OWASP Global Projects Committee

Slides:



Advertisements
Similar presentations
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Advertisements

OpenSAMM Software Assurance Maturity Model Seba Deleersnyder SAMM project co-leaders Pravir Chandra AppSec USA 2014 Project.
The OWASP Foundation Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under.
GLOBAL COMMITTEE UPDATE COMMITTEE: INDUSTRY /COMMITTEE CHAIR: JOE BERNIK.
The OWASP Foundation ABC About me MOSHIUL ISLAM, CISA A: Information System Auditor B: Currently working for a Bank – EBL, IT Security.
1 Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
The OWASP Foundation AppSec DC Learning by Breaking A New Project for Insecure Web Apps Chuck Willis Technical Director MANDIANT
Copyright © The OWASP Foundation This work is available under the Creative Commons SA 3.0 license The OWASP Foundation OWASP
Copyright © The OWASP Foundation This work is available under the Creative Commons SA 2.5 license The OWASP Foundation OWASP BeNeLux 2010
Security Scanning OWASP Education Nishi Kumar Computer based training
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the Creative Commons Attribution-ShareAlike.
OWASP Intra- Governmental Affairs David Campbell Denver Chapter Puneet Mehta Delhi Chapter.
The OWASP Foundation AppSecEU11 Where we are.. Where we are going Tom Brennan, Eoin Keary, Seba Deleersnyder, Dave Wichers, Jeff Williams,
Copyright 2008 © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
“Security is a process, not a product” -- Bruce Schneier.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the Creative Commons Attribution-ShareAlike.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Copyright 2007 © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
The OWASP Foundation Where we are Where we are going Seba DeleersnyderEoin Keary OWASP Foundation Board.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the Creative Commons Attribution-ShareAlike.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
The OWASP Foundation OWASP Belgium Chapter OWASP Update 12-Sep-2012 Seba Deleersnyder Foundation / BE Board
OWASP Global Projects Committee Brad Causey Leo Cavallari Pravir Chandra Jason Li Matt Tesauro **Paulo Coimbra** **Dinis Cruz**
Copyright 2007 © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Copyright © The OWASP Foundation This work is available under the Creative Commons SA 2.5 license The OWASP Foundation OWASP AppSec India Aug 2008.
OWASP Update Seba Deleersnyder Vice-Chair OWASP Foundation OWASP BeNeLux 2013.
Copyright © The OWASP Foundation This work is available under the Creative Commons SA 2.5 license The OWASP Foundation OWASP AppSec India Aug 2008.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the Creative Commons Attribution-ShareAlike.
Software Security Common Vulnerabilities Encoded During Development Chris Wysopal, CTO & Co-Founder, Veracode. ISACA Luncheon, 11:30am Tuesday, February.
Copyright © The OWASP Foundation This work is available under the Creative Commons SA 2.5 license The OWASP Foundation OWASP Denver February 2012.
Copyright 2007 © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
OWASP 1 Industry Committee – Recently Completed  InfraGard Presentation to Denver chapter of InfraGard (US critical national infrastructure)  DPC BS.
The OWASP Foundation OWASP Global Update Seba Deleersnyder OWASP Foundation Board Member.
OWASP Foundation OWASP Where we are.. Where we are going.
Copyright 2007 © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation.
Copyright 2007 © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
OWASP Global Education Committee (GEC)
OWASP Leeds OWASP Leeds Chapter OWASP Leeds
Finding and Fighting the Causes of Insecure Applications
Jeff Williams OWASP Chair
Best Practices for Local Chapter Leaders
OWASP Ireland Limerick Chapter Meeting
OWASP 2009 Membership Drive
OWASP BOD Meeting 24 January
The Owasp Orizon Project
An Introduction to Web Application Security

OWASP in favor of a more secure world
Canberra OWASP Chapter meeting
Tour of OWASP’s projects
Virtual Patching “A security policy enforcement layer which prevents the exploitation of a known vulnerability”
Organizing and Delivering the World’s AppSec Information
Agenda About OWASP Upcoming Events
Finding and Fighting the Causes of Insecure Applications
Industry Committee – Recently Completed
WELCOME Welcome to NYC Welcome to OWASP Welcome to AppSec USA 2013!
OWASP Global Projects Committee
OWASP Joomla! (CMS) Vulnerability Scanner Project Flyer
Industry Committee – Recently Completed
Industry Committee – Recently Completed
Presentation transcript:

OWASP Global Projects Committee Committee Update Slides May 19, 2009 1

Global Projects Committee Dinis Cruz, Paulo Coimbra, Jason Li, Matt Tesauro, Leo Cavallari, Pravir Chandra, Brad Causey New Committee Member: Brad Causey Meeting weekly on Monday at 10 PM GMT Organizing and documenting the “rules of engagement” for OWASP projects and the Season of Code Launching the next Season of Code 2 2

Announced at AppSec EU 2009 in Poland Provisional budget of $90,000 OWASP Season of Code 2009 Announced at AppSec EU 2009 in Poland Provisional budget of $90,000 Focus: Improving quality in for key areas OWASP Education Pack Enterprise usability of OWASP Projects Additional Source of Funding Marketing and PR Any project proposals are welcome including joint proposals up to 20K 3 3

Global Committees assist with areas: Education Committee OWASP Season of Code 2009 Global Committees assist with areas: Education Committee OWASP Education Pack Projects Committee Enterprise usability of OWASP Projects Membership & Chapters Committee Additional Sources of Funding Industry and Conference Committee Marketing and PR Projects will be assessed with Criteria v2 4 4

16 Projects launched recently < 6 months Date Project Leader 14-12-2008 Source Code Flaws Top 10 Paolo Perego 09-01-2009 Yasca Michael Scovetta 13-01-2009 Wapiti Nicolas Surribas 14-01-2009 Use of Web Application Firewalls Germany Chapter 23-01-2009 Anti-Malware Giorgio Fedon 30-01-2009 Vicnum Mordecai Kraushar OWASP Proxy Rogan Dawes 06-02-2009 ModSecurity Core Rule Set Project Ryan Barnett 5 5

Web Application Scanner Specification Corey LeBleu Date Project Leader 23-02-2009 Web Application Scanner Specification Corey LeBleu 26-02-2009 Web App Security Metric using Attack Patterns Raja Krovi 27-02-2009 Learn About Encoding Federico Casani 11-03-2009 Software Assurance Maturity Model Pravir Chandra 26-03-2009 Mutillidae Adrian Crenshaw 27-03-2009 Joomla Vulnerability Scanner Aung Khant 01-04-2009 CRM Tom Brennan 05-05-2009 PCI Trey Ford

hypothetical 9 new OWASP Projects – work in progress Leader IntelliPass - Behaviour based Password Lockout System Anurag Agarwal Malware Link Scanner Aung Khant Web Input Vector Extractor Teaser (wivet) v3 Bedirhan Urgun Web Application Harvesting Esteban Ribičić Forensic Analysis Project Evgueni Tchijevski Application Security Survey Project Frederik Security Vulnerability Contextualization Framework Rafal International Security Challenge Sarb N-Stealth Scanner Thiago Zaninotti 7 7