<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Sbarnum</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Sbarnum"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Sbarnum"/>
		<updated>2026-05-24T04:10:49Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Software_Assurance_Day_DC_2009&amp;diff=57233</id>
		<title>OWASP Software Assurance Day DC 2009</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Software_Assurance_Day_DC_2009&amp;diff=57233"/>
				<updated>2009-03-23T15:19:19Z</updated>
		
		<summary type="html">&lt;p&gt;Sbarnum: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Welcome to the OWASP Software Assurance Day DC 2009. &lt;br /&gt;
&lt;br /&gt;
This single-day conference will be held on March 13th in conjunction with the Software Assurance Forum (March 10th-12th) sponsored by the US Department of Homeland Security, Department of Defense and National Institute of Standards and Technology. &lt;br /&gt;
&lt;br /&gt;
We are pleased to invite OWASP members, attendees of the Software Assurance Forum and any other interested parties to join us for this event. &lt;br /&gt;
&lt;br /&gt;
At this event, you will hear presentations from key leaders in the web application security domain on:&lt;br /&gt;
&lt;br /&gt;
* the state of the union for the Open Web Application Security Project&lt;br /&gt;
* the current status of several ongoing OWASP projects&lt;br /&gt;
* recently released knowledge resources to assist web application security programs in establishing a standard for minimum due care&lt;br /&gt;
* recipes for leveraging OWASP resources in security testing efforts&lt;br /&gt;
* the emerging importance of application security in the wireless domain&lt;br /&gt;
* a state-of-the-art approach to automating multi-perspective application security assessment&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You will also find out how you can leverage OWASP resources and participate in OWASP activities through local chapters in the DC/NOVA/Maryland area.&lt;br /&gt;
&lt;br /&gt;
The co-located Software Assurance Forum is also a free conference and open to any attendees of OWASP Software Assurance Day DC 2009, though it will require separate registration. &lt;br /&gt;
&lt;br /&gt;
For information on registration for the Software Assurance Forum, please contact [mailto:Jennifer.Brezovic@associates.dhs.gov Jennifer Brezovic].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
If you have any questions relating to the conference or just want to help out, please email the conference chair, [mailto:sbarnum@cigital.com Sean Barnum].&lt;br /&gt;
&lt;br /&gt;
'''Registrations must be received by Mar 7th!'''&lt;br /&gt;
&lt;br /&gt;
[http://guest.cvent.com/i.aspx?4W,M3,fd34d554-0341-493c-bfdc-94d42d3e3c6d https://www.owasp.org/images/9/9d/Register_now.gif]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Conference Location==&lt;br /&gt;
&lt;br /&gt;
The OWASP Software Assurance Day DC 2009 will be held in conjunction with the DHS/DOD/NIST Software Assurance Forum at [http://www.mitre.org/about/locations/mitre1_map.html '''MITRE Building 1''']''', 7525 Colshire Drive, McLean, VA 22102.''' &lt;br /&gt;
&lt;br /&gt;
Please use the Conference Center entrance.&lt;br /&gt;
&lt;br /&gt;
==Agenda and Presentations: 13 March 2009==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:80%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot; | March 13, 2009&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 08:15-08:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''OWASP Software Assurance Day DC kickoff''' &lt;br /&gt;
''Sean Barnum, Conference Chair''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 08:30-09:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''Intro to OWASP''' [[Media:Brennan_-_OWASP_SwA_Day_DC_2009_-_OWASP_Intro_and_Overview.pdf‎|   (slides)]]&lt;br /&gt;
''Tom Brennan, WhiteHat Security''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 09:00-09:45 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[Maturing Software Assessment Through Static Analysis]][[Media:Maturing_Assessment_through_SA.ppt|   (slides)]]&lt;br /&gt;
''John Steven, Cigital''&lt;br /&gt;
  |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 09:50-10:35 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[Don’t Write Your Own Security Code: The OWASP Enterprise Security API]] ([http://www.owasp.org/images/f/f2/ESAPI_for_OWASP_Day.pptx slides])&lt;br /&gt;
''Jeff Williams, Aspect Security''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 10:35-10:50 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | '''Morning Break'''&lt;br /&gt;
  |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 10:50-11:35 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[Cooking with OWASP: Recipes in Web Security Testing]][[Media:CookingWithOWASP-opt.pdf|   (slides)]]&lt;br /&gt;
''Paco Hope, Cigital''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 11:40-12:25 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[OWASP Application Security Verification Standard (ASVS)]][[Media:Wichers_-_About_OWASP_ASVS_Web_Edition_v2.pdf‎|   (slides)]]&lt;br /&gt;
''Dave Wichers, Aspect Security''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 12:25-13:40 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | '''Lunch – MITRE Cafeteria'''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 13:45-14:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[CWE/SANS Top 25: Towards Minimum Due Care in Software Security]][[Media:CWE_Top_25_Minimum_Due_Care.pdf‎|   (slides)]]&lt;br /&gt;
''Steve Christey, Mitre''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 14:35-15:20 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[The Future of Mobile:  Developing Secure Mobile Applications]][[Media:Rouse_-_Securing_Mobile_Applications_(size_reduced).pdf‎|   (slides)]]&lt;br /&gt;
''Jason Rouse, Cigital''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 15:25-15:40 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | '''Afternoon Break'''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 15:40-16:25 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[OWASP Live CD:  An open environment for Web Application Security]][[Media:OWASP_Live_CD.pdf‎‎|   (slides)]]&lt;br /&gt;
''Matt Tesauro, Texas Education Agency''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 16:25-16:45 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''Conference Wrap Up and Opportunities to Contribute''' &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Logistics==&lt;br /&gt;
&lt;br /&gt;
Venue: [http://www.mitre.org/about/locations/mitre1_map.html '''MITRE Building 1''']''', 7525 Colshire Drive, McLean, VA 22102'''&lt;br /&gt;
&lt;br /&gt;
Please use the Conference Center entrance.&lt;br /&gt;
&lt;br /&gt;
==Accommodations==&lt;br /&gt;
&lt;br /&gt;
The conference has not negotiated any special rates for hotel accommodation but the following hotels are near the conference venue:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''McLean Hilton&lt;br /&gt;
7920 Jones Branch Drive&lt;br /&gt;
McLean, VA&lt;br /&gt;
Tel: 1-703-448-1234'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://www1.hilton.com/en_US/hi/hotel/MCLMHHH-Hilton-McLean-Tysons-Corner-Virginia/index.do http://www1.hilton.com/en_US/hi/hotel/MCLMHHH-Hilton-McLean-Tysons-Corner-Virginia/index.do]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Westin Hotel&lt;br /&gt;
7801 Leesburg Pike&lt;br /&gt;
Falls Church, VA&lt;br /&gt;
Tel: 1-703-893-1340'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://www.starwoodhotels.com/westin/property/overview/index.html?propertyID=1750 http://www.starwoodhotels.com/westin/property/overview/index.html?propertyID=1750]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Marriott&lt;br /&gt;
8028 Leesburg Pike&lt;br /&gt;
Vienna, VA&lt;br /&gt;
Tel: 1-703-734-3200'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://www.marriott.com/hotels/travel/wastc-tysons-corner-marriott/ http://www.marriott.com/hotels/travel/wastc-tysons-corner-marriott/]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Embassy Suites&lt;br /&gt;
8517 Leesburg Pike&lt;br /&gt;
Vienna, VA&lt;br /&gt;
Tel: 1-703-883-0707'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://embassysuites1.hilton.com/en_US/es/hotel/WASTSES-Embassy-Suites-Tysons-Corner-Virginia/index.do http://embassysuites1.hilton.com/en_US/es/hotel/WASTSES-Embassy-Suites-Tysons-Corner-Virginia/index.do]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''The Crowne Plaza Tysons Corner (formerly the Holiday Inn) &lt;br /&gt;
1960 Chain &lt;br /&gt;
Bridge Rd McLean, VA&lt;br /&gt;
Tel: 1-703-893-2100'''&lt;br /&gt;
&lt;br /&gt;
Website: [http://www.cptysonscorner.com/ http://www.cptysonscorner.com/]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Sheraton Premiere Tysons&lt;br /&gt;
8661 Leesburg Pike&lt;br /&gt;
Vienna, VA&lt;br /&gt;
Tel: 1-703-506-2500'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://www.starwoodhotels.com/sheraton/property/overview/index.html?propertyID=691 http://www.starwoodhotels.com/sheraton/property/overview/index.html?propertyID=691]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Transportation to the Conference==&lt;br /&gt;
===By plane===&lt;br /&gt;
The venue area can be reached by commercial aviation through either [http://www.metwashairports.com/Dulles/ Dulles International Airport] or [http://www.mwaa.com/national/ Reagan National Airport]. &lt;br /&gt;
&lt;br /&gt;
Both are roughly equidistant from the venue and offer a range of airline and flight options.&lt;br /&gt;
===How to get to the venue?===&lt;br /&gt;
See the [http://www.mitre.org/about/locations/mitre1_map.html map].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Registration and Conference Fees==&lt;br /&gt;
&lt;br /&gt;
OWASP Software Assurance Day DC 2009 will be a free conference.&lt;br /&gt;
&lt;br /&gt;
Despite the fact that this is a free conference, we still need you to register to fulfill security requirements of the facility and to ensure that we don't exceed venue capacity.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Registrations must be received by Mar 7th!'''&lt;br /&gt;
&lt;br /&gt;
[http://guest.cvent.com/i.aspx?4W,M3,fd34d554-0341-493c-bfdc-94d42d3e3c6d https://www.owasp.org/images/9/9d/Register_now.gif]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Conference Contacts==&lt;br /&gt;
&lt;br /&gt;
For more information please contact the team below for conference details, sponsorship or registration. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Mr Sean Barnum (Conference Chair)''' , Cigital Federal, Inc.&lt;br /&gt;
&lt;br /&gt;
Email: [mailto:sbarnum@cigital.com sbarnum@cigital.com]&lt;br /&gt;
&lt;br /&gt;
Mobile: 703-473-8262 &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Kate Hartmann''' &lt;br /&gt;
&lt;br /&gt;
OWASP Operations Director &lt;br /&gt;
&lt;br /&gt;
9175 Guilford Road, Suite 300 &lt;br /&gt;
&lt;br /&gt;
Columbia, MD 21046, USA &lt;br /&gt;
&lt;br /&gt;
Phone: +1-301-575-0189 &lt;br /&gt;
&lt;br /&gt;
Facsimile: +1-301-604-8033 &lt;br /&gt;
&lt;br /&gt;
Email: [mailto:kate.hartmann@owasp.org kate.hartmann@owasp.org] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Conference Sponsors==&lt;br /&gt;
&lt;br /&gt;
Under negotiation.&lt;br /&gt;
&lt;br /&gt;
If you are interested in sponsoring this OWASP conference, please contact [mailto:sbarnum@cigital.com Sean Barnum].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 [[Category:OWASP AppSec Conference]]&lt;/div&gt;</summary>
		<author><name>Sbarnum</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=The_Future_of_Mobile:_Developing_Secure_Mobile_Applications&amp;diff=57231</id>
		<title>The Future of Mobile: Developing Secure Mobile Applications</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=The_Future_of_Mobile:_Developing_Secure_Mobile_Applications&amp;diff=57231"/>
				<updated>2009-03-23T15:13:05Z</updated>
		
		<summary type="html">&lt;p&gt;Sbarnum: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==The Presentation: &amp;quot;The Future of Mobile:  Developing Secure Mobile Applications&amp;quot;==&lt;br /&gt;
&lt;br /&gt;
Mobile applications enable millions of users to be more productive, have more fun, and interact with their world in more ways than ever before.  We're approaching mobile applications with many of the same tried-and-true approaches that we've used in more traditional software, but what are the dangers?   Mobile architectures run the gamut from simple web-based applications optimized for mobile displays to custom-built handset-specific applications that can interact directly with the mobile operating system.  &lt;br /&gt;
&lt;br /&gt;
In this talk, we’ll explore the hybrid mobile/web application approach, and discuss the threads that binds them together — information protection and convergence.  Mobile devices are unique in that they offer one of the most potentially hostile environments imaginable -- privacy, compliance, and capture protection top the charts as the three most difficult issues facing mobile applications and those who use them.  We’ll dive into specifics on what are today “mobile-only” threats; that is, those issues such as location-based services or text messages, and discover how they can be compromised, and how we, as security practitioners, can protect them and the back-end applications that service them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Download: [[Media:Rouse_-_Securing_Mobile_Applications_(size_reduced).pdf‎| Securing Mobile Applications.ppt]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==The Speaker: Jason Rouse==&lt;br /&gt;
Mr. Rouse is Cigital’s Wireless and Mobile Security practice leader.  Mr. Rouse has spent the last five years designing, implementing, and deploying state of the art wireless security solutions for mobile environments, spanning access control, application management, payment systems, and hybrid J2EE-and-mobile systems.  Drawing from his wealth of experience in the security space and leveraging over a decade of hands-on experience, Mr. Rouse has become a trusted advisor to Fortune 50 companies, financial groups, and private interests.  As a trusted advisor, Mr. Rouse has led standards efforts, chairing the FSTC Mobile Payment Security workgroup, and has contributed to several mobile payment solutions, greatly enhancing the security and performance of each project.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[OWASP_Software_Assurance_Day_DC_2009#Agenda and Presentations:_13_March_2009|back to Presentation Agenda]]&lt;/div&gt;</summary>
		<author><name>Sbarnum</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Rouse_-_Securing_Mobile_Applications_(size_reduced).pdf&amp;diff=57230</id>
		<title>File:Rouse - Securing Mobile Applications (size reduced).pdf</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Rouse_-_Securing_Mobile_Applications_(size_reduced).pdf&amp;diff=57230"/>
				<updated>2009-03-23T15:12:07Z</updated>
		
		<summary type="html">&lt;p&gt;Sbarnum: Securing Mobile Applications slide deck delivered by Jason Rouse at OWASP Software Assurance Day DC 2009&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Securing Mobile Applications slide deck delivered by Jason Rouse at OWASP Software Assurance Day DC 2009&lt;/div&gt;</summary>
		<author><name>Sbarnum</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Software_Assurance_Day_DC_2009&amp;diff=57229</id>
		<title>OWASP Software Assurance Day DC 2009</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Software_Assurance_Day_DC_2009&amp;diff=57229"/>
				<updated>2009-03-23T15:06:21Z</updated>
		
