004 update Sue Halbwirth University of Technology Sydney 5 th Annual Conference ACTKM Forum 14 October 2004 Standards Australia.
Youth Justice Resource Hub An online resource for the youth justice community A presentation for Team Meetings
Open Ag Data : Landscape Analysis ●Who is involved in collecting data on agricultural investments, and from whom? ●How is data publicly shared? Which.
NGSS Resources Facilitator Notes:
Michael J. Novak ASQ Section 0511 Meeting, February 8, 2017
MATERI #6 Proses Perancangan Intervensi
Instructional slide to Partner: REMOVE BEFORE PRESENTING TO CUSTOMER
ServiceNow Implementation Knowledge Management
Governor Conference Saturday 25th November 2017.
Presentation transcript:

Mapping the Software Assurance Landscape: A Guide to What’s Going On In the Community Sean Barnum

© 2006 Cigital Inc. All Rights Reserved. 2 So Tell Us About What’s Going On in SwA

© 2006 Cigital Inc. All Rights Reserved. 3 Software Assurance Landscape Paper The landscape paper is intended to:  Draw a somewhat broad picture of the organizations and efforts of the software assurance landscape  Identify and describe various knowledge resources being developed and made available by these efforts  Describe and explore how many of these efforts and knowledge resources are actually mutually supportive, well aligned, and complimentary  Identify gaps and opportunities in the current landscape Structure  Intro & Purpose of Landscape  Brief overview and scoping of “Software Assurance”  Software Assurance State of the Art/Practice Summary  Software Assurance Landscape Index  Software Assurance Domain Summaries  Graphical Representations of Landscape  Software Assurance Knowledge, Activities and Initiatives  Targeted Capabilities  Software Assurance Roadmap

© 2006 Cigital Inc. All Rights Reserved. 4 Landscape Index Objective: Present full list of organizations, activities and knowledge in an organized taxonomy to more easily identify items of interest Key Domains  Communities & Leadership  Developing and Maintaining Software-based Systems  Operation and Maintenance of Systems and Networks  Evaluating, Certifying, Reviewing, and Monitoring Compliance of Software-base Systems  Formalization and Enabling Technologies for Implementing Security Guidelines and Specifications  Research & Development (R&D)  Education  Acquisition & Marketing  Forums, Conferences, Colloquia, Working Groups, etc.

© 2006 Cigital Inc. All Rights Reserved. 5 Domain Summaries & Graphical Representations Domain Summaries Objective: Prose descriptions of each organization, activity and knowledge resource along with explanations of the relationships between them A good place to start Graphical Representations Objective: Present single picture overviews of the interrelationships between elements of a given type Currently complete: Knowledge To be created: Organizations & Activities

© 2006 Cigital Inc. All Rights Reserved. 6 SwA Efforts in Context

© 2006 Cigital Inc. All Rights Reserved. 7 Software Assurance Knowledge, Activities and Initiatives Enumerated list of all of the identified organizations, activities and knowledge Each entry includes:  A very brief description of the element  Links and references to where you can go to learn more  Who is sponsoring or leading  Eventually, descriptions of how this element is related to other elements in the enumeration

© 2006 Cigital Inc. All Rights Reserved. 8 Targeted Capabilities & SwA Roadmap Targeted Capabilities outlines capabilities that the SwA community seeks to achieve with the elements of the landscape This listing helps to establish the beginnings of a framework for identifying gaps in the current landscape SwA Roadmap is intended to link to various specifically actionable roadmaps that may exist for filling identified gaps in the landscape

© 2006 Cigital Inc. All Rights Reserved. 9 Challenges & Future Plans Challenges How tightly to bound the landscape to software assurance Requires many different perspectives (noone knows it all) Gathering adequate details on such a large number and wide variety of organizations, activities and knowledge Keeping landscape current Future Plans Continue to flesh out and revise current content Identify new content and expand Eventually deploy as a website

© 2006 Cigital Inc. All Rights Reserved. 10 Opportunities for Involvement Need your assistance with identifying other relevant topics of interest Need your assistance with identifying other relevant organizations, activities and knowledge Need your assistance with descriptive detail for each organization, activity or knowledge entry Need your perspective on how to make this more valuable Need your assistance in spreading the word To get involved, Sean or Bob