The OWASP Foundation Where we are Where we are going Seba DeleersnyderEoin Keary OWASP Foundation Board.

Slides:



Advertisements
Similar presentations
IBM WebSphere Everyplace Access for Multiplatforms Managing the e-business Customer Experience.
Advertisements

Enabling Technology Innovation using Open Source Software
ICANN Plan for Enhancing Internet Security, Stability and Resiliency.
The OWASP Foundation Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under.
Interactive Financial eXchange XML Usage in Financial Services Mark Tiggas President, Interactive Financial eXchange Open Applications.
Summit 2011 Outcomes PRESENTED BY __________. About the Summit Over 180 application security experts from over 120 companies, 30 different countries,
OpenSAMM Software Assurance Maturity Model Seba Deleersnyder SAMM project co-leaders Pravir Chandra AppSec USA 2014 Project.
The OWASP Foundation Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
The OWASP Foundation Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under.
The OWASP Foundation ABC About me MOSHIUL ISLAM, CISA A: Information System Auditor B: Currently working for a Bank – EBL, IT Security.
Vision for ECR Europe Presentation to National Initiatives April 3 rd, 2003 Paris.
Unified Logs and Reporting for Hybrid Centralized Management
The OWASP Foundation Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under.
The OWASP Foundation Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under.
The OWASP Foundation OWASP Summit 2011 ¿A donde vamos…?
Simple Online Accounts for Your Business – With Help from Microsoft Azure, Big Red Cloud Makes Accounting Easier for Thousands of Businesses MICROSOFT.
The OWASP Foundation Setting up a Secure Development Life Cycle with OWASP Seba Deleersnyder OWASP Foundation Board.
Copyright © The OWASP Foundation This work is available under the Creative Commons SA 2.5 license The OWASP Foundation OWASP BeNeLux 2010
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Overview of REALNEO Technologies REALNEO Web Platform Architecture Overview of Drupal.
Board on Career Development: Strategic Planning David E. Lee Chair Board on Career Development 25 February 2013.
OWASP Intra- Governmental Affairs David Campbell Denver Chapter Puneet Mehta Delhi Chapter.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation.
The OWASP Foundation AppSecEU11 Where we are.. Where we are going Tom Brennan, Eoin Keary, Seba Deleersnyder, Dave Wichers, Jeff Williams,
“Security is a process, not a product” -- Bruce Schneier.
The world’s libraries. Connected. WorldShare platform & Management Services Integrate all of your collections: print, licensed & digital Chris Thewlis.
The OWASP Foundation OWASP The Open Web Application Security Project Join the application security community for free, unbiased, open.
Meet OWASP: resources you can use, today. Antonio Fontes OWASP Geneva Chapter Leader Switzerland.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the Creative Commons Attribution-ShareAlike.
Adra Match BALANCER: Balance Sheet Reconciliation Software Powered by the Microsoft Azure Cloud MICROSOFT AZURE ISV PROFILE: ADRA MATCH Adra Match develops.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
OWASP Update Seba Deleersnyder BE Board OWASP Belgium Chapter Meeting 17-Dec-2013.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the Creative Commons Attribution-ShareAlike.
The OWASP Foundation OWASP Belgium Chapter OWASP Update Sebastien Deleersnyder Foundation Board, Zenitel Belgium
The OWASP Foundation OWASP Belgium Chapter OWASP Update Sebastien Deleersnyder Foundation Board, Zenitel Belgium
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
The OWASP Foundation OWASP Belgium Chapter OWASP Update 12-Sep-2012 Seba Deleersnyder Foundation / BE Board
OWASP ESAPI SwingSet An introduction by Fabio Cerullo.
OWASP Update Seba Deleersnyder BE Board OWASP Belgium Chapter Meeting 12-Feb-2014.
Copyright © The OWASP Foundation This work is available under the Creative Commons SA 2.5 license The OWASP Foundation OWASP AppSec India Aug 2008.
OWASP-Knoxville June 2015 Enjoy the free appetizers and non-alcoholic drinks Cash bar is open for alcoholic drinks.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the Creative Commons Attribution-ShareAlike.
Gaining Unprecedented Visibility into Microsoft Dynamics CRM with Halo’s Pipeline Advisor, Powered by the Microsoft Azure Cloud Platform MICROSOFT AZURE.
Copyright © The OWASP Foundation This work is available under the Creative Commons SA 2.5 license The OWASP Foundation OWASP Denver February 2012.
The OWASP Foundation OWASP Global Update Seba Deleersnyder OWASP Foundation Board Member.
OWASP Foundation OWASP Where we are.. Where we are going.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
June 23, 2016 Organizational Overview. 2 Automation Federation Background A fragmented community of automation professional associations and societies.
The Power To Do More, Together Joshua Marks CTO Curriki.org Ludovic Dubost CEO XWiki SANKORE CONFERENCE AT EDUCATEC-EDUCATICE November 24 th, 2011.
Foundation Board, SAIT Zenitel Belgium
Send Final PPT by Wed 9am. (866) ID: , Leader PIN: 4869
Overview of REALNEO Technologies
OWASP Leeds OWASP Leeds Chapter OWASP Leeds
Speaker’s Name, SAP Month 00, 2017