		<summary type="html">&lt;p&gt;Sbarnum: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Welcome to the OWASP Software Assurance Day DC 2009. &lt;br /&gt;
&lt;br /&gt;
This single-day conference will be held on March 13th in conjunction with the Software Assurance Forum (March 10th-12th) sponsored by the US Department of Homeland Security, Department of Defense and National Institute of Standards and Technology. &lt;br /&gt;
&lt;br /&gt;
We are pleased to invite OWASP members, attendees of the Software Assurance Forum and any other interested parties to join us for this event. &lt;br /&gt;
&lt;br /&gt;
At this event, you will hear presentations from key leaders in the web application security domain on:&lt;br /&gt;
&lt;br /&gt;
* the state of the union for the Open Web Application Security Project&lt;br /&gt;
* the current status of several ongoing OWASP projects&lt;br /&gt;
* recently released knowledge resources to assist web application security programs in establishing a standard for minimum due care&lt;br /&gt;
* recipes for leveraging OWASP resources in security testing efforts&lt;br /&gt;
* the emerging importance of application security in the wireless domain&lt;br /&gt;
* a state-of-the-art approach to automating multi-perspective application security assessment&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You will also find out how you can leverage OWASP resources and participate in OWASP activities through local chapters in the DC/NOVA/Maryland area.&lt;br /&gt;
&lt;br /&gt;
The co-located Software Assurance Forum is also a free conference and open to any attendees of OWASP Software Assurance Day DC 2009, though it will require separate registration. &lt;br /&gt;
&lt;br /&gt;
For information on registration for the Software Assurance Forum, please contact [mailto:Jennifer.Brezovic@associates.dhs.gov Jennifer Brezovic].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
If you have any questions relating to the conference or just want to help out, please email the conference chair, [mailto:sbarnum@cigital.com Sean Barnum].&lt;br /&gt;
&lt;br /&gt;
'''Registrations must be received by Mar 7th!'''&lt;br /&gt;
&lt;br /&gt;
[http://guest.cvent.com/i.aspx?4W,M3,fd34d554-0341-493c-bfdc-94d42d3e3c6d https://www.owasp.org/images/9/9d/Register_now.gif]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Conference Location==&lt;br /&gt;
&lt;br /&gt;
The OWASP Software Assurance Day DC 2009 will be held in conjunction with the DHS/DOD/NIST Software Assurance Forum at [http://www.mitre.org/about/locations/mitre1_map.html '''MITRE Building 1''']''', 7525 Colshire Drive, McLean, VA 22102.''' &lt;br /&gt;
&lt;br /&gt;
Please use the Conference Center entrance.&lt;br /&gt;
&lt;br /&gt;
==Agenda and Presentations: 13 March 2009==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:80%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot; | March 13, 2009&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 08:15-08:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''OWASP Software Assurance Day DC kickoff''' &lt;br /&gt;
''Sean Barnum, Conference Chair''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 08:30-09:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''Intro to OWASP''' [[Media:Brennan_-_OWASP_SwA_Day_DC_2009_-_OWASP_Intro_and_Overview.pdf‎|   (Download slides)]]&lt;br /&gt;
''Tom Brennan, WhiteHat Security''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 09:00-09:45 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[Maturing Software Assessment Through Static Analysis]]&lt;br /&gt;
''John Steven, Cigital''&lt;br /&gt;
  |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 09:50-10:35 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[Don’t Write Your Own Security Code: The OWASP Enterprise Security API]] ([http://www.owasp.org/images/f/f2/ESAPI_for_OWASP_Day.pptx slides])&lt;br /&gt;
''Jeff Williams, Aspect Security''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 10:35-10:50 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | '''Morning Break'''&lt;br /&gt;
  |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 10:50-11:35 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[Cooking with OWASP: Recipes in Web Security Testing]]&lt;br /&gt;
''Paco Hope, Cigital''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 11:40-12:25 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[OWASP Application Security Verification Standard (ASVS)]]&lt;br /&gt;
''Dave Wichers, Aspect Security''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 12:25-13:40 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | '''Lunch – MITRE Cafeteria'''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 13:45-14:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[CWE/SANS Top 25: Towards Minimum Due Care in Software Security]]&lt;br /&gt;
''Steve Christey, Mitre''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 14:35-15:20 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[The Future of Mobile:  Developing Secure Mobile Applications]]&lt;br /&gt;
''Jason Rouse, Cigital''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 15:25-15:40 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | '''Afternoon Break'''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 15:40-16:25 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[OWASP Live CD:  An open environment for Web Application Security]]&lt;br /&gt;
''Matt Tesauro, Texas Education Agency''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 16:25-16:45 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''Conference Wrap Up and Opportunities to Contribute''' &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Logistics==&lt;br /&gt;
&lt;br /&gt;
Venue: [http://www.mitre.org/about/locations/mitre1_map.html '''MITRE Building 1''']''', 7525 Colshire Drive, McLean, VA 22102'''&lt;br /&gt;
&lt;br /&gt;
Please use the Conference Center entrance.&lt;br /&gt;
&lt;br /&gt;
==Accommodations==&lt;br /&gt;
&lt;br /&gt;
The conference has not negotiated any special rates for hotel accommodation but the following hotels are near the conference venue:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''McLean Hilton&lt;br /&gt;
7920 Jones Branch Drive&lt;br /&gt;
McLean, VA&lt;br /&gt;
Tel: 1-703-448-1234'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://www1.hilton.com/en_US/hi/hotel/MCLMHHH-Hilton-McLean-Tysons-Corner-Virginia/index.do http://www1.hilton.com/en_US/hi/hotel/MCLMHHH-Hilton-McLean-Tysons-Corner-Virginia/index.do]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Westin Hotel&lt;br /&gt;
7801 Leesburg Pike&lt;br /&gt;
Falls Church, VA&lt;br /&gt;
Tel: 1-703-893-1340'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://www.starwoodhotels.com/westin/property/overview/index.html?propertyID=1750 http://www.starwoodhotels.com/westin/property/overview/index.html?propertyID=1750]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Marriott&lt;br /&gt;
8028 Leesburg Pike&lt;br /&gt;
Vienna, VA&lt;br /&gt;
Tel: 1-703-734-3200'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://www.marriott.com/hotels/travel/wastc-tysons-corner-marriott/ http://www.marriott.com/hotels/travel/wastc-tysons-corner-marriott/]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Embassy Suites&lt;br /&gt;
8517 Leesburg Pike&lt;br /&gt;
Vienna, VA&lt;br /&gt;
Tel: 1-703-883-0707'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://embassysuites1.hilton.com/en_US/es/hotel/WASTSES-Embassy-Suites-Tysons-Corner-Virginia/index.do http://embassysuites1.hilton.com/en_US/es/hotel/WASTSES-Embassy-Suites-Tysons-Corner-Virginia/index.do]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''The Crowne Plaza Tysons Corner (formerly the Holiday Inn) &lt;br /&gt;
1960 Chain &lt;br /&gt;
Bridge Rd McLean, VA&lt;br /&gt;
Tel: 1-703-893-2100'''&lt;br /&gt;
&lt;br /&gt;
Website: [http://www.cptysonscorner.com/ http://www.cptysonscorner.com/]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Sheraton Premiere Tysons&lt;br /&gt;
8661 Leesburg Pike&lt;br /&gt;
Vienna, VA&lt;br /&gt;
Tel: 1-703-506-2500'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://www.starwoodhotels.com/sheraton/property/overview/index.html?propertyID=691 http://www.starwoodhotels.com/sheraton/property/overview/index.html?propertyID=691]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Transportation to the Conference==&lt;br /&gt;
===By plane===&lt;br /&gt;
The venue area can be reached by commercial aviation through either [http://www.metwashairports.com/Dulles/ Dulles International Airport] or [http://www.mwaa.com/national/ Reagan National Airport]. &lt;br /&gt;
&lt;br /&gt;
Both are roughly equidistant from the venue and offer a range of airline and flight options.&lt;br /&gt;
===How to get to the venue?===&lt;br /&gt;
See the [http://www.mitre.org/about/locations/mitre1_map.html map].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Registration and Conference Fees==&lt;br /&gt;
&lt;br /&gt;
OWASP Software Assurance Day DC 2009 will be a free conference.&lt;br /&gt;
&lt;br /&gt;
Despite the fact that this is a free conference, we still need you to register to fulfill security requirements of the facility and to ensure that we don't exceed venue capacity.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Registrations must be received by Mar 7th!'''&lt;br /&gt;
&lt;br /&gt;
[http://guest.cvent.com/i.aspx?4W,M3,fd34d554-0341-493c-bfdc-94d42d3e3c6d https://www.owasp.org/images/9/9d/Register_now.gif]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Conference Contacts==&lt;br /&gt;
&lt;br /&gt;
For more information please contact the team below for conference details, sponsorship or registration. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Mr Sean Barnum (Conference Chair)''' , Cigital Federal, Inc.&lt;br /&gt;
&lt;br /&gt;
Email: [mailto:sbarnum@cigital.com sbarnum@cigital.com]&lt;br /&gt;
&lt;br /&gt;
Mobile: 703-473-8262 &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Kate Hartmann''' &lt;br /&gt;
&lt;br /&gt;
OWASP Operations Director &lt;br /&gt;
&lt;br /&gt;
9175 Guilford Road, Suite 300 &lt;br /&gt;
&lt;br /&gt;
Columbia, MD 21046, USA &lt;br /&gt;
&lt;br /&gt;
Phone: +1-301-575-0189 &lt;br /&gt;
&lt;br /&gt;
Facsimile: +1-301-604-8033 &lt;br /&gt;
&lt;br /&gt;
Email: [mailto:kate.hartmann@owasp.org kate.hartmann@owasp.org] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Conference Sponsors==&lt;br /&gt;
&lt;br /&gt;
Under negotiation.&lt;br /&gt;
&lt;br /&gt;
If you are interested in sponsoring this OWASP conference, please contact [mailto:sbarnum@cigital.com Sean Barnum].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 [[Category:OWASP AppSec Conference]]&lt;/div&gt;</summary>
		<author><name>Sbarnum</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Brennan_-_OWASP_SwA_Day_DC_2009_-_OWASP_Intro_and_Overview.pdf&amp;diff=57228</id>
		<title>File:Brennan - OWASP SwA Day DC 2009 - OWASP Intro and Overview.pdf</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Brennan_-_OWASP_SwA_Day_DC_2009_-_OWASP_Intro_and_Overview.pdf&amp;diff=57228"/>
				<updated>2009-03-23T15:05:13Z</updated>
		
		<summary type="html">&lt;p&gt;Sbarnum: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Sbarnum</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Software_Assurance_Day_DC_2009&amp;diff=57227</id>
		<title>OWASP Software Assurance Day DC 2009</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Software_Assurance_Day_DC_2009&amp;diff=57227"/>
				<updated>2009-03-23T15:02:55Z</updated>
		
		<summary type="html">&lt;p&gt;Sbarnum: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Welcome to the OWASP Software Assurance Day DC 2009. &lt;br /&gt;
&lt;br /&gt;
This single-day conference will be held on March 13th in conjunction with the Software Assurance Forum (March 10th-12th) sponsored by the US Department of Homeland Security, Department of Defense and National Institute of Standards and Technology. &lt;br /&gt;
&lt;br /&gt;
We are pleased to invite OWASP members, attendees of the Software Assurance Forum and any other interested parties to join us for this event. &lt;br /&gt;
&lt;br /&gt;
At this event, you will hear presentations from key leaders in the web application security domain on:&lt;br /&gt;
&lt;br /&gt;
* the state of the union for the Open Web Application Security Project&lt;br /&gt;
* the current status of several ongoing OWASP projects&lt;br /&gt;
* recently released knowledge resources to assist web application security programs in establishing a standard for minimum due care&lt;br /&gt;
* recipes for leveraging OWASP resources in security testing efforts&lt;br /&gt;
* the emerging importance of application security in the wireless domain&lt;br /&gt;
* a state-of-the-art approach to automating multi-perspective application security assessment&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You will also find out how you can leverage OWASP resources and participate in OWASP activities through local chapters in the DC/NOVA/Maryland area.&lt;br /&gt;
&lt;br /&gt;
The co-located Software Assurance Forum is also a free conference and open to any attendees of OWASP Software Assurance Day DC 2009, though it will require separate registration. &lt;br /&gt;
&lt;br /&gt;
For information on registration for the Software Assurance Forum, please contact [mailto:Jennifer.Brezovic@associates.dhs.gov Jennifer Brezovic].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
If you have any questions relating to the conference or just want to help out, please email the conference chair, [mailto:sbarnum@cigital.com Sean Barnum].&lt;br /&gt;
&lt;br /&gt;
'''Registrations must be received by Mar 7th!'''&lt;br /&gt;
&lt;br /&gt;
[http://guest.cvent.com/i.aspx?4W,M3,fd34d554-0341-493c-bfdc-94d42d3e3c6d https://www.owasp.org/images/9/9d/Register_now.gif]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Conference Location==&lt;br /&gt;
&lt;br /&gt;
The OWASP Software Assurance Day DC 2009 will be held in conjunction with the DHS/DOD/NIST Software Assurance Forum at [http://www.mitre.org/about/locations/mitre1_map.html '''MITRE Building 1''']''', 7525 Colshire Drive, McLean, VA 22102.''' &lt;br /&gt;
&lt;br /&gt;
Please use the Conference Center entrance.&lt;br /&gt;
&lt;br /&gt;
==Agenda and Presentations: 13 March 2009==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:80%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot; | March 13, 2009&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 08:15-08:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''OWASP Software Assurance Day DC kickoff''' &lt;br /&gt;
''Sean Barnum, Conference Chair''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 08:30-09:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[Intro to OWASP]]&lt;br /&gt;
''Tom Brennan, WhiteHat Security''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 09:00-09:45 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[Maturing Software Assessment Through Static Analysis]]&lt;br /&gt;
''John Steven, Cigital''&lt;br /&gt;
  |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 09:50-10:35 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[Don’t Write Your Own Security Code: The OWASP Enterprise Security API]] ([http://www.owasp.org/images/f/f2/ESAPI_for_OWASP_Day.pptx slides])&lt;br /&gt;
''Jeff Williams, Aspect Security''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 10:35-10:50 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | '''Morning Break'''&lt;br /&gt;
  |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 10:50-11:35 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[Cooking with OWASP: Recipes in Web Security Testing]]&lt;br /&gt;
''Paco Hope, Cigital''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 11:40-12:25 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[OWASP Application Security Verification Standard (ASVS)]]&lt;br /&gt;
''Dave Wichers, Aspect Security''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 12:25-13:40 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | '''Lunch – MITRE Cafeteria'''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 13:45-14:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[CWE/SANS Top 25: Towards Minimum Due Care in Software Security]]&lt;br /&gt;
''Steve Christey, Mitre''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 14:35-15:20 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[The Future of Mobile:  Developing Secure Mobile Applications]]&lt;br /&gt;
''Jason Rouse, Cigital''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 15:25-15:40 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | '''Afternoon Break'''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 15:40-16:25 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[OWASP Live CD:  An open environment for Web Application Security]]&lt;br /&gt;
''Matt Tesauro, Texas Education Agency''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 16:25-16:45 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''Conference Wrap Up and Opportunities to Contribute''' &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Logistics==&lt;br /&gt;
&lt;br /&gt;
Venue: [http://www.mitre.org/about/locations/mitre1_map.html '''MITRE Building 1''']''', 7525 Colshire Drive, McLean, VA 22102'''&lt;br /&gt;
&lt;br /&gt;
Please use the Conference Center entrance.&lt;br /&gt;
&lt;br /&gt;
==Accommodations==&lt;br /&gt;
&lt;br /&gt;
The conference has not negotiated any special rates for hotel accommodation but the following hotels are near the conference venue:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''McLean Hilton&lt;br /&gt;
7920 Jones Branch Drive&lt;br /&gt;
McLean, VA&lt;br /&gt;
Tel: 1-703-448-1234'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://www1.hilton.com/en_US/hi/hotel/MCLMHHH-Hilton-McLean-Tysons-Corner-Virginia/index.do http://www1.hilton.com/en_US/hi/hotel/MCLMHHH-Hilton-McLean-Tysons-Corner-Virginia/index.do]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Westin Hotel&lt;br /&gt;
7801 Leesburg Pike&lt;br /&gt;
Falls Church, VA&lt;br /&gt;
Tel: 1-703-893-1340'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://www.starwoodhotels.com/westin/property/overview/index.html?propertyID=1750 http://www.starwoodhotels.com/westin/property/overview/index.html?propertyID=1750]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Marriott&lt;br /&gt;
8028 Leesburg Pike&lt;br /&gt;
Vienna, VA&lt;br /&gt;
Tel: 1-703-734-3200'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://www.marriott.com/hotels/travel/wastc-tysons-corner-marriott/ http://www.marriott.com/hotels/travel/wastc-tysons-corner-marriott/]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Embassy Suites&lt;br /&gt;
8517 Leesburg Pike&lt;br /&gt;
Vienna, VA&lt;br /&gt;
Tel: 1-703-883-0707'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://embassysuites1.hilton.com/en_US/es/hotel/WASTSES-Embassy-Suites-Tysons-Corner-Virginia/index.do http://embassysuites1.hilton.com/en_US/es/hotel/WASTSES-Embassy-Suites-Tysons-Corner-Virginia/index.do]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''The Crowne Plaza Tysons Corner (formerly the Holiday Inn) &lt;br /&gt;
1960 Chain &lt;br /&gt;
Bridge Rd McLean, VA&lt;br /&gt;
Tel: 1-703-893-2100'''&lt;br /&gt;
&lt;br /&gt;
Website: [http://www.cptysonscorner.com/ http://www.cptysonscorner.com/]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Sheraton Premiere Tysons&lt;br /&gt;
8661 Leesburg Pike&lt;br /&gt;
Vienna, VA&lt;br /&gt;
Tel: 1-703-506-2500'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://www.starwoodhotels.com/sheraton/property/overview/index.html?propertyID=691 http://www.starwoodhotels.com/sheraton/property/overview/index.html?propertyID=691]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Transportation to the Conference==&lt;br /&gt;
===By plane===&lt;br /&gt;
The venue area can be reached by commercial aviation through either [http://www.metwashairports.com/Dulles/ Dulles International Airport] or [http://www.mwaa.com/national/ Reagan National Airport]. &lt;br /&gt;
&lt;br /&gt;
Both are roughly equidistant from the venue and offer a range of airline and flight options.&lt;br /&gt;
===How to get to the venue?===&lt;br /&gt;
See the [http://www.mitre.org/about/locations/mitre1_map.html map].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Registration and Conference Fees==&lt;br /&gt;
&lt;br /&gt;
OWASP Software Assurance Day DC 2009 will be a free conference.&lt;br /&gt;
&lt;br /&gt;
Despite the fact that this is a free conference, we still need you to register to fulfill security requirements of the facility and to ensure that we don't exceed venue capacity.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Registrations must be received by Mar 7th!'''&lt;br /&gt;
&lt;br /&gt;
[http://guest.cvent.com/i.aspx?4W,M3,fd34d554-0341-493c-bfdc-94d42d3e3c6d https://www.owasp.org/images/9/9d/Register_now.gif]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Conference Contacts==&lt;br /&gt;
&lt;br /&gt;
For more information please contact the team below for conference details, sponsorship or registration. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Mr Sean Barnum (Conference Chair)''' , Cigital Federal, Inc.&lt;br /&gt;
&lt;br /&gt;
Email: [mailto:sbarnum@cigital.com sbarnum@cigital.com]&lt;br /&gt;
&lt;br /&gt;
Mobile: 703-473-8262 &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Kate Hartmann''' &lt;br /&gt;
&lt;br /&gt;
OWASP Operations Director &lt;br /&gt;
&lt;br /&gt;
9175 Guilford Road, Suite 300 &lt;br /&gt;
&lt;br /&gt;
Columbia, MD 21046, USA &lt;br /&gt;
&lt;br /&gt;
Phone: +1-301-575-0189 &lt;br /&gt;
&lt;br /&gt;
Facsimile: +1-301-604-8033 &lt;br /&gt;
&lt;br /&gt;
Email: [mailto:kate.hartmann@owasp.org kate.hartmann@owasp.org] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Conference Sponsors==&lt;br /&gt;
&lt;br /&gt;
Under negotiation.&lt;br /&gt;
&lt;br /&gt;
If you are interested in sponsoring this OWASP conference, please contact [mailto:sbarnum@cigital.com Sean Barnum].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 [[Category:OWASP AppSec Conference]]&lt;/div&gt;</summary>
		<author><name>Sbarnum</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Application_Security_Verification_Standard_(ASVS)&amp;diff=57226</id>
		<title>OWASP Application Security Verification Standard (ASVS)</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Application_Security_Verification_Standard_(ASVS)&amp;diff=57226"/>
				<updated>2009-03-23T14:59:34Z</updated>
		
		<summary type="html">&lt;p&gt;Sbarnum: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==The Presentation: &amp;quot;OWASP Application Security Verification Standard (ASVS)&amp;quot;==&lt;br /&gt;
&lt;br /&gt;
Providers of web application security verification services can take wildly different approaches and levels of rigor, ranging from using simple search tools to performing painstaking code review and manual testing. This process also typically involves searching for and only reporting vulnerabilities, but does not necessarily comment on what good security practices were found.&lt;br /&gt;
All of these problems have a single root cause: the lack of a standard for performing application-level security verification that can be used for any application without special interpretation. The OWASP Application Security Verification Standard (ASVS) was designed to normalize the range in coverage, level of rigor, and reporting requirements available in the market when it comes to performing application security verification.&lt;br /&gt;
By the end of this presentation, you will understand how OWASP ASVS defines:&lt;br /&gt;
* Levels of application-level security verification that increase in breadth and depth as one moves up the levels,&lt;br /&gt;
* Verification requirements that prescribe a unique white-list approach for security controls,&lt;br /&gt;
* Reporting requirements that ensure reports are sufficiently detailed to make verification repeatable, and to determine if the verification was accurate and complete.&lt;br /&gt;
&lt;br /&gt;
Download: [[Media:Wichers_-_About_OWASP_ASVS_Web_Edition_v2.pdf‎ ‎| About OWASP ASVS Web Edition.pdf‎]]&lt;br /&gt;
&lt;br /&gt;
==The Speaker: Dave Wichers==&lt;br /&gt;
Dave Wichers is a cofounder and the Chief Operating Officer (COO) of [http://www.aspectsecurity.com Aspect Security], a company that specializes in application security services. For OWASP, he is the volunteer [[:Category:OWASP_AppSec_Conference | OWASP Conferences]] Chair, a volunteer member of the [[About_OWASP#Global_Board_Members|OWASP Board]], a coauthor of the [[OWASP_Top_Ten_Project | OWASP Top 10]] and the [[ASVS | OWASP Application Security Verification Standard]], and a contributor to the [[ESAPI | OWASP Enterprise Security API (ESAPI)]] project.&lt;br /&gt;
&lt;br /&gt;
[[OWASP_Software_Assurance_Day_DC_2009#Agenda and Presentations:_13_March_2009|back to Presentation Agenda]]&lt;/div&gt;</summary>
		<author><name>Sbarnum</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Wichers_-_About_OWASP_ASVS_Web_Edition_v2.pdf&amp;diff=57225</id>
		<title>File:Wichers - About OWASP ASVS Web Edition v2.pdf</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Wichers_-_About_OWASP_ASVS_Web_Edition_v2.pdf&amp;diff=57225"/>
				<updated>2009-03-23T14:58:53Z</updated>
		
		<summary type="html">&lt;p&gt;Sbarnum: Updated deck from OWASP Software Assurance Day DC 2009&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Updated deck from OWASP Software Assurance Day DC 2009&lt;/div&gt;</summary>
		<author><name>Sbarnum</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Live_CD:_An_open_environment_for_Web_Application_Security&amp;diff=56653</id>
		<title>OWASP Live CD: An open environment for Web Application Security</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Live_CD:_An_open_environment_for_Web_Application_Security&amp;diff=56653"/>
				<updated>2009-03-13T16:11:06Z</updated>
		
		<summary type="html">&lt;p&gt;Sbarnum: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==The Presentation: &amp;quot;OWASP Live CD:  An open environment for Web Application Security&amp;quot;==&lt;br /&gt;
&lt;br /&gt;
The OWASP Live CD is a project that collects some of the best open source security projects in a single environment.  Web developers, testers and security professionals can boot from this Live CD and have access to a full security testing suite. This allows its users to test for various security issues in web applications and web sites. The Live CD also contains documentation and an interactive learning environment to enhance users web application security knowledge.  This presentation will cover the current state of the OWASP Live CD as well as the plans for future developments.  Time permitting, a live demonstration of the OWASP Live CD will be conducted.  The OWASP Live CD is a project of the Open Web Application Security Project (OWASP) and is free for commercial or non-commercial use.  More information is available at:&lt;br /&gt;
http://www.owasp.org/index.php/Category:OWASP_Live_CD_Project&lt;br /&gt;
&lt;br /&gt;
Download: [[Media:OWASP_Live_CD.pdf‎‎| OWASP_Live_CD.pdf‎]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==The Speaker: Matt Tesauro==&lt;br /&gt;
Matt Tesauro has worked in web application development and security since 2000. He has worn many different hats, from developer to DBA to System Administrator to Penetration Tester. Matt also taught graduate and undergraduate classes on web application development and XML at the Texas A&amp;amp;M Mays Business School. Currently, he's focused on web application security and developing a Secure SDLC for TEA. Outside work, he is the project lead for the OWASP Live CD Project and is also a member of the OWASP Global Projects Committee. Matt Tesauro has a B.S.&lt;br /&gt;
in Economics and a M.S in Management Information Systems from Texas A&amp;amp;M University. He is also has the CISSP, CEH (Certified Ethical Hacker), RHCE (Red Hat Certified Engineer), and Linux+ certifications.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[OWASP_Software_Assurance_Day_DC_2009#Agenda and Presentations:_13_March_2009|back to Presentation Agenda]]&lt;/div&gt;</summary>
		<author><name>Sbarnum</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:OWASP_Live_CD.pdf&amp;diff=56651</id>
		<title>File:OWASP Live CD.pdf</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:OWASP_Live_CD.pdf&amp;diff=56651"/>
				<updated>2009-03-13T16:10:38Z</updated>
		
		<summary type="html">&lt;p&gt;Sbarnum: OWASP Live CD: An open environment for web application security presentation deck from OWASP Software Assurance Day DC 2009
Presenter: Matt Tesauro - TEA (LiveCD Project lead)&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;OWASP Live CD: An open environment for web application security presentation deck from OWASP Software Assurance Day DC 2009&lt;br /&gt;
Presenter: Matt Tesauro - TEA (LiveCD Project lead)&lt;/div&gt;</summary>
		<author><name>Sbarnum</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=The_Future_of_Mobile:_Developing_Secure_Mobile_Applications&amp;diff=56650</id>
		<title>The Future of Mobile: Developing Secure Mobile Applications</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=The_Future_of_Mobile:_Developing_Secure_Mobile_Applications&amp;diff=56650"/>
				<updated>2009-03-13T16:05:50Z</updated>
		
		<summary type="html">&lt;p&gt;Sbarnum: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==The Presentation: &amp;quot;The Future of Mobile:  Developing Secure Mobile Applications&amp;quot;==&lt;br /&gt;
&lt;br /&gt;
Mobile applications enable millions of users to be more productive, have more fun, and interact with their world in more ways than ever before.  We're approaching mobile applications with many of the same tried-and-true approaches that we've used in more traditional software, but what are the dangers?   Mobile architectures run the gamut from simple web-based applications optimized for mobile displays to custom-built handset-specific applications that can interact directly with the mobile operating system.  &lt;br /&gt;
&lt;br /&gt;
In this talk, we’ll explore the hybrid mobile/web application approach, and discuss the threads that binds them together — information protection and convergence.  Mobile devices are unique in that they offer one of the most potentially hostile environments imaginable -- privacy, compliance, and capture protection top the charts as the three most difficult issues facing mobile applications and those who use them.  We’ll dive into specifics on what are today “mobile-only” threats; that is, those issues such as location-based services or text messages, and discover how they can be compromised, and how we, as security practitioners, can protect them and the back-end applications that service them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Download: [[Media:‎| ]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==The Speaker: Jason Rouse==&lt;br /&gt;
Mr. Rouse is Cigital’s Wireless and Mobile Security practice leader.  Mr. Rouse has spent the last five years designing, implementing, and deploying state of the art wireless security solutions for mobile environments, spanning access control, application management, payment systems, and hybrid J2EE-and-mobile systems.  Drawing from his wealth of experience in the security space and leveraging over a decade of hands-on experience, Mr. Rouse has become a trusted advisor to Fortune 50 companies, financial groups, and private interests.  As a trusted advisor, Mr. Rouse has led standards efforts, chairing the FSTC Mobile Payment Security workgroup, and has contributed to several mobile payment solutions, greatly enhancing the security and performance of each project.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[OWASP_Software_Assurance_Day_DC_2009#Agenda and Presentations:_13_March_2009|back to Presentation Agenda]]&lt;/div&gt;</summary>
		<author><name>Sbarnum</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=CWE/SANS_Top_25:_Towards_Minimum_Due_Care_in_Software_Security&amp;diff=56649</id>
		<title>CWE/SANS Top 25: Towards Minimum Due Care in Software Security</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=CWE/SANS_Top_25:_Towards_Minimum_Due_Care_in_Software_Security&amp;diff=56649"/>
				<updated>2009-03-13T16:01:48Z</updated>
		
		<summary type="html">&lt;p&gt;Sbarnum: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==The Presentation: &amp;quot;CWE/SANS Top 25: Towards Minimum Due Care in Software Security&amp;quot;==&lt;br /&gt;
&lt;br /&gt;
The CWE/SANS Top 25 Most Dangerous Programming Errors list was released on January 12, 2009, and quickly achieved the rare accomplishment of actually getting noticed by people who don't do security full time.  But once January 13 rolled around, the overall response can be summarized in two words: &amp;quot;NOW what?&amp;quot;  What place does the Top 25 have in the grand scheme of software security, when there are already competing efforts like the OWASP Top Ten?  How was the Top 25 arrived at, and what should its role be in compliance, software acquisition, developer awareness, and - perhaps most importantly - starting the conversation about software security?  What are these &amp;quot;weakness&amp;quot; things anyway?  If the Top 25 is covered, how much assurance does that really provide, and does anything else get covered for free?  And finally: what next?  Mr Christey will answer and re-ask these questions in order to frame the Top 25 as an early step in a long journey towards software security.  Along the way, he will discuss the Top 25's role in the web world (and outside of it), highlight the two entries that tied for Number 26 and why they didn't make it, and how the Top 25 can concretely demonstrate how there still isn't a &amp;quot;Silver Bullet&amp;quot; for software security.&lt;br /&gt;
&lt;br /&gt;
Download: [[Media:CWE_Top_25_Minimum_Due_Care.pdf‎ ‎| CWE Top 25 Minimum Due Care.pdf‎ ]]&lt;br /&gt;
&lt;br /&gt;
==The Speaker: Steve Christey==&lt;br /&gt;
Steve Christey is a Principal Information Security Engineer in the Security and Information Operations Division at The MITRE Corporation.&lt;br /&gt;
Since 1999, he has been the Editor of the Common Vulnerabilities and Exposures (CVE) list and the Chair of the CVE Editorial Board.  He is the technical lead of the Common Weakness Enumeration (CWE) project.&lt;br /&gt;
He was the technical editor of the 2009 CWE/SANS Top 25 Most Dangerous Programming Errors list and an active contributor to other efforts including the SANS Secure Programming exams, NIST's Static Analysis Tool Exposition (SATE), and the Common Vulnerability Scoring System (CVSS).  His current interests include secure software development and testing, the theoretical underpinnings of vulnerabilities, making software security accessible to the general public, vulnerability information management including post-disclosure analysis, and vulnerability research.  Past work, which dates back to 1993, includes co-authoring the &amp;quot;Responsible Vulnerability Disclosure Process&amp;quot; draft with Chris Wysopal in 2002, reverse engineering of malicious code, automated vulnerability analysis of source code, and vulnerability scanning and incident response.  He holds a B.S. in Computer Science from Hobart College.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[OWASP_Software_Assurance_Day_DC_2009#Agenda and Presentations:_13_March_2009|back to Presentation Agenda]]&lt;/div&gt;</summary>
		<author><name>Sbarnum</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:CWE_Top_25_Minimum_Due_Care.pdf&amp;diff=56648</id>
		<title>File:CWE Top 25 Minimum Due Care.pdf</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:CWE_Top_25_Minimum_Due_Care.pdf&amp;diff=56648"/>
				<updated>2009-03-13T16:01:10Z</updated>
		
		<summary type="html">&lt;p&gt;Sbarnum: CWE Top 25 Minimum Due Care presentation deck from OWASP Software Assurance Day DC 2009
Presenter: Steve Christey - Mitre&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;CWE Top 25 Minimum Due Care presentation deck from OWASP Software Assurance Day DC 2009&lt;br /&gt;
Presenter: Steve Christey - Mitre&lt;/div&gt;</summary>
		<author><name>Sbarnum</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Application_Security_Verification_Standard_(ASVS)&amp;diff=56647</id>
		<title>OWASP Application Security Verification Standard (ASVS)</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Application_Security_Verification_Standard_(ASVS)&amp;diff=56647"/>
				<updated>2009-03-13T15:58:30Z</updated>
		
		<summary type="html">&lt;p&gt;Sbarnum: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==The Presentation: &amp;quot;OWASP Application Security Verification Standard (ASVS)&amp;quot;==&lt;br /&gt;
&lt;br /&gt;
Providers of web application security verification services can take wildly different approaches and levels of rigor, ranging from using simple search tools to performing painstaking code review and manual testing. This process also typically involves searching for and only reporting vulnerabilities, but does not necessarily comment on what good security practices were found.&lt;br /&gt;
All of these problems have a single root cause: the lack of a standard for performing application-level security verification that can be used for any application without special interpretation. The OWASP Application Security Verification Standard (ASVS) was designed to normalize the range in coverage, level of rigor, and reporting requirements available in the market when it comes to performing application security verification.&lt;br /&gt;
By the end of this presentation, you will understand how OWASP ASVS defines:&lt;br /&gt;
* Levels of application-level security verification that increase in breadth and depth as one moves up the levels,&lt;br /&gt;
* Verification requirements that prescribe a unique white-list approach for security controls,&lt;br /&gt;
* Reporting requirements that ensure reports are sufficiently detailed to make verification repeatable, and to determine if the verification was accurate and complete.&lt;br /&gt;
&lt;br /&gt;
Download: [[Media:About_OWASP_ASVS_Web_Edition.pdf‎ ‎| About OWASP ASVS Web Edition.pdf‎]]&lt;br /&gt;
&lt;br /&gt;
==The Speaker: Dave Wichers==&lt;br /&gt;
Dave Wichers is a cofounder and the Chief Operating Officer (COO) of [http://www.aspectsecurity.com Aspect Security], a company that specializes in application security services. For OWASP, he is the volunteer [[:Category:OWASP_AppSec_Conference | OWASP Conferences]] Chair, a volunteer member of the [[About_OWASP#Global_Board_Members|OWASP Board]], a coauthor of the [[OWASP_Top_Ten_Project | OWASP Top 10]] and the [[ASVS | OWASP Application Security Verification Standard]], and a contributor to the [[ESAPI | OWASP Enterprise Security API (ESAPI)]] project.&lt;br /&gt;
&lt;br /&gt;
[[OWASP_Software_Assurance_Day_DC_2009#Agenda and Presentations:_13_March_2009|back to Presentation Agenda]]&lt;/div&gt;</summary>
		<author><name>Sbarnum</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Application_Security_Verification_Standard_(ASVS)&amp;diff=56646</id>
		<title>OWASP Application Security Verification Standard (ASVS)</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Application_Security_Verification_Standard_(ASVS)&amp;diff=56646"/>
				<updated>2009-03-13T15:58:16Z</updated>
		
		<summary type="html">&lt;p&gt;Sbarnum: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==The Presentation: &amp;quot;OWASP Application Security Verification Standard (ASVS)&amp;quot;==&lt;br /&gt;
&lt;br /&gt;
Providers of web application security verification services can take wildly different approaches and levels of rigor, ranging from using simple search tools to performing painstaking code review and manual testing. This process also typically involves searching for and only reporting vulnerabilities, but does not necessarily comment on what good security practices were found.&lt;br /&gt;
All of these problems have a single root cause: the lack of a standard for performing application-level security verification that can be used for any application without special interpretation. The OWASP Application Security Verification Standard (ASVS) was designed to normalize the range in coverage, level of rigor, and reporting requirements available in the market when it comes to performing application security verification.&lt;br /&gt;
By the end of this presentation, you will understand how OWASP ASVS defines:&lt;br /&gt;
* Levels of application-level security verification that increase in breadth and depth as one moves up the levels,&lt;br /&gt;
* Verification requirements that prescribe a unique white-list approach for security controls,&lt;br /&gt;
* Reporting requirements that ensure reports are sufficiently detailed to make verification repeatable, and to determine if the verification was accurate and complete.&lt;br /&gt;
&lt;br /&gt;
Download: [[Media:About_OWASP_ASVS_Web_Edition.pdf‎ ‎| About OWASP ASVS Web Edition.pdf‎ .ppt]]&lt;br /&gt;
&lt;br /&gt;
==The Speaker: Dave Wichers==&lt;br /&gt;
Dave Wichers is a cofounder and the Chief Operating Officer (COO) of [http://www.aspectsecurity.com Aspect Security], a company that specializes in application security services. For OWASP, he is the volunteer [[:Category:OWASP_AppSec_Conference | OWASP Conferences]] Chair, a volunteer member of the [[About_OWASP#Global_Board_Members|OWASP Board]], a coauthor of the [[OWASP_Top_Ten_Project | OWASP Top 10]] and the [[ASVS | OWASP Application Security Verification Standard]], and a contributor to the [[ESAPI | OWASP Enterprise Security API (ESAPI)]] project.&lt;br /&gt;
&lt;br /&gt;
[[OWASP_Software_Assurance_Day_DC_2009#Agenda and Presentations:_13_March_2009|back to Presentation Agenda]]&lt;/div&gt;</summary>
		<author><name>Sbarnum</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:About_OWASP_ASVS_Web_Edition.pdf&amp;diff=56645</id>
		<title>File:About OWASP ASVS Web Edition.pdf</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:About_OWASP_ASVS_Web_Edition.pdf&amp;diff=56645"/>
				<updated>2009-03-13T15:56:06Z</updated>
		