Canberra OWASP Chapter meeting
Tour of OWASP’s projects
OWASP Charlotte What, Why, Where and How
Single Cell’s Progenitor Powered by Microsoft Azure Improves Organisational Efficiency with Strategic Procurement, Contract Management, and Analytics MICROSOFT.
An Introduction to ZAP The OWASP Zed Attack Proxy
OWASP Update 26-Sep-2012 OWASP Belgium Chapter David Mathy
Presentation transcript:

The OWASP Foundation Where we are Where we are going Seba DeleersnyderEoin Keary OWASP Foundation Board Members BeNeLux OWASP Day 2011

Core Mission The Open Web Application Security Project (OWASP) is a not-for-profit worldwide organization focused on improving the security of application software. Our mission is to make application security visible, so that people and organizations can make informed decisions about true application security risks. Everyone is free to participate in OWASP and all of our materials are available under a free and open software license.

Core Values OPEN Everything at OWASP is radically transparent from our finances to our code INNOVATION OWASP encourages and supports innovation / experiments for solutions to software security challenges GLOBAL Anyone around the world is encouraged to participate in the OWASP community INTEGRITY OWASP is an honest and truthful, vendor agnostic, global community

Celebrating 10 years 4 Dec 2011

Numbers OWASP tools and documentation: ~15,000 downloads (per month) ~30,000 unique visitors (per month) ~2 million website hits (per month) OWASP community is blossoming worldwide OWASP Members in active chapters worldwide 20,000+ participants 5

~140 Projects PROTECT - These are tools and documents that can be used to guard against security-related design and implementation flaws. DETECT - These are tools and documents that can be used to find security-related design and implementation flaws. LIFE CYCLE - These are tools and documents that can be used to add security-related activities into the Software Development Life Cycle (SDLC).

New projects – last months Common Numbering Project HTTP Post Tool Forward Exploit Tool Project Java XML Templates Project ASIDE Project Secure Password Project Secure the Flag Competition Project Security Baseline Project ESAPI Objective – C Project Academy Portal Project Exams Project Portuguese Language Project Browser Security ACID Tests Project Web Browser Testing System Project Java Project Myth Breakers Project LAPSE Project Software Security Assurance Process Enhancing Security Options Framework German Language Project Mantra – Security Framework Java HTML Sanitizer Java Encoder Project WebScarab NG Project Threat Modelling Project Application Security Assessment Standards Project Hackademic Challenges Project Hatkit Proxy Project Hatkit Datafiddler Project ESAPI Swingset Interactive Project ESAPI Swingset Demo Project Web Application Security Accessibility Project Cloud ‐ 10 Project Web Testing Environment Project iGoat Project Opa Mobile Security Project – Mobile Threat Model Codes of Conduct

Spotlight Zed Attack Proxy (ZAP): Intercepting Proxy Automated scanner Passive scanner Brute Force scanner Spider Fuzzer Port scanner Dynamic SSL certificates API Beanshell integration 5 main coders, 15 contributors Fully internationalized Translated into 9 languages: Brazilian Portuguese, Chinese, French, German, Greek, Indonesian, Japanese, Polish, Spanish

Spotlight OWASP Mobile Security: Security testing Development guidance Top 10 controls Mobile threat model GoatDroid Top 10 risks

220 Chapters ~ 100 active 10

Conferences 11

“I saw the ‘blossoming’ of OWASP in Portugal’s Spring. From an external viewpoint, OWASP has moved from niche to widely relevant, from localized to global, from pen testing to SDLC, from server to every component of the application’s delivery and use, from InfoSec to business process relevance.” – Colin Watson

Massive Outreach OWASP-Portugal Partnership OWASP Outreach to Educational Institutions OWASP Industry Outreach OWASP Browser Security Project OWASP-Apache Partnership OWASP Mobile Security Initiative OWASP Governance Expansion International Focus Application Security Programs Application Security Certification

Board Election OWASP Governance maturing – OWASP updated its Bylaws and worked out procedures for the Board elections. These governance updates support the dynamic and growing OWASP community. Currently (5) board members are elected.

6 June 2011 OWASP Europe non-profit established Global extension of organisation Legal & financial support 15

Global Committees

Individual, academic & corporate sponsors

Strategic Goals

2012 Strategic Goals Build the OWASP platform Expand communication channels Grow the OWASP community Financial stability

OWASP Platform Define the processes, resources, and tools to enable volunteers to quickly join and contribute to OWASP in the areas of projects, chapters, education, conferences and connections

Communication Channels Establish effective communication channels into developer groups, universities, and industry groups

OWASP Community Build and grow the OWASP community throughout the world by focusing on the quality of chapters, conferences, and social technologies

Financial Stability Further build out a stable financial foundation and create new sources of income for the organisation to achieve the goals of 2012 and future years.

Our Challenge

25 Application Security Is Just Getting Started You can’t improve what you can’t measure We need to… Experiment Share what works Combine our efforts Expect another 10 years!

Call for action Start or join your OWASP chapter Start or join OWASP projects Translate material (documents, tool interfaces) Join as member Become active in OWASP organisation (committees, board election 2013) Together we will achieve our mission! 26

Enjoy BeNeLux OWASP Day 2011