		<summary type="html">&lt;p&gt;Sbarnum: About OWASP ASVS Web Edition presentation deck from OWASP Software Assurance Day DC 2009.
Presenter: Dave Wichers - OWASP Board Member (Aspect Security)&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;About OWASP ASVS Web Edition presentation deck from OWASP Software Assurance Day DC 2009.&lt;br /&gt;
Presenter: Dave Wichers - OWASP Board Member (Aspect Security)&lt;/div&gt;</summary>
		<author><name>Sbarnum</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cooking_with_OWASP:_Recipes_in_Web_Security_Testing&amp;diff=56644</id>
		<title>Cooking with OWASP: Recipes in Web Security Testing</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cooking_with_OWASP:_Recipes_in_Web_Security_Testing&amp;diff=56644"/>
				<updated>2009-03-13T15:53:17Z</updated>
		
		<summary type="html">&lt;p&gt;Sbarnum: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==The Presentation: &amp;quot;Cooking with OWASP: Recipes in Web Security Testing&amp;quot;==&lt;br /&gt;
&lt;br /&gt;
Many of the OWASP projects are tools that you can use to test web applications directly., but not just from a security assessor’s point of view. Software testers need to be able to work security testing into their day-to-day testing regimen. In this talk, Paco will show you a few recipes from his recently released “Web Security Testing Cookbook” that feature OWASP tools. You’ll see how to cheat at some Facebook games by decoding their data with CAL9000, how to assess session ID strength using WebScarab, and how to fuzz web services with wsFuzzer. This talk is all about how to get some actionable hands-on results from some outstanding OWASP tools.&lt;br /&gt;
&lt;br /&gt;
Download: [[Media:CookingWithOWASP-opt.pdf‎‎| Cooking With OWASP.pdf‎]]&lt;br /&gt;
&lt;br /&gt;
==The Speaker: Paco Hope==&lt;br /&gt;
Paco Hope  is a Technical Manager with Cigital, Inc. and has 12 years of experience in the security of web applications, operating systems, and embedded devices (lottery systems, cell phones, casino gaming devices, smart cards). As a consultant, his customers include MasterCard International, WMS Gaming, GTECH, FINRA (the US securities exchange regulator) and Sterling Commerce (an AT&amp;amp;T Company). He is a frequent speaker on security testing and web application security. His current passion is bringing the techniques of security assessment into the mainstream activities of QA departments and testers. He is co-author of two security books and is also a prior co-chair of VERIFY, an international conference on software testing.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[OWASP_Software_Assurance_Day_DC_2009#Agenda and Presentations:_13_March_2009|back to Presentation Agenda]]&lt;/div&gt;</summary>
		<author><name>Sbarnum</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:CookingWithOWASP-opt.pdf&amp;diff=56643</id>
		<title>File:CookingWithOWASP-opt.pdf</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:CookingWithOWASP-opt.pdf&amp;diff=56643"/>
				<updated>2009-03-13T15:51:33Z</updated>
		
		<summary type="html">&lt;p&gt;Sbarnum: Cooking With OWASP presentation deck from OWASP Software Assurance Day DC 2009
Presenter: Paco Hope - Cigital, Inc.
Optimized for printing&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Cooking With OWASP presentation deck from OWASP Software Assurance Day DC 2009&lt;br /&gt;
Presenter: Paco Hope - Cigital, Inc.&lt;br /&gt;
Optimized for printing&lt;/div&gt;</summary>
		<author><name>Sbarnum</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Software_Assurance_Day_DC_2009&amp;diff=55477</id>
		<title>OWASP Software Assurance Day DC 2009</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Software_Assurance_Day_DC_2009&amp;diff=55477"/>
				<updated>2009-02-25T17:39:19Z</updated>
		
		<summary type="html">&lt;p&gt;Sbarnum: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Welcome to the OWASP Software Assurance Day DC 2009. &lt;br /&gt;
&lt;br /&gt;
This single-day conference will be held on March 13th in conjunction with the Software Assurance Forum (March 10th-12th) sponsored by the US Department of Homeland Security, Department of Defense and National Institute of Standards and Technology. &lt;br /&gt;
&lt;br /&gt;
We are pleased to invite OWASP members, attendees of the Software Assurance Forum and any other interested parties to join us for this event. &lt;br /&gt;
&lt;br /&gt;
At this event, you will hear presentations from key leaders in the web application security domain on:&lt;br /&gt;
&lt;br /&gt;
* the state of the union for the Open Web Application Security Project&lt;br /&gt;
* the current status of several ongoing OWASP projects&lt;br /&gt;
* recently released knowledge resources to assist web application security programs in establishing a standard for minimum due care&lt;br /&gt;
* recipes for leveraging OWASP resources in security testing efforts&lt;br /&gt;
* the emerging importance of application security in the wireless domain&lt;br /&gt;
* a state-of-the-art approach to automating multi-perspective application security assessment&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You will also find out how you can leverage OWASP resources and participate in OWASP activities through local chapters in the DC/NOVA/Maryland area.&lt;br /&gt;
&lt;br /&gt;
The co-located Software Assurance Forum is also a free conference and open to any attendees of OWASP Software Assurance Day DC 2009, though it will require separate registration. &lt;br /&gt;
&lt;br /&gt;
For information on registration for the Software Assurance Forum, please contact [mailto:Jennifer.Brezovic@associates.dhs.gov Jennifer Brezovic].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
If you have any questions relating to the conference or just want to help out, please email the conference chair, [mailto:sbarnum@cigital.com Sean Barnum].&lt;br /&gt;
&lt;br /&gt;
'''Registrations must be received by Mar 7th!'''&lt;br /&gt;
&lt;br /&gt;
[http://guest.cvent.com/i.aspx?4W,M3,fd34d554-0341-493c-bfdc-94d42d3e3c6d https://www.owasp.org/images/9/9d/Register_now.gif]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Conference Location==&lt;br /&gt;
&lt;br /&gt;
The OWASP Software Assurance Day DC 2009 will be held in conjunction with the DHS/DOD/NIST Software Assurance Forum at [http://www.mitre.org/about/locations/mitre1_map.html '''MITRE Building 1''']''', 7525 Colshire Drive, McLean, VA 22102.''' &lt;br /&gt;
&lt;br /&gt;
Please use the Conference Center entrance.&lt;br /&gt;
&lt;br /&gt;
==Agenda and Presentations: 13 March 2009==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:80%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot; | March 13, 2009&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 08:15-08:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''OWASP Software Assurance Day DC kickoff''' &lt;br /&gt;
''Sean Barnum, Conference Chair''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 08:30-09:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''Intro to OWASP'''&lt;br /&gt;
''Tom Brennan''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 09:00-09:45 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[Maturing Software Assessment Through Static Analysis]]&lt;br /&gt;
''John Steven, Cigital''&lt;br /&gt;
  |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 09:50-10:35 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[Don’t Write Your Own Security Code: The OWASP Enterprise Security API']]&lt;br /&gt;
''Jeff Williams, Aspect Security''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 10:35-10:50 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | '''Morning Break'''&lt;br /&gt;
  |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 10:50-11:35 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[Cooking with OWASP: Recipes in Web Security Testing]]&lt;br /&gt;
''Paco Hope, Cigital''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 11:40-12:25 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[OWASP Application Security Verification Standard (ASVS)]]&lt;br /&gt;
''Dave Wichers, Aspect Security''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 12:25-13:40 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | '''Lunch – MITRE Cafeteria'''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 13:45-14:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[CWE/SANS Top 25: Towards Minimum Due Care in Software Security]]&lt;br /&gt;
''Steve Christey, Mitre''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 14:35-15:20 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[The Future of Mobile:  Developing Secure Mobile Applications]]&lt;br /&gt;
''Jason Rouse, Cigital''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 15:25-15:40 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | '''Afternoon Break'''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 15:40-16:25 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[OWASP Live CD:  An open environment for Web Application Security]]&lt;br /&gt;
''Matt Tesauro, Texas Education Agency''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 16:25-16:45 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''Conference Wrap Up and Opportunities to Contribute''' &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Logistics==&lt;br /&gt;
&lt;br /&gt;
Venue: [http://www.mitre.org/about/locations/mitre1_map.html '''MITRE Building 1''']''', 7525 Colshire Drive, McLean, VA 22102'''&lt;br /&gt;
&lt;br /&gt;
Please use the Conference Center entrance.&lt;br /&gt;
&lt;br /&gt;
==Accommodations==&lt;br /&gt;
&lt;br /&gt;
The conference has not negotiated any special rates for hotel accommodation but the following hotels are near the conference venue:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''McLean Hilton&lt;br /&gt;
7920 Jones Branch Drive&lt;br /&gt;
McLean, VA&lt;br /&gt;
Tel: 1-703-448-1234'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://www1.hilton.com/en_US/hi/hotel/MCLMHHH-Hilton-McLean-Tysons-Corner-Virginia/index.do http://www1.hilton.com/en_US/hi/hotel/MCLMHHH-Hilton-McLean-Tysons-Corner-Virginia/index.do]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Westin Hotel&lt;br /&gt;
7801 Leesburg Pike&lt;br /&gt;
Falls Church, VA&lt;br /&gt;
Tel: 1-703-893-1340'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://www.starwoodhotels.com/westin/property/overview/index.html?propertyID=1750 http://www.starwoodhotels.com/westin/property/overview/index.html?propertyID=1750]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Marriott&lt;br /&gt;
8028 Leesburg Pike&lt;br /&gt;
Vienna, VA&lt;br /&gt;
Tel: 1-703-734-3200'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://www.marriott.com/hotels/travel/wastc-tysons-corner-marriott/ http://www.marriott.com/hotels/travel/wastc-tysons-corner-marriott/]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Embassy Suites&lt;br /&gt;
8517 Leesburg Pike&lt;br /&gt;
Vienna, VA&lt;br /&gt;
Tel: 1-703-883-0707'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://embassysuites1.hilton.com/en_US/es/hotel/WASTSES-Embassy-Suites-Tysons-Corner-Virginia/index.do http://embassysuites1.hilton.com/en_US/es/hotel/WASTSES-Embassy-Suites-Tysons-Corner-Virginia/index.do]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''The Crowne Plaza Tysons Corner (formerly the Holiday Inn) &lt;br /&gt;
1960 Chain &lt;br /&gt;
Bridge Rd McLean, VA&lt;br /&gt;
Tel: 1-703-893-2100'''&lt;br /&gt;
&lt;br /&gt;
Website: [http://www.cptysonscorner.com/ http://www.cptysonscorner.com/]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Sheraton Premiere Tysons&lt;br /&gt;
8661 Leesburg Pike&lt;br /&gt;
Vienna, VA&lt;br /&gt;
Tel: 1-703-506-2500'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://www.starwoodhotels.com/sheraton/property/overview/index.html?propertyID=691 http://www.starwoodhotels.com/sheraton/property/overview/index.html?propertyID=691]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Transportation to the Conference==&lt;br /&gt;
===By plane===&lt;br /&gt;
The venue area can be reached by commercial aviation through either [http://www.metwashairports.com/Dulles/ Dulles International Airport] or [http://www.mwaa.com/national/ Reagan National Airport]. &lt;br /&gt;
&lt;br /&gt;
Both are roughly equidistant from the venue and offer a range of airline and flight options.&lt;br /&gt;
===How to get to the venue?===&lt;br /&gt;
See the [http://www.mitre.org/about/locations/mitre1_map.html map].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Registration and Conference Fees==&lt;br /&gt;
&lt;br /&gt;
OWASP Software Assurance Day DC 2009 will be a free conference.&lt;br /&gt;
&lt;br /&gt;
Despite the fact that this is a free conference, we still need you to register to fulfill security requirements of the facility and to ensure that we don't exceed venue capacity.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Registrations must be received by Mar 7th!'''&lt;br /&gt;
&lt;br /&gt;
[http://guest.cvent.com/i.aspx?4W,M3,fd34d554-0341-493c-bfdc-94d42d3e3c6d https://www.owasp.org/images/9/9d/Register_now.gif]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Conference Contacts==&lt;br /&gt;
&lt;br /&gt;
For more information please contact the team below for conference details, sponsorship or registration. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Mr Sean Barnum (Conference Chair)''' , Cigital Federal, Inc.&lt;br /&gt;
&lt;br /&gt;
Email: [mailto:sbarnum@cigital.com sbarnum@cigital.com]&lt;br /&gt;
&lt;br /&gt;
Mobile: 703-473-8262 &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Kate Hartmann''' &lt;br /&gt;
&lt;br /&gt;
OWASP Operations Director &lt;br /&gt;
&lt;br /&gt;
9175 Guilford Road, Suite 300 &lt;br /&gt;
&lt;br /&gt;
Columbia, MD 21046, USA &lt;br /&gt;
&lt;br /&gt;
Phone: +1-301-575-0189 &lt;br /&gt;
&lt;br /&gt;
Facsimile: +1-301-604-8033 &lt;br /&gt;
&lt;br /&gt;
Email: [mailto:kate.hartmann@owasp.org kate.hartmann@owasp.org] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Conference Sponsors==&lt;br /&gt;
&lt;br /&gt;
Under negotiation.&lt;br /&gt;
&lt;br /&gt;
If you are interested in sponsoring this OWASP conference, please contact [mailto:sbarnum@cigital.com Sean Barnum].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 [[Category:OWASP AppSec Conference]]&lt;/div&gt;</summary>
		<author><name>Sbarnum</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Software_Assurance_Day_DC_2009&amp;diff=55429</id>
		<title>OWASP Software Assurance Day DC 2009</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Software_Assurance_Day_DC_2009&amp;diff=55429"/>
				<updated>2009-02-25T06:31:08Z</updated>
		
		<summary type="html">&lt;p&gt;Sbarnum: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Welcome to the OWASP Software Assurance Day DC 2009. &lt;br /&gt;
&lt;br /&gt;
This single-day conference will be held on March 13th in conjunction with the Software Assurance Forum (March 10th-12th) sponsored by the US Department of Homeland Security, Department of Defense and National Institute of Standards and Technology. &lt;br /&gt;
&lt;br /&gt;
We are pleased to invite OWASP members, attendees of the Software Assurance Forum and any other interested parties to join us for this event. &lt;br /&gt;
&lt;br /&gt;
At this event, you will hear presentations from key leaders in the web application security domain on:&lt;br /&gt;
&lt;br /&gt;
* the state of the union for the Open Web Application Security Project&lt;br /&gt;
* the current status of several ongoing OWASP projects&lt;br /&gt;
* recently released knowledge resources to assist web application security programs in establishing a standard for minimum due care&lt;br /&gt;
* recipes for leveraging OWASP resources in security testing efforts&lt;br /&gt;
* the emerging importance of application security in the wireless domain&lt;br /&gt;
* a state-of-the-art approach to automating multi-perspective application security assessment&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You will also find out how you can leverage OWASP resources and participate in OWASP activities through local chapters in the DC/NOVA/Maryland area.&lt;br /&gt;
&lt;br /&gt;
The co-located Software Assurance Forum is also a free conference and open to any attendees of OWASP Software Assurance Day DC 2009, though it will require separate registration. &lt;br /&gt;
&lt;br /&gt;
For information on registration for the Software Assurance Forum, please contact [mailto:Jennifer.Brezovic@associates.dhs.gov Jennifer Brezovic].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
If you have any questions relating to the conference or just want to help out, please email the conference chair, [mailto:sbarnum@cigital.com Sean Barnum].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://guest.cvent.com/i.aspx?4W,M3,fd34d554-0341-493c-bfdc-94d42d3e3c6d https://www.owasp.org/images/9/9d/Register_now.gif]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Conference Location==&lt;br /&gt;
&lt;br /&gt;
The OWASP Software Assurance Day DC 2009 will be held in conjunction with the DHS/DOD/NIST Software Assurance Forum at [http://www.mitre.org/about/locations/mitre1_map.html '''MITRE Building 1''']''', 7525 Colshire Drive, McLean, VA 22102.''' &lt;br /&gt;
&lt;br /&gt;
Please use the Conference Center entrance.&lt;br /&gt;
&lt;br /&gt;
==Agenda and Presentations: 13 March 2009==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:80%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot; | March 13, 2009&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 08:15-08:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''OWASP Software Assurance Day DC kickoff''' &lt;br /&gt;
''Sean Barnum, Conference Chair''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 08:30-09:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''Intro to OWASP'''&lt;br /&gt;
''Tom Brennan''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 09:00-09:45 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[Maturing Software Assessment Through Static Analysis]]&lt;br /&gt;
''John Steven, Cigital''&lt;br /&gt;
  |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 09:50-10:35 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[Don’t Write Your Own Security Code: The OWASP Enterprise Security API']]&lt;br /&gt;
''Jeff Williams, Aspect Security''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 10:35-10:50 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | '''Morning Break'''&lt;br /&gt;
  |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 10:50-11:35 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[Cooking with OWASP: Recipes in Web Security Testing]]&lt;br /&gt;
''Paco Hope, Cigital''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 11:40-12:25 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[OWASP Application Security Verification Standard (ASVS)]]&lt;br /&gt;
''Dave Wichers, Aspect Security''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 12:25-13:40 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | '''Lunch – MITRE Cafeteria'''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 13:45-14:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[CWE/SANS Top 25: Towards Minimum Due Care in Software Security]]&lt;br /&gt;
''Steve Christey, Mitre''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 14:35-15:20 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[The Future of Mobile:  Developing Secure Mobile Applications]]&lt;br /&gt;
''Jason Rouse, Cigital''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 15:25-15:40 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | '''Afternoon Break'''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 15:40-16:25 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[OWASP Live CD:  An open environment for Web Application Security]]&lt;br /&gt;
''Matt Tesauro, Texas Education Agency''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 16:25-16:45 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''Conference Wrap Up and Opportunities to Contribute''' &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Logistics==&lt;br /&gt;
&lt;br /&gt;
Venue: [http://www.mitre.org/about/locations/mitre1_map.html '''MITRE Building 1''']''', 7525 Colshire Drive, McLean, VA 22102'''&lt;br /&gt;
&lt;br /&gt;
Please use the Conference Center entrance.&lt;br /&gt;
&lt;br /&gt;
==Accommodations==&lt;br /&gt;
&lt;br /&gt;
The conference has not negotiated any special rates for hotel accommodation but the following hotels are near the conference venue:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''McLean Hilton&lt;br /&gt;
7920 Jones Branch Drive&lt;br /&gt;
McLean, VA&lt;br /&gt;
Tel: 1-703-448-1234'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://www1.hilton.com/en_US/hi/hotel/MCLMHHH-Hilton-McLean-Tysons-Corner-Virginia/index.do http://www1.hilton.com/en_US/hi/hotel/MCLMHHH-Hilton-McLean-Tysons-Corner-Virginia/index.do]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Westin Hotel&lt;br /&gt;
7801 Leesburg Pike&lt;br /&gt;
Falls Church, VA&lt;br /&gt;
Tel: 1-703-893-1340'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://www.starwoodhotels.com/westin/property/overview/index.html?propertyID=1750 http://www.starwoodhotels.com/westin/property/overview/index.html?propertyID=1750]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Marriott&lt;br /&gt;
8028 Leesburg Pike&lt;br /&gt;
Vienna, VA&lt;br /&gt;
Tel: 1-703-734-3200'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://www.marriott.com/hotels/travel/wastc-tysons-corner-marriott/ http://www.marriott.com/hotels/travel/wastc-tysons-corner-marriott/]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Embassy Suites&lt;br /&gt;
8517 Leesburg Pike&lt;br /&gt;
Vienna, VA&lt;br /&gt;
Tel: 1-703-883-0707'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://embassysuites1.hilton.com/en_US/es/hotel/WASTSES-Embassy-Suites-Tysons-Corner-Virginia/index.do http://embassysuites1.hilton.com/en_US/es/hotel/WASTSES-Embassy-Suites-Tysons-Corner-Virginia/index.do]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''The Crowne Plaza Tysons Corner (formerly the Holiday Inn) &lt;br /&gt;
1960 Chain &lt;br /&gt;
Bridge Rd McLean, VA&lt;br /&gt;
Tel: 1-703-893-2100'''&lt;br /&gt;
&lt;br /&gt;
Website: [http://www.cptysonscorner.com/ http://www.cptysonscorner.com/]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Sheraton Premiere Tysons&lt;br /&gt;
8661 Leesburg Pike&lt;br /&gt;
Vienna, VA&lt;br /&gt;
Tel: 1-703-506-2500'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://www.starwoodhotels.com/sheraton/property/overview/index.html?propertyID=691 http://www.starwoodhotels.com/sheraton/property/overview/index.html?propertyID=691]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Transportation to the Conference==&lt;br /&gt;
===By plane===&lt;br /&gt;
The venue area can be reached by commercial aviation through either [http://www.metwashairports.com/Dulles/ Dulles International Airport] or [http://www.mwaa.com/national/ Reagan National Airport]. &lt;br /&gt;
&lt;br /&gt;
Both are roughly equidistant from the venue and offer a range of airline and flight options.&lt;br /&gt;
===How to get to the venue?===&lt;br /&gt;
See the [http://www.mitre.org/about/locations/mitre1_map.html map].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Registration and Conference Fees==&lt;br /&gt;
&lt;br /&gt;
OWASP Software Assurance Day DC 2009 will be a free conference.&lt;br /&gt;
&lt;br /&gt;
Despite the fact that this is a free conference, we still need you to register to fulfill security requirements of the facility and to ensure that we don't exceed venue capacity.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://guest.cvent.com/i.aspx?4W,M3,fd34d554-0341-493c-bfdc-94d42d3e3c6d https://www.owasp.org/images/9/9d/Register_now.gif]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Conference Contacts==&lt;br /&gt;
&lt;br /&gt;
For more information please contact the team below for conference details, sponsorship or registration. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Mr Sean Barnum (Conference Chair)''' , Cigital Federal, Inc.&lt;br /&gt;
&lt;br /&gt;
Email: [mailto:sbarnum@cigital.com sbarnum@cigital.com]&lt;br /&gt;
&lt;br /&gt;
Mobile: 703-473-8262 &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Kate Hartmann''' &lt;br /&gt;
&lt;br /&gt;
OWASP Operations Director &lt;br /&gt;
&lt;br /&gt;
9175 Guilford Road, Suite 300 &lt;br /&gt;
&lt;br /&gt;
Columbia, MD 21046, USA &lt;br /&gt;
&lt;br /&gt;
Phone: +1-301-575-0189 &lt;br /&gt;
&lt;br /&gt;
Facsimile: +1-301-604-8033 &lt;br /&gt;
&lt;br /&gt;
Email: [mailto:kate.hartmann@owasp.org kate.hartmann@owasp.org] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Conference Sponsors==&lt;br /&gt;
&lt;br /&gt;
Under negotiation.&lt;br /&gt;
&lt;br /&gt;
If you are interested in sponsoring this OWASP conference, please contact [mailto:sbarnum@cigital.com Sean Barnum].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 [[Category:OWASP AppSec Conference]]&lt;/div&gt;</summary>
		<author><name>Sbarnum</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Live_CD:_An_open_environment_for_Web_Application_Security&amp;diff=55428</id>
		<title>OWASP Live CD: An open environment for Web Application Security</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Live_CD:_An_open_environment_for_Web_Application_Security&amp;diff=55428"/>
				<updated>2009-02-25T06:28:54Z</updated>
		
		<summary type="html">&lt;p&gt;Sbarnum: New page: ==The Presentation: &amp;quot;OWASP Live CD:  An open environment for Web Application Security&amp;quot;==  The OWASP Live CD is a project that collects some of the best open source security projects in a s...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==The Presentation: &amp;quot;OWASP Live CD:  An open environment for Web Application Security&amp;quot;==&lt;br /&gt;
&lt;br /&gt;
The OWASP Live CD is a project that collects some of the best open source security projects in a single environment.  Web developers, testers and security professionals can boot from this Live CD and have access to a full security testing suite. This allows its users to test for various security issues in web applications and web sites. The Live CD also contains documentation and an interactive learning environment to enhance users web application security knowledge.  This presentation will cover the current state of the OWASP Live CD as well as the plans for future developments.  Time permitting, a live demonstration of the OWASP Live CD will be conducted.  The OWASP Live CD is a project of the Open Web Application Security Project (OWASP) and is free for commercial or non-commercial use.  More information is available at:&lt;br /&gt;
http://www.owasp.org/index.php/Category:OWASP_Live_CD_Project&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==The Speaker: Matt Tesauro==&lt;br /&gt;
Matt Tesauro has worked in web application development and security since 2000. He has worn many different hats, from developer to DBA to System Administrator to Penetration Tester. Matt also taught graduate and undergraduate classes on web application development and XML at the Texas A&amp;amp;M Mays Business School. Currently, he's focused on web application security and developing a Secure SDLC for TEA. Outside work, he is the project lead for the OWASP Live CD Project and is also a member of the OWASP Global Projects Committee. Matt Tesauro has a B.S.&lt;br /&gt;
in Economics and a M.S in Management Information Systems from Texas A&amp;amp;M University. He is also has the CISSP, CEH (Certified Ethical Hacker), RHCE (Red Hat Certified Engineer), and Linux+ certifications.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[OWASP_Software_Assurance_Day_DC_2009#Agenda and Presentations:_13_March_2009|back to Presentation Agenda]]&lt;/div&gt;</summary>
		<author><name>Sbarnum</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=The_Future_of_Mobile:_Developing_Secure_Mobile_Applications&amp;diff=55427</id>
		<title>The Future of Mobile: Developing Secure Mobile Applications</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=The_Future_of_Mobile:_Developing_Secure_Mobile_Applications&amp;diff=55427"/>
				<updated>2009-02-25T06:27:37Z</updated>
		
		<summary type="html">&lt;p&gt;Sbarnum: New page: ==The Presentation: &amp;quot;The Future of Mobile:  Developing Secure Mobile Applications&amp;quot;==  Mobile applications enable millions of users to be more productive, have more fun, and interact with t...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==The Presentation: &amp;quot;The Future of Mobile:  Developing Secure Mobile Applications&amp;quot;==&lt;br /&gt;
&lt;br /&gt;
Mobile applications enable millions of users to be more productive, have more fun, and interact with their world in more ways than ever before.  We're approaching mobile applications with many of the same tried-and-true approaches that we've used in more traditional software, but what are the dangers?   Mobile architectures run the gamut from simple web-based applications optimized for mobile displays to custom-built handset-specific applications that can interact directly with the mobile operating system.  &lt;br /&gt;
&lt;br /&gt;
In this talk, we’ll explore the hybrid mobile/web application approach, and discuss the threads that binds them together — information protection and convergence.  Mobile devices are unique in that they offer one of the most potentially hostile environments imaginable -- privacy, compliance, and capture protection top the charts as the three most difficult issues facing mobile applications and those who use them.  We’ll dive into specifics on what are today “mobile-only” threats; that is, those issues such as location-based services or text messages, and discover how they can be compromised, and how we, as security practitioners, can protect them and the back-end applications that service them.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==The Speaker: Jason Rouse==&lt;br /&gt;
Mr. Rouse is Cigital’s Wireless and Mobile Security practice leader.  Mr. Rouse has spent the last five years designing, implementing, and deploying state of the art wireless security solutions for mobile environments, spanning access control, application management, payment systems, and hybrid J2EE-and-mobile systems.  Drawing from his wealth of experience in the security space and leveraging over a decade of hands-on experience, Mr. Rouse has become a trusted advisor to Fortune 50 companies, financial groups, and private interests.  As a trusted advisor, Mr. Rouse has led standards efforts, chairing the FSTC Mobile Payment Security workgroup, and has contributed to several mobile payment solutions, greatly enhancing the security and performance of each project.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[OWASP_Software_Assurance_Day_DC_2009#Agenda and Presentations:_13_March_2009|back to Presentation Agenda]]&lt;/div&gt;</summary>
		<author><name>Sbarnum</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Maturing_Software_Assessment_Through_Static_Analysis&amp;diff=55426</id>
		<title>Maturing Software Assessment Through Static Analysis</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Maturing_Software_Assessment_Through_Static_Analysis&amp;diff=55426"/>
				<updated>2009-02-25T06:22:51Z</updated>
		
		<summary type="html">&lt;p&gt;Sbarnum: New page: ==The Presentation: &amp;quot;Maturing Software Assessment Through Static Analysis&amp;quot;==  '''Presentation Abstract'''  Organizations have struggled to understand the place of dynamic security testing ...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==The Presentation: &amp;quot;Maturing Software Assessment Through Static Analysis&amp;quot;==&lt;br /&gt;
&lt;br /&gt;
'''Presentation Abstract'''&lt;br /&gt;
&lt;br /&gt;
Organizations have struggled to understand the place of dynamic security testing techniques and their penetration testing tool use has suffered setbacks as a result. Likewise, as these same organizations turn to static analysis tools they find themselves struggling to decide who should run the tool and what kinds of vulnerabilities the tool will find for them. Finally, organizations lament the lack of depth or scale associated with their manual security analyses. This presentation will show how recent approaches to holistic application assessment at Cigital have overcome the limitations of existing tools by combining industry-best scanning tools and open source technologies for continuous integration. This combination, in turn, has the security benefit of scanning tools to be seen more closely to when vulnerabilities are introduced (and can be fixed) and allows them to be applied more frequently.&lt;br /&gt;
&lt;br /&gt;
'''Prerequisites'''&lt;br /&gt;
&lt;br /&gt;
A working understanding of common security vulnerabilities and experience using vulnerability scanning tools (preferably static analysis tools) will help.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==The Speaker: John Steven==&lt;br /&gt;
John Steven is the Senior Director, Advanced Technology Consulting at Cigital, Inc.  His experience includes research in static code analysis and hands-on architecture and implementation of high-performance, scalable Java EE systems. John has provided security consulting services to a broad variety of commercial clients including two of the largest trading platforms in the world and has advised America’s largest internet provider in the Midwest on security and forensics.  John led the development of Cigital’s architectural analysis methodology and its approach to deploying enterprise software security frameworks. He has demonstrated success in building Cigital’s intellectual property for providing cutting-edge security.  He brings this experience and a track record of effective strategic innovation to clients seeking to change, whether to adopt more cutting-edge approaches, or to solidify ROI.  John currently chairs the SD Best Practices security track and co-edits the building security in department of IEEE’s Security and Privacy magazine. John has served on numerous conference panels regarding software security, wireless security and Java EE system development.  He holds a B.S. in Computer Engineering and an M.S. in Computer Science from Case Western Reserve University.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[OWASP_Software_Assurance_Day_DC_2009#Agenda and Presentations:_13_March_2009|back to Presentation Agenda]]&lt;/div&gt;</summary>
		<author><name>Sbarnum</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Application_Security_Verification_Standard_(ASVS)&amp;diff=55425</id>
		<title>OWASP Application Security Verification Standard (ASVS)</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Application_Security_Verification_Standard_(ASVS)&amp;diff=55425"/>
				<updated>2009-02-25T06:20:31Z</updated>
		
		<summary type="html">&lt;p&gt;Sbarnum: New page: ==The Presentation: &amp;quot;OWASP Application Security Verification Standard (ASVS)&amp;quot;==  Providers of web application security verification services can take wildly different approaches and levels...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==The Presentation: &amp;quot;OWASP Application Security Verification Standard (ASVS)&amp;quot;==&lt;br /&gt;
&lt;br /&gt;
Providers of web application security verification services can take wildly different approaches and levels of rigor, ranging from using simple search tools to performing painstaking code review and manual testing. This process also typically involves searching for and only reporting vulnerabilities, but does not necessarily comment on what good security practices were found.&lt;br /&gt;
All of these problems have a single root cause: the lack of a standard for performing application-level security verification that can be used for any application without special interpretation. The OWASP Application Security Verification Standard (ASVS) was designed to normalize the range in coverage, level of rigor, and reporting requirements available in the market when it comes to performing application security verification.&lt;br /&gt;
By the end of this presentation, you will understand how OWASP ASVS defines:&lt;br /&gt;
* Levels of application-level security verification that increase in breadth and depth as one moves up the levels,&lt;br /&gt;
* Verification requirements that prescribe a unique white-list approach for security controls,&lt;br /&gt;
* Reporting requirements that ensure reports are sufficiently detailed to make verification repeatable, and to determine if the verification was accurate and complete.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==The Speaker: Dave Wichers==&lt;br /&gt;
Dave Wichers is a cofounder and the Chief Operating Officer (COO) of Aspect Security, a company that specializes in application security services. For OWASP, he is the volunteer  OWASP Conferences Chair, a volunteer member of the OWASP Board, a coauthor of the  OWASP Top 10 and the  OWASP ASVS, and a contributor to the  OWASP Enterprise Security API (ESAPI) project.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[OWASP_Software_Assurance_Day_DC_2009#Agenda and Presentations:_13_March_2009|back to Presentation Agenda]]&lt;/div&gt;</summary>
		<author><name>Sbarnum</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Cooking_with_OWASP:_Recipes_in_Web_Security_Testing&amp;diff=55424</id>
		<title>Cooking with OWASP: Recipes in Web Security Testing</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Cooking_with_OWASP:_Recipes_in_Web_Security_Testing&amp;diff=55424"/>
				<updated>2009-02-25T06:18:54Z</updated>
		
		<summary type="html">&lt;p&gt;Sbarnum: New page: ==The Presentation: &amp;quot;Cooking with OWASP: Recipes in Web Security Testing&amp;quot;==  Many of the OWASP projects are tools that you can use to test web applications directly., but not just from a s...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==The Presentation: &amp;quot;Cooking with OWASP: Recipes in Web Security Testing&amp;quot;==&lt;br /&gt;
&lt;br /&gt;
Many of the OWASP projects are tools that you can use to test web applications directly., but not just from a security assessor’s point of view. Software testers need to be able to work security testing into their day-to-day testing regimen. In this talk, Paco will show you a few recipes from his recently released “Web Security Testing Cookbook” that feature OWASP tools. You’ll see how to cheat at some Facebook games by decoding their data with CAL9000, how to assess session ID strength using WebScarab, and how to fuzz web services with wsFuzzer. This talk is all about how to get some actionable hands-on results from some outstanding OWASP tools.&lt;br /&gt;
&lt;br /&gt;
==The Speaker: Paco Hope==&lt;br /&gt;
Paco Hope  is a Technical Manager with Cigital, Inc. and has 12 years of experience in the security of web applications, operating systems, and embedded devices (lottery systems, cell phones, casino gaming devices, smart cards). As a consultant, his customers include MasterCard International, WMS Gaming, GTECH, FINRA (the US securities exchange regulator) and Sterling Commerce (an AT&amp;amp;T Company). He is a frequent speaker on security testing and web application security. His current passion is bringing the techniques of security assessment into the mainstream activities of QA departments and testers. He is co-author of two security books and is also a prior co-chair of VERIFY, an international conference on software testing.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[OWASP_Software_Assurance_Day_DC_2009#Agenda and Presentations:_13_March_2009|back to Presentation Agenda]]&lt;/div&gt;</summary>
		<author><name>Sbarnum</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Don%E2%80%99t_Write_Your_Own_Security_Code:_The_OWASP_Enterprise_Security_API&amp;diff=55423</id>
		<title>Don’t Write Your Own Security Code: The OWASP Enterprise Security API</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Don%E2%80%99t_Write_Your_Own_Security_Code:_The_OWASP_Enterprise_Security_API&amp;diff=55423"/>
				<updated>2009-02-25T06:17:44Z</updated>
		
		<summary type="html">&lt;p&gt;Sbarnum: New page: ==The Presentation: &amp;quot;Don’t Write Your Own Security Code: The OWASP Enterprise Security API&amp;quot;==  Application security is arguably the most difficult IT challenge facing organizations today...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==The Presentation: &amp;quot;Don’t Write Your Own Security Code: The OWASP Enterprise Security API&amp;quot;==&lt;br /&gt;
&lt;br /&gt;
Application security is arguably the most difficult IT challenge facing organizations today. Chasing the 700 types of common weaknesses with scanners and static analysis is a losing proposition. Rather than chasing after these vulnerabilities, developers can address almost all of these problems with a set of 10 to 12 strong centralized security controls. To make it easier for developers to establish these controls, the Open Web Application Security Project (OWASP) has created a clean, intuitive, and open-source toolbox of the core security building blocks that every web developer needs. In this talk, Jeff will show you how to create an ESAPI for your organization that will solve the OWASP Top Ten vulnerabilities, increase assurance, and dramatically cut costs all at the same time.&lt;br /&gt;
&lt;br /&gt;
==The Speaker: Jeff Williams==&lt;br /&gt;
Jeff Williams is the founder and CEO of Aspect Security, specializing exclusively in application security risk management services. Jeff also serves as the volunteer Chair of the Open Web Application Security Project (OWASP). Jeff has made extensive contributions to the application security community through OWASP, including writing the Top Ten, WebGoat, Secure Software Contract Annex, Enterprise Security API, OWASP Risk Rating Methodology, and starting the worldwide local chapters program. Jeff has spent 20 years in security, and for the last 10 has focused on securing enterprise Java applications. He also wasted four years and a ton of money on a law degree from Georgetown that he doesn’t use.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[OWASP_Software_Assurance_Day_DC_2009#Agenda and Presentations:_13_March_2009|back to Presentation Agenda]]&lt;/div&gt;</summary>
		<author><name>Sbarnum</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Software_Assurance_Day_DC_2009&amp;diff=55422</id>
		<title>OWASP Software Assurance Day DC 2009</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Software_Assurance_Day_DC_2009&amp;diff=55422"/>
				<updated>2009-02-25T06:15:36Z</updated>
		
		<summary type="html">&lt;p&gt;Sbarnum: created links to presentation details pages&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Welcome to the OWASP Software Assurance Day DC 2009. &lt;br /&gt;
&lt;br /&gt;
This single-day conference will be held on March 13th in conjunction with the Software Assurance Forum (March 10th-12th) sponsored by the US Department of Homeland Security, Department of Defense and National Institute of Standards and Technology. &lt;br /&gt;
&lt;br /&gt;
We are pleased to invite OWASP members, attendees of the Software Assurance Forum and any other interested parties to join us for this event. &lt;br /&gt;
&lt;br /&gt;
At this event, you will hear presentations from key leaders in the web application security domain on:&lt;br /&gt;
&lt;br /&gt;
* the state of the union for the Open Web Application Security Project&lt;br /&gt;
* the current status of several ongoing OWASP projects&lt;br /&gt;
* recently released knowledge resources to assist web application security programs in establishing a standard for minimum due care&lt;br /&gt;
* recipes for leveraging OWASP resources in security testing efforts&lt;br /&gt;
* the emerging importance of application security in the wireless domain&lt;br /&gt;
* a state-of-the-art approach to automating multi-perspective application security assessment&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You will also find out how you can leverage OWASP resources and participate in OWASP activities through local chapters in the DC/NOVA/Maryland area.&lt;br /&gt;
&lt;br /&gt;
The co-located Software Assurance Forum is also a free conference and open to any attendees of OWASP Software Assurance Day DC 2009, though it will require separate registration. &lt;br /&gt;
&lt;br /&gt;
For information on registration for the Software Assurance Forum, please contact [mailto:Jennifer.Brezovic@associates.dhs.gov Jennifer Brezovic].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
If you have any questions relating to the conference or just want to help out, please email the conference chair, [mailto:sbarnum@cigital.com Sean Barnum].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://guest.cvent.com/i.aspx?4W,M3,fd34d554-0341-493c-bfdc-94d42d3e3c6d https://www.owasp.org/images/9/9d/Register_now.gif]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Conference Location==&lt;br /&gt;
&lt;br /&gt;
The OWASP Software Assurance Day DC 2009 will be held in conjunction with the DHS/DOD/NIST Software Assurance Forum at [http://www.mitre.org/about/locations/mitre1_map.html '''MITRE Building 1''']''', 7525 Colshire Drive, McLean, VA 22102.''' &lt;br /&gt;
&lt;br /&gt;
Please use the Conference Center entrance.&lt;br /&gt;
&lt;br /&gt;
==Agenda and Presentations: 13 March 2009==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:80%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot; | March 13, 2009&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 08:15-08:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''OWASP Software Assurance Day DC kickoff''' &lt;br /&gt;
''Sean Barnum, Conference Chair''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 08:30-09:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''Intro to OWASP'''&lt;br /&gt;
''Tom Brennan''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 09:00-09:45 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[CWE/SANS Top 25: Towards Minimum Due Care in Software Security]]&lt;br /&gt;
''Steve Christey, Mitre''&lt;br /&gt;
  |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 09:50-10:35 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[Don’t Write Your Own Security Code: The OWASP Enterprise Security API']]&lt;br /&gt;
''Jeff Williams, Aspect Security''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 10:35-10:50 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | '''Morning Break'''&lt;br /&gt;
  |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 10:50-11:35 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[Cooking with OWASP: Recipes in Web Security Testing]]&lt;br /&gt;
''Paco Hope, Cigital''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 11:40-12:25 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[OWASP Application Security Verification Standard (ASVS)]]&lt;br /&gt;
''Dave Wichers, Aspect Security''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 12:25-13:40 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | '''Lunch – MITRE Cafeteria'''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 13:45-14:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[Maturing Software Assessment Through Static Analysis]]&lt;br /&gt;
''John Steven, Cigital''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 14:35-15:20 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[The Future of Mobile:  Developing Secure Mobile Applications]]&lt;br /&gt;
''Jason Rouse, Cigital''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 15:25-15:40 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | '''Afternoon Break'''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 15:40-16:25 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | [[OWASP Live CD:  An open environment for Web Application Security]]&lt;br /&gt;
''Matt Tesauro, Texas Education Agency''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 16:25-16:45 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''Conference Wrap Up and Opportunities to Contribute''' &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Logistics==&lt;br /&gt;
&lt;br /&gt;
Venue: [http://www.mitre.org/about/locations/mitre1_map.html '''MITRE Building 1''']''', 7525 Colshire Drive, McLean, VA 22102'''&lt;br /&gt;
&lt;br /&gt;
Please use the Conference Center entrance.&lt;br /&gt;
&lt;br /&gt;
==Accommodations==&lt;br /&gt;
&lt;br /&gt;
The conference has not negotiated any special rates for hotel accommodation but the following hotels are near the conference venue:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''McLean Hilton&lt;br /&gt;
7920 Jones Branch Drive&lt;br /&gt;
McLean, VA&lt;br /&gt;
Tel: 1-703-448-1234'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://www1.hilton.com/en_US/hi/hotel/MCLMHHH-Hilton-McLean-Tysons-Corner-Virginia/index.do http://www1.hilton.com/en_US/hi/hotel/MCLMHHH-Hilton-McLean-Tysons-Corner-Virginia/index.do]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Westin Hotel&lt;br /&gt;
7801 Leesburg Pike&lt;br /&gt;
Falls Church, VA&lt;br /&gt;
Tel: 1-703-893-1340'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://www.starwoodhotels.com/westin/property/overview/index.html?propertyID=1750 http://www.starwoodhotels.com/westin/property/overview/index.html?propertyID=1750]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Marriott&lt;br /&gt;
8028 Leesburg Pike&lt;br /&gt;
Vienna, VA&lt;br /&gt;
Tel: 1-703-734-3200'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://www.marriott.com/hotels/travel/wastc-tysons-corner-marriott/ http://www.marriott.com/hotels/travel/wastc-tysons-corner-marriott/]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Embassy Suites&lt;br /&gt;
8517 Leesburg Pike&lt;br /&gt;
Vienna, VA&lt;br /&gt;
Tel: 1-703-883-0707'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://embassysuites1.hilton.com/en_US/es/hotel/WASTSES-Embassy-Suites-Tysons-Corner-Virginia/index.do http://embassysuites1.hilton.com/en_US/es/hotel/WASTSES-Embassy-Suites-Tysons-Corner-Virginia/index.do]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''The Crowne Plaza Tysons Corner (formerly the Holiday Inn) &lt;br /&gt;
1960 Chain &lt;br /&gt;
Bridge Rd McLean, VA&lt;br /&gt;
Tel: 1-703-893-2100'''&lt;br /&gt;
&lt;br /&gt;
Website: [http://www.cptysonscorner.com/ http://www.cptysonscorner.com/]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Sheraton Premiere Tysons&lt;br /&gt;
8661 Leesburg Pike&lt;br /&gt;
Vienna, VA&lt;br /&gt;
Tel: 1-703-506-2500'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://www.starwoodhotels.com/sheraton/property/overview/index.html?propertyID=691 http://www.starwoodhotels.com/sheraton/property/overview/index.html?propertyID=691]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Transportation to the Conference==&lt;br /&gt;
===By plane===&lt;br /&gt;
The venue area can be reached by commercial aviation through either [http://www.metwashairports.com/Dulles/ Dulles International Airport] or [http://www.mwaa.com/national/ Reagan National Airport]. &lt;br /&gt;
&lt;br /&gt;
Both are roughly equidistant from the venue and offer a range of airline and flight options.&lt;br /&gt;
===How to get to the venue?===&lt;br /&gt;
See the [http://www.mitre.org/about/locations/mitre1_map.html map].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Registration and Conference Fees==&lt;br /&gt;
&lt;br /&gt;
OWASP Software Assurance Day DC 2009 will be a free conference.&lt;br /&gt;
&lt;br /&gt;
Despite the fact that this is a free conference, we still need you to register to fulfill security requirements of the facility and to ensure that we don't exceed venue capacity.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://guest.cvent.com/i.aspx?4W,M3,fd34d554-0341-493c-bfdc-94d42d3e3c6d https://www.owasp.org/images/9/9d/Register_now.gif]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Conference Contacts==&lt;br /&gt;
&lt;br /&gt;
For more information please contact the team below for conference details, sponsorship or registration. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Mr Sean Barnum (Conference Chair)''' , Cigital Federal, Inc.&lt;br /&gt;
&lt;br /&gt;
Email: [mailto:sbarnum@cigital.com sbarnum@cigital.com]&lt;br /&gt;
&lt;br /&gt;
Mobile: 703-473-8262 &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Kate Hartmann''' &lt;br /&gt;
&lt;br /&gt;
OWASP Operations Director &lt;br /&gt;
&lt;br /&gt;
9175 Guilford Road, Suite 300 &lt;br /&gt;
&lt;br /&gt;
Columbia, MD 21046, USA &lt;br /&gt;
&lt;br /&gt;
Phone: +1-301-575-0189 &lt;br /&gt;
&lt;br /&gt;
Facsimile: +1-301-604-8033 &lt;br /&gt;
&lt;br /&gt;
Email: [mailto:kate.hartmann@owasp.org kate.hartmann@owasp.org] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Conference Sponsors==&lt;br /&gt;
&lt;br /&gt;
Under negotiation.&lt;br /&gt;
&lt;br /&gt;
If you are interested in sponsoring this OWASP conference, please contact [mailto:sbarnum@cigital.com Sean Barnum].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 [[Category:OWASP AppSec Conference]]&lt;/div&gt;</summary>
		<author><name>Sbarnum</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=CWE/SANS_Top_25:_Towards_Minimum_Due_Care_in_Software_Security&amp;diff=55421</id>
		<title>CWE/SANS Top 25: Towards Minimum Due Care in Software Security</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=CWE/SANS_Top_25:_Towards_Minimum_Due_Care_in_Software_Security&amp;diff=55421"/>
				<updated>2009-02-25T06:13:25Z</updated>
		
		<summary type="html">&lt;p&gt;Sbarnum: Initial page creation&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==The Presentation: &amp;quot;CWE/SANS Top 25: Towards Minimum Due Care in Software Security&amp;quot;==&lt;br /&gt;
&lt;br /&gt;
The CWE/SANS Top 25 Most Dangerous Programming Errors list was released on January 12, 2009, and quickly achieved the rare accomplishment of actually getting noticed by people who don't do security full time.  But once January 13 rolled around, the overall response can be summarized in two words: &amp;quot;NOW what?&amp;quot;  What place does the Top 25 have in the grand scheme of software security, when there are already competing efforts like the OWASP Top Ten?  How was the Top 25 arrived at, and what should its role be in compliance, software acquisition, developer awareness, and - perhaps most importantly - starting the conversation about software security?  What are these &amp;quot;weakness&amp;quot; things anyway?  If the Top 25 is covered, how much assurance does that really provide, and does anything else get covered for free?  And finally: what next?  Mr Christey will answer and re-ask these questions in order to frame the Top 25 as an early step in a long journey towards software security.  Along the way, he will discuss the Top 25's role in the web world (and outside of it), highlight the two entries that tied for Number 26 and why they didn't make it, and how the Top 25 can concretely demonstrate how there still isn't a &amp;quot;Silver Bullet&amp;quot; for software security.&lt;br /&gt;
&lt;br /&gt;
==The Speaker: Steve Christey==&lt;br /&gt;
Steve Christey is a Principal Information Security Engineer in the Security and Information Operations Division at The MITRE Corporation.&lt;br /&gt;
Since 1999, he has been the Editor of the Common Vulnerabilities and Exposures (CVE) list and the Chair of the CVE Editorial Board.  He is the technical lead of the Common Weakness Enumeration (CWE) project.&lt;br /&gt;
He was the technical editor of the 2009 CWE/SANS Top 25 Most Dangerous Programming Errors list and an active contributor to other efforts including the SANS Secure Programming exams, NIST's Static Analysis Tool Exposition (SATE), and the Common Vulnerability Scoring System (CVSS).  His current interests include secure software development and testing, the theoretical underpinnings of vulnerabilities, making software security accessible to the general public, vulnerability information management including post-disclosure analysis, and vulnerability research.  Past work, which dates back to 1993, includes co-authoring the &amp;quot;Responsible Vulnerability Disclosure Process&amp;quot; draft with Chris Wysopal in 2002, reverse engineering of malicious code, automated vulnerability analysis of source code, and vulnerability scanning and incident response.  He holds a B.S. in Computer Science from Hobart College.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[OWASP_Software_Assurance_Day_DC_2009#Agenda and Presentations:_13_March_2009|back to Presentation Agenda]]&lt;/div&gt;</summary>
		<author><name>Sbarnum</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Software_Assurance_Day_DC_2009&amp;diff=55266</id>
		<title>OWASP Software Assurance Day DC 2009</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Software_Assurance_Day_DC_2009&amp;diff=55266"/>
				<updated>2009-02-23T06:02:26Z</updated>
		
		<summary type="html">&lt;p&gt;Sbarnum: minor tweaks to spacing&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Welcome to the OWASP Software Assurance Day DC 2009. &lt;br /&gt;
&lt;br /&gt;
This single-day conference will be held on March 13th in conjunction with the Software Assurance Forum (March 10th-12th) sponsored by the US Department of Homeland Security, Department of Defense and National Institute of Standards and Technology. &lt;br /&gt;
&lt;br /&gt;
We are pleased to invite OWASP members, attendees of the Software Assurance Forum and any other interested parties to join us for this event. &lt;br /&gt;
&lt;br /&gt;
At this event, you will hear presentations from key leaders in the web application security domain on:&lt;br /&gt;
&lt;br /&gt;
* the state of the union for the Open Web Application Security Project&lt;br /&gt;
* the current status of several ongoing OWASP projects&lt;br /&gt;
* recently released knowledge resources to assist web application security programs in establishing a standard for minimum due care&lt;br /&gt;
* recipes for leveraging OWASP resources in security testing efforts&lt;br /&gt;
* the emerging importance of application security in the wireless domain&lt;br /&gt;
* a state-of-the-art approach to automating multi-perspective application security assessment&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You will also find out how you can leverage OWASP resources and participate in OWASP activities through local chapters in the DC/NOVA/Maryland area.&lt;br /&gt;
&lt;br /&gt;
The co-located Software Assurance Forum is also a free conference and open to any attendees of OWASP Software Assurance Day DC 2009, though it will require separate registration. &lt;br /&gt;
&lt;br /&gt;
For information on registration for the Software Assurance Forum, please contact [mailto:Jennifer.Brezovic@associates.dhs.gov Jennifer Brezovic].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
If you have any questions relating to the conference or just want to help out, please email the conference chair, [mailto:sbarnum@cigital.com Sean Barnum].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Registration link should be up soon.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Conference Location==&lt;br /&gt;
&lt;br /&gt;
The OWASP Software Assurance Day DC 2009 will be held in conjunction with the DHS/DOD/NIST Software Assurance Forum at [http://www.mitre.org/about/locations/mitre1_map.html '''MITRE Building 1''']''', 7525 Colshire Drive, McLean, VA 22102.''' &lt;br /&gt;
&lt;br /&gt;
Please use the Conference Center entrance.&lt;br /&gt;
&lt;br /&gt;
==Agenda and Presentations: 13 March 2009==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:80%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot; | March 13, 2009&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 08:15-08:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''OWASP Software Assurance Day DC kickoff''' &lt;br /&gt;
''Sean Barnum, Conference Chair''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 08:30-09:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''Intro to OWASP'''&lt;br /&gt;
''Tom Brennan''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 09:00-09:45 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''CWE/SANS Top 25: Towards Minimum Due Care in Software Security'''&lt;br /&gt;
''Steve Christey, Mitre''&lt;br /&gt;
  |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 09:50-10:35 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''Don’t Write Your Own Security Code: The OWASP Enterprise Security API'''&lt;br /&gt;
''Jeff Williams, Aspect Security''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 10:35-10:50 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | '''Morning Break'''&lt;br /&gt;
  |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 10:50-11:35 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''Cooking with OWASP: Recipes in Web Security Testing'''&lt;br /&gt;
''Paco Hope, Cigital''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 11:40-12:25 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''OWASP Application Security Verification Standard (ASVS)'''&lt;br /&gt;
''Dave Wichers, Aspect Security''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 12:25-13:40 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | '''Lunch – MITRE Cafeteria'''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 13:45-14:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''Maturing Software Assessment Through Static Analysis'''&lt;br /&gt;
''John Steven, Cigital''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 14:35-15:20 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''The Future of Mobile:  Developing Secure Mobile Applications'''&lt;br /&gt;
''Jason Rouse, Cigital''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 15:25-15:40 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | '''Afternoon Break'''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 15:40-16:25 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''OWASP Live CD:  An open environment for Web Application Security'''&lt;br /&gt;
''Matt Tesauro, Texas Education Agency''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 16:25-16:45 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''Conference Wrap Up and Opportunities to Contribute''' &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Logistics==&lt;br /&gt;
&lt;br /&gt;
Venue: [http://www.mitre.org/about/locations/mitre1_map.html '''MITRE Building 1''']''', 7525 Colshire Drive, McLean, VA 22102'''&lt;br /&gt;
&lt;br /&gt;
Please use the Conference Center entrance.&lt;br /&gt;
&lt;br /&gt;
==Accommodations==&lt;br /&gt;
&lt;br /&gt;
The conference has not negotiated any special rates for hotel accommodation but the following hotels are near the conference venue:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''McLean Hilton&lt;br /&gt;
7920 Jones Branch Drive&lt;br /&gt;
McLean, VA&lt;br /&gt;
Tel: 1-703-448-1234'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://www1.hilton.com/en_US/hi/hotel/MCLMHHH-Hilton-McLean-Tysons-Corner-Virginia/index.do http://www1.hilton.com/en_US/hi/hotel/MCLMHHH-Hilton-McLean-Tysons-Corner-Virginia/index.do]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Westin Hotel&lt;br /&gt;
7801 Leesburg Pike&lt;br /&gt;
Falls Church, VA&lt;br /&gt;
Tel: 1-703-893-1340'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://www.starwoodhotels.com/westin/property/overview/index.html?propertyID=1750 http://www.starwoodhotels.com/westin/property/overview/index.html?propertyID=1750]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Marriott&lt;br /&gt;
8028 Leesburg Pike&lt;br /&gt;
Vienna, VA&lt;br /&gt;
Tel: 1-703-734-3200'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://www.marriott.com/hotels/travel/wastc-tysons-corner-marriott/ http://www.marriott.com/hotels/travel/wastc-tysons-corner-marriott/]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Embassy Suites&lt;br /&gt;
8517 Leesburg Pike&lt;br /&gt;
Vienna, VA&lt;br /&gt;
Tel: 1-703-883-0707'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://embassysuites1.hilton.com/en_US/es/hotel/WASTSES-Embassy-Suites-Tysons-Corner-Virginia/index.do http://embassysuites1.hilton.com/en_US/es/hotel/WASTSES-Embassy-Suites-Tysons-Corner-Virginia/index.do]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''The Crowne Plaza Tysons Corner (formerly the Holiday Inn) &lt;br /&gt;
1960 Chain &lt;br /&gt;
Bridge Rd McLean, VA&lt;br /&gt;
Tel: 1-703-893-2100'''&lt;br /&gt;
&lt;br /&gt;
Website: [http://www.cptysonscorner.com/ http://www.cptysonscorner.com/]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Sheraton Premiere Tysons&lt;br /&gt;
8661 Leesburg Pike&lt;br /&gt;
Vienna, VA&lt;br /&gt;
Tel: 1-703-506-2500'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://www.starwoodhotels.com/sheraton/property/overview/index.html?propertyID=691 http://www.starwoodhotels.com/sheraton/property/overview/index.html?propertyID=691]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Transportation to the Conference==&lt;br /&gt;
===By plane===&lt;br /&gt;
The venue area can be reached by commercial aviation through either [http://www.metwashairports.com/Dulles/ Dulles International Airport] or [http://www.mwaa.com/national/ Reagan National Airport]. &lt;br /&gt;
&lt;br /&gt;
Both are roughly equidistant from the venue and offer a range of airline and flight options.&lt;br /&gt;
===How to get to the venue?===&lt;br /&gt;
See the [http://www.mitre.org/about/locations/mitre1_map.html map].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Registration and Conference Fees==&lt;br /&gt;
&lt;br /&gt;
OWASP Software Assurance Day DC 2009 will be a free conference.&lt;br /&gt;
&lt;br /&gt;
Despite the fact that this is a free conference, we still need you to register to fulfill security requirements of the facility and to ensure that we don't exceed venue capacity.&lt;br /&gt;
&lt;br /&gt;
Registration links should be up soon.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Conference Contacts==&lt;br /&gt;
&lt;br /&gt;
For more information please contact the team below for conference details, sponsorship or registration. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Mr Sean Barnum (Conference Chair)''' , Cigital Federal, Inc.&lt;br /&gt;
&lt;br /&gt;
Email: [mailto:sbarnum@cigital.com sbarnum@cigital.com]&lt;br /&gt;
&lt;br /&gt;
Mobile: 703-473-8262 &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Kate Hartmann''' &lt;br /&gt;
&lt;br /&gt;
OWASP Operations Director &lt;br /&gt;
&lt;br /&gt;
9175 Guilford Road, Suite 300 &lt;br /&gt;
&lt;br /&gt;
Columbia, MD 21046, USA &lt;br /&gt;
&lt;br /&gt;
Phone: +1-301-575-0189 &lt;br /&gt;
&lt;br /&gt;
Facsimile: +1-301-604-8033 &lt;br /&gt;
&lt;br /&gt;
Email: [mailto:kate.hartmann@owasp.org kate.hartmann@owasp.org] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Conference Sponsors==&lt;br /&gt;
&lt;br /&gt;
Under negotiation.&lt;br /&gt;
&lt;br /&gt;
If you are interested in sponsoring this OWASP conference, please contact [mailto:sbarnum@cigital.com Sean Barnum].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 [[Category:OWASP AppSec Conference]]&lt;/div&gt;</summary>
		<author><name>Sbarnum</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Software_Assurance_Day_DC_2009&amp;diff=55265</id>
		<title>OWASP Software Assurance Day DC 2009</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Software_Assurance_Day_DC_2009&amp;diff=55265"/>
				<updated>2009-02-23T05:58:00Z</updated>
		
		<summary type="html">&lt;p&gt;Sbarnum: Fixed agenda&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Welcome to the OWASP Software Assurance Day DC 2009. &lt;br /&gt;
&lt;br /&gt;
This single-day conference will be held on March 13th in conjunction with the Software Assurance Forum (March 10th-12th) sponsored by the US Department of Homeland Security, Department of Defense and National Institute of Standards and Technology. &lt;br /&gt;
&lt;br /&gt;
We are pleased to invite OWASP members, attendees of the Software Assurance Forum and any other interested parties to join us for this event. &lt;br /&gt;
&lt;br /&gt;
At this event, you will hear presentations from key leaders in the web application security domain on:&lt;br /&gt;
&lt;br /&gt;
* the state of the union for the Open Web Application Security Project&lt;br /&gt;
* the current status of several ongoing OWASP projects&lt;br /&gt;
* recently released knowledge resources to assist web application security programs in establishing a standard for minimum due care&lt;br /&gt;
* recipes for leveraging OWASP resources in security testing efforts&lt;br /&gt;
* the emerging importance of application security in the wireless domain&lt;br /&gt;
* a state-of-the-art approach to automating multi-perspective application security assessment&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You will also find out how you can leverage OWASP resources and participate in OWASP activities through local chapters in the DC/NOVA/Maryland area.&lt;br /&gt;
&lt;br /&gt;
The co-located Software Assurance Forum is also a free conference and open to any attendees of OWASP Software Assurance Day DC 2009, though it will require separate registration. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
For information on registration for the Software Assurance Forum, please contact [mailto:Jennifer.Brezovic@associates.dhs.gov Jennifer Brezovic].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
If you have any questions relating to the conference or just want to help out, please email the conference chair, [mailto:sbarnum@cigital.com Sean Barnum].&lt;br /&gt;
&lt;br /&gt;
Registration link should be up soon.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Conference Location==&lt;br /&gt;
&lt;br /&gt;
The OWASP Software Assurance Day DC 2009 will be held in conjunction with the DHS/DOD/NIST Software Assurance Forum at [http://www.mitre.org/about/locations/mitre1_map.html '''MITRE Building 1''']''', 7525 Colshire Drive, McLean, VA 22102.''' &lt;br /&gt;
&lt;br /&gt;
Please use the Conference Center entrance.&lt;br /&gt;
&lt;br /&gt;
==Agenda and Presentations: 13 March 2009==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:80%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot; | March 13, 2009&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 08:15-08:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''OWASP Software Assurance Day DC kickoff''' &lt;br /&gt;
''Sean Barnum, Conference Chair''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 08:30-09:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''Intro to OWASP'''&lt;br /&gt;
''Tom Brennan''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 09:00-09:45 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''CWE/SANS Top 25: Towards Minimum Due Care in Software Security'''&lt;br /&gt;
''Steve Christey, Mitre''&lt;br /&gt;
  |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 09:50-10:35 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''Don’t Write Your Own Security Code: The OWASP Enterprise Security API'''&lt;br /&gt;
''Jeff Williams, Aspect Security''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 10:35-10:50 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | '''Morning Break'''&lt;br /&gt;
  |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 10:50-11:35 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''Cooking with OWASP: Recipes in Web Security Testing'''&lt;br /&gt;
''Paco Hope, Cigital''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 11:40-12:25 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''OWASP Application Security Verification Standard (ASVS)'''&lt;br /&gt;
''Dave Wichers, Aspect Security''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 12:25-13:40 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | '''Lunch – MITRE Cafeteria'''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 13:45-14:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''Maturing Software Assessment Through Static Analysis'''&lt;br /&gt;
''John Steven, Cigital''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 14:35-15:20 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''The Future of Mobile:  Developing Secure Mobile Applications'''&lt;br /&gt;
''Jason Rouse, Cigital''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 15:25-15:40 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | '''Afternoon Break'''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 15:40-16:25 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''OWASP Live CD:  An open environment for Web Application Security'''&lt;br /&gt;
''Matt Tesauro, Texas Education Agency''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 16:25-16:45 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''Conference Wrap Up and Opportunities to Contribute''' &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Logistics==&lt;br /&gt;
&lt;br /&gt;
Venue: [http://www.mitre.org/about/locations/mitre1_map.html '''MITRE Building 1''']''', 7525 Colshire Drive, McLean, VA 22102'''&lt;br /&gt;
&lt;br /&gt;
Please use the Conference Center entrance.&lt;br /&gt;
&lt;br /&gt;
==Accommodations==&lt;br /&gt;
&lt;br /&gt;
The conference has not negotiated any special rates for hotel accommodation but the following hotels are near the conference venue:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''McLean Hilton&lt;br /&gt;
7920 Jones Branch Drive&lt;br /&gt;
McLean, VA&lt;br /&gt;
Tel: 1-703-448-1234'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://www1.hilton.com/en_US/hi/hotel/MCLMHHH-Hilton-McLean-Tysons-Corner-Virginia/index.do http://www1.hilton.com/en_US/hi/hotel/MCLMHHH-Hilton-McLean-Tysons-Corner-Virginia/index.do]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Westin Hotel&lt;br /&gt;
7801 Leesburg Pike&lt;br /&gt;
Falls Church, VA&lt;br /&gt;
Tel: 1-703-893-1340'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://www.starwoodhotels.com/westin/property/overview/index.html?propertyID=1750 http://www.starwoodhotels.com/westin/property/overview/index.html?propertyID=1750]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Marriott&lt;br /&gt;
8028 Leesburg Pike&lt;br /&gt;
Vienna, VA&lt;br /&gt;
Tel: 1-703-734-3200'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://www.marriott.com/hotels/travel/wastc-tysons-corner-marriott/ http://www.marriott.com/hotels/travel/wastc-tysons-corner-marriott/]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Embassy Suites&lt;br /&gt;
8517 Leesburg Pike&lt;br /&gt;
Vienna, VA&lt;br /&gt;
Tel: 1-703-883-0707'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://embassysuites1.hilton.com/en_US/es/hotel/WASTSES-Embassy-Suites-Tysons-Corner-Virginia/index.do http://embassysuites1.hilton.com/en_US/es/hotel/WASTSES-Embassy-Suites-Tysons-Corner-Virginia/index.do]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''The Crowne Plaza Tysons Corner (formerly the Holiday Inn) &lt;br /&gt;
1960 Chain &lt;br /&gt;
Bridge Rd McLean, VA&lt;br /&gt;
Tel: 1-703-893-2100'''&lt;br /&gt;
&lt;br /&gt;
Website: [http://www.cptysonscorner.com/ http://www.cptysonscorner.com/]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Sheraton Premiere Tysons&lt;br /&gt;
8661 Leesburg Pike&lt;br /&gt;
Vienna, VA&lt;br /&gt;
Tel: 1-703-506-2500'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://www.starwoodhotels.com/sheraton/property/overview/index.html?propertyID=691 http://www.starwoodhotels.com/sheraton/property/overview/index.html?propertyID=691]&lt;br /&gt;
&lt;br /&gt;
==Transportation to the Conference==&lt;br /&gt;
===By plane===&lt;br /&gt;
The venue area can be reached by commercial aviation through either [http://www.metwashairports.com/Dulles/ Dulles International Airport] or [http://www.mwaa.com/national/ Reagan National Airport]. &lt;br /&gt;
&lt;br /&gt;
Both are roughly equidistant from the venue and offer a range of airline and flight options.&lt;br /&gt;
===How to get to the venue?===&lt;br /&gt;
See the [http://www.mitre.org/about/locations/mitre1_map.html map].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Registration and Conference Fees==&lt;br /&gt;
&lt;br /&gt;
OWASP Software Assurance Day DC 2009 will be a free conference.&lt;br /&gt;
&lt;br /&gt;
Despite the fact that this is a free conference, we still need you to register to fulfill security requirements of the facility and to ensure that we don't exceed venue capacity.&lt;br /&gt;
&lt;br /&gt;
Registration links should be up soon.&lt;br /&gt;
&lt;br /&gt;
==Conference Contacts==&lt;br /&gt;
&lt;br /&gt;
For more information please contact the team below for conference details, sponsorship or registration. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Mr Sean Barnum (Conference Chair) , Cigital Federal, Inc.&lt;br /&gt;
&lt;br /&gt;
Email: sbarnum@cigital.com&lt;br /&gt;
&lt;br /&gt;
Mobile: 703-473-8262 &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Kate Hartmann &lt;br /&gt;
&lt;br /&gt;
OWASP Operations Director &lt;br /&gt;
&lt;br /&gt;
9175 Guilford Road, Suite 300 &lt;br /&gt;
&lt;br /&gt;
Columbia, MD 21046, USA &lt;br /&gt;
&lt;br /&gt;
Phone: +1-301-575-0189 &lt;br /&gt;
&lt;br /&gt;
Facsimile: +1-301-604-8033 &lt;br /&gt;
&lt;br /&gt;
Email: kate.hartmann@owasp.org &lt;br /&gt;
&lt;br /&gt;
==Conference Sponsors==&lt;br /&gt;
&lt;br /&gt;
Under negotiation.&lt;br /&gt;
&lt;br /&gt;
If you are interested in sponsoring this OWASP conference, please contact [mailto:sbarnum@cigital.com Sean Barnum].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 [[Category:OWASP AppSec Conference]]&lt;/div&gt;</summary>
		<author><name>Sbarnum</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Software_Assurance_Day_DC_2009&amp;diff=55264</id>
		<title>OWASP Software Assurance Day DC 2009</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Software_Assurance_Day_DC_2009&amp;diff=55264"/>
				<updated>2009-02-23T05:50:49Z</updated>
		
		<summary type="html">&lt;p&gt;Sbarnum: Initial page creation&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Welcome to the OWASP Software Assurance Day DC 2009. &lt;br /&gt;
&lt;br /&gt;
This single-day conference will be held on March 13th in conjunction with the Software Assurance Forum (March 10th-12th) sponsored by the US Department of Homeland Security, Department of Defense and National Institute of Standards and Technology. &lt;br /&gt;
&lt;br /&gt;
We are pleased to invite OWASP members, attendees of the Software Assurance Forum and any other interested parties to join us for this event. &lt;br /&gt;
&lt;br /&gt;
At this event, you will hear presentations from key leaders in the web application security domain on:&lt;br /&gt;
&lt;br /&gt;
* the state of the union for the Open Web Application Security Project&lt;br /&gt;
* the current status of several ongoing OWASP projects&lt;br /&gt;
* recently released knowledge resources to assist web application security programs in establishing a standard for minimum due care&lt;br /&gt;
* recipes for leveraging OWASP resources in security testing efforts&lt;br /&gt;
* the emerging importance of application security in the wireless domain&lt;br /&gt;
* a state-of-the-art approach to automating multi-perspective application security assessment&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You will also find out how you can leverage OWASP resources and participate in OWASP activities through local chapters in the DC/NOVA/Maryland area.&lt;br /&gt;
&lt;br /&gt;
The co-located Software Assurance Forum is also a free conference and open to any attendees of OWASP Software Assurance Day DC 2009, though it will require separate registration. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
For information on registration for the Software Assurance Forum, please contact [mailto:Jennifer.Brezovic@associates.dhs.gov Jennifer Brezovic].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
If you have any questions relating to the conference or just want to help out, please email the conference chair, [mailto:sbarnum@cigital.com Sean Barnum].&lt;br /&gt;
&lt;br /&gt;
Registration link should be up soon.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Conference Location==&lt;br /&gt;
&lt;br /&gt;
The OWASP Software Assurance Day DC 2009 will be held in conjunction with the DHS/DOD/NIST Software Assurance Forum at [http://www.mitre.org/about/locations/mitre1_map.html '''MITRE Building 1''']''', 7525 Colshire Drive, McLean, VA 22102.''' &lt;br /&gt;
&lt;br /&gt;
Please use the Conference Center entrance.&lt;br /&gt;
&lt;br /&gt;
==Agenda and Presentations: 13 March 2009==&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:80%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot; | March 13, 2009&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 08:15-08:3 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''OWASP Software Assurance Day DC kickoff''' &lt;br /&gt;
''Sean Barnum, Conference Chair''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 08:30-09:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''Intro to OWASP'''&lt;br /&gt;
''Tom Brennan''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 09:00-09:45 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''CWE/SANS Top 25: Towards Minimum Due Care in Software Security'''&lt;br /&gt;
''Steve Christey, Mitre''&lt;br /&gt;
  |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 09:50-10:35 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | '''Don’t Write Your Own Security Code: The OWASP Enterprise Security API'''&lt;br /&gt;
''Jeff Williams, Aspect Security''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 10:15-10:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | ‘’’Break’’’&lt;br /&gt;
  |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 09:45-10:15 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | OWASP State of the Union&lt;br /&gt;
''Tom Brennan, OWASP Board''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 09:45-10:15 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | OWASP State of the Union&lt;br /&gt;
''Tom Brennan, OWASP Board''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 12:00-13:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | ‘’’Lunch – MITRE Cafeteria’’’&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 09:45-10:15 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | OWASP State of the Union&lt;br /&gt;
''Tom Brennan, OWASP Board''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 09:45-10:15 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | OWASP State of the Union&lt;br /&gt;
''Tom Brennan, OWASP Board''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 14:50-15:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | ‘’’Break’’’&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 09:45-10:15 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | OWASP State of the Union&lt;br /&gt;
''Tom Brennan, OWASP Board''&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 16:30-17:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | Conference Wrap Up and Opportunities to Contribute &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Logistics==&lt;br /&gt;
&lt;br /&gt;
Venue: [http://www.mitre.org/about/locations/mitre1_map.html '''MITRE Building 1''']''', 7525 Colshire Drive, McLean, VA 22102'''&lt;br /&gt;
&lt;br /&gt;
Please use the Conference Center entrance.&lt;br /&gt;
&lt;br /&gt;
==Accommodations==&lt;br /&gt;
&lt;br /&gt;
The conference has not negotiated any special rates for hotel accommodation but the following hotels are near the conference venue:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''McLean Hilton&lt;br /&gt;
7920 Jones Branch Drive&lt;br /&gt;
McLean, VA&lt;br /&gt;
Tel: 1-703-448-1234'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://www1.hilton.com/en_US/hi/hotel/MCLMHHH-Hilton-McLean-Tysons-Corner-Virginia/index.do http://www1.hilton.com/en_US/hi/hotel/MCLMHHH-Hilton-McLean-Tysons-Corner-Virginia/index.do]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Westin Hotel&lt;br /&gt;
7801 Leesburg Pike&lt;br /&gt;
Falls Church, VA&lt;br /&gt;
Tel: 1-703-893-1340'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://www.starwoodhotels.com/westin/property/overview/index.html?propertyID=1750 http://www.starwoodhotels.com/westin/property/overview/index.html?propertyID=1750]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Marriott&lt;br /&gt;
8028 Leesburg Pike&lt;br /&gt;
Vienna, VA&lt;br /&gt;
Tel: 1-703-734-3200'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://www.marriott.com/hotels/travel/wastc-tysons-corner-marriott/ http://www.marriott.com/hotels/travel/wastc-tysons-corner-marriott/]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Embassy Suites&lt;br /&gt;
8517 Leesburg Pike&lt;br /&gt;
Vienna, VA&lt;br /&gt;
Tel: 1-703-883-0707'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://embassysuites1.hilton.com/en_US/es/hotel/WASTSES-Embassy-Suites-Tysons-Corner-Virginia/index.do http://embassysuites1.hilton.com/en_US/es/hotel/WASTSES-Embassy-Suites-Tysons-Corner-Virginia/index.do]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''The Crowne Plaza Tysons Corner (formerly the Holiday Inn) &lt;br /&gt;
1960 Chain &lt;br /&gt;
Bridge Rd McLean, VA&lt;br /&gt;
Tel: 1-703-893-2100'''&lt;br /&gt;
&lt;br /&gt;
Website: [http://www.cptysonscorner.com/ http://www.cptysonscorner.com/]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Sheraton Premiere Tysons&lt;br /&gt;
8661 Leesburg Pike&lt;br /&gt;
Vienna, VA&lt;br /&gt;
Tel: 1-703-506-2500'''&lt;br /&gt;
&lt;br /&gt;
Website: &lt;br /&gt;
[http://www.starwoodhotels.com/sheraton/property/overview/index.html?propertyID=691 http://www.starwoodhotels.com/sheraton/property/overview/index.html?propertyID=691]&lt;br /&gt;
&lt;br /&gt;
==Transportation to the Conference==&lt;br /&gt;
===By plane===&lt;br /&gt;
The venue area can be reached by commercial aviation through either [http://www.metwashairports.com/Dulles/ Dulles International Airport] or [http://www.mwaa.com/national/ Reagan National Airport]. &lt;br /&gt;
&lt;br /&gt;
Both are roughly equidistant from the venue and offer a range of airline and flight options.&lt;br /&gt;
===How to get to the venue?===&lt;br /&gt;
See the [http://www.mitre.org/about/locations/mitre1_map.html map].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Registration and Conference Fees==&lt;br /&gt;
&lt;br /&gt;
OWASP Software Assurance Day DC 2009 will be a free conference.&lt;br /&gt;
&lt;br /&gt;
Despite the fact that this is a free conference, we still need you to register to fulfill security requirements of the facility and to ensure that we don't exceed venue capacity.&lt;br /&gt;
&lt;br /&gt;
Registration links should be up soon.&lt;br /&gt;
&lt;br /&gt;
==Conference Contacts==&lt;br /&gt;
&lt;br /&gt;
For more information please contact the team below for conference details, sponsorship or registration. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Mr Sean Barnum (Conference Chair) , Cigital Federal, Inc.&lt;br /&gt;
&lt;br /&gt;
Email: sbarnum@cigital.com&lt;br /&gt;
&lt;br /&gt;
Mobile: 703-473-8262 &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Kate Hartmann &lt;br /&gt;
&lt;br /&gt;
OWASP Operations Director &lt;br /&gt;
&lt;br /&gt;
9175 Guilford Road, Suite 300 &lt;br /&gt;
&lt;br /&gt;
Columbia, MD 21046, USA &lt;br /&gt;
&lt;br /&gt;
Phone: +1-301-575-0189 &lt;br /&gt;
&lt;br /&gt;
Facsimile: +1-301-604-8033 &lt;br /&gt;
&lt;br /&gt;
Email: kate.hartmann@owasp.org &lt;br /&gt;
&lt;br /&gt;
==Conference Sponsors==&lt;br /&gt;
&lt;br /&gt;
Under negotiation.&lt;br /&gt;
&lt;br /&gt;
If you are interested in sponsoring this OWASP conference, please contact [mailto:sbarnum@cigital.com Sean Barnum].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 [[Category:OWASP AppSec Conference]]&lt;/div&gt;</summary>
		<author><name>Sbarnum</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_AppSec_Conference&amp;diff=55236</id>
		<title>Category:OWASP AppSec Conference</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_AppSec_Conference&amp;diff=55236"/>
				<updated>2009-02-22T05:21:41Z</updated>
		
		<summary type="html">&lt;p&gt;Sbarnum: Added OWASP Software Assurance Day DC 2009&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
The OWASP AppSec conference series is dedicated to bringing together industry, government, and security researchers and practitioners to discuss the state of the art in application security. This series was launched in the U.S. in the Fall of 2004 and in Europe in the Spring of 2005 and this has rapidly grown into a world wide phenomenon which now includes the U.S., Europe, Asia, Australia, and Israel. All of the presentations from our previous conferences can be downloaded from the agenda pages for each conference.&lt;br /&gt;
&lt;br /&gt;
Chapter leaders wanting to host a conference click [[How_to_Host_a_Conference|here]] and when your ready, please contact [https://www.owasp.org/index.php/Global_Conferences_Committee Global Conferences Committee] to make it happen.&lt;br /&gt;
&lt;br /&gt;
Checkout OWASP's conferences for the past two years on [http://maps.google.com/maps/ms?hl=en&amp;amp;gl=us&amp;amp;ie=UTF8&amp;amp;oe=UTF8&amp;amp;msa=0&amp;amp;msid=102471112605576686928.00046255c51af35309c77 Google Maps].&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP AppSec Conference]]&lt;br /&gt;
&lt;br /&gt;
==2009 Conferences Schedule==&lt;br /&gt;
; February 2009 - [[Italy_OWASP_Day_3 |Day 3 Italy]]&lt;br /&gt;
: Feb 23rd - OWASP Day III: &amp;quot;Web Application Security: research meets industry&amp;quot; - Bari (Italy) &lt;br /&gt;
&lt;br /&gt;
; February 2009 - [[OWASP_AU_Conference_2009|OWASP AppSec Australia 2009]] - Gold Coast&lt;br /&gt;
: Feb 25th-27th - Training &amp;amp; Conference, Gold Coast Convention Center, QLD Australia&lt;br /&gt;
&lt;br /&gt;
; March 2009 - [[Front_Range_OWASP_Conference_2009|Front Range OWASP Conference 2009 (aka SNOWFroc)]]&lt;br /&gt;
: March 5th, 2nd Annual 1-Day Conference in Denver, Colorado&lt;br /&gt;
&lt;br /&gt;
; March 2009 - [[OWASP_Software_Assurance_Day_DC_2009|OWASP Software Assurance Day DC 2009 (in conjunction with the DHS/DOD/NIST Software Assurance Forum)]]&lt;br /&gt;
: March 13th, 1-Day Conference in McLean, Virginia&lt;br /&gt;
&lt;br /&gt;
; May 2009 - [[OWASP_AppSec_Europe_2009_-_Poland |OWASP AppSec Europe 2009]] - Poland&lt;br /&gt;
: May 11th-14th - Conference and Training, Qubus Hotel, Krakow, Poland ([[OWASP AppSec Europe 2009 CFP |Call for Presentations is out!]])&lt;br /&gt;
&lt;br /&gt;
; September 2009 - [[OWASP_Ireland_AppSec_2009_Conference |OWASP AppSec Ireland 2009]]&lt;br /&gt;
: September 10th - 1-Day Conference at Trinity College in Dublin&lt;br /&gt;
&lt;br /&gt;
; November 2009 - [[OWASP_AppSec_US_2009_-_Washington_DC |OWASP AppSec US 2009]] - Washington, D.C.&lt;br /&gt;
&lt;br /&gt;
; May/June 2010 - [[OWASP_AppSec_Europe_2010_-_Sweden |OWASP AppSec Europe 2010]] - Stockholm, Sweden&lt;br /&gt;
&lt;br /&gt;
==Completed Conferences==&lt;br /&gt;
&lt;br /&gt;
=== 2008 ===&lt;br /&gt;
; November 2008 - [[OWASP_Germany_2008_Conference | OWASP Germany Conference]]&lt;br /&gt;
: November 25th - 1-Day Conference in Frankfurt, Germany&lt;br /&gt;
&lt;br /&gt;
; November 2008 - [[OWASP_EU_Summit_2008 | OWASP Summit 2008 - Portugal]]&lt;br /&gt;
: November 3rd - 7th - Working Sessions, Conference &amp;amp; Training, Algarve, Portugal&lt;br /&gt;
&lt;br /&gt;
; October 2008 - [[OWASP AppSec Asia 2008 - Taiwan]]&lt;br /&gt;
: October 27th - 28th - NTUH International Convention Centre, Taipei, Taiwan&lt;br /&gt;
&lt;br /&gt;
; October 2008 - [[OWASP_Minneapolis_St_Paul_2008_Conference | OWASP Minnesota Conference]]&lt;br /&gt;
: October 21st - University of Minnesota's St. Paul Student Center&lt;br /&gt;
&lt;br /&gt;
; September 2008 - [[OWASP_NYC_AppSec_2008_Conference | OWASP AppSec U.S. 2008 - New York City]]&lt;br /&gt;
: September 22nd - 25th - Conference &amp;amp; Training, Park Central Hotel, NYC&lt;br /&gt;
&lt;br /&gt;
; September 2008 - [[OWASP_Israel_2008_Conference | OWASP Israel 2008 - Herzliya, Israel]]&lt;br /&gt;
: September 14th - The Interdisciplinary Center Herzliya, Israel&lt;br /&gt;
&lt;br /&gt;
; August 2008 - [[OWASP_AppSec_India_Conference_2008 | OWASP AppSec India 2008 - Delhi, India]]&lt;br /&gt;
: August 20th - 21st - Conference &amp;amp; Training&lt;br /&gt;
&lt;br /&gt;
; June 10th 2008 - [[Front_Range_Web_Application_Security_Summit_Planning_Page | Front Range Web Application Security Conference]] - Denver, CO&lt;br /&gt;
&lt;br /&gt;
; May 2008 - [[OWASP_AppSec_Europe_2008_-_Belgium | OWASP AppSec Europe 2008 - Ghent, Belgium]]&lt;br /&gt;
: May 19th - 22nd - Conference &amp;amp; Training, Ghent University, Belgium (view [[OWASP_AppSec_Europe_2008_-_Belgium#Agenda_and_Presentations_-_May_21-22|agenda and presentations]])&lt;br /&gt;
&lt;br /&gt;
; February 2008 - [[OWASP_Australia_AppSec_2008_Conference | OWASP Australia AppSec 2008 Conference]] &lt;br /&gt;
: February 27th-29th - Training &amp;amp; Conference, Gold Coast Convention Center, QLD Australia&lt;br /&gt;
&lt;br /&gt;
=== 2007 ===&lt;br /&gt;
; December 2007 - [[OWASP_Israel_2007_Conference | OWASP Israel AppSec 2007 Conference]]&lt;br /&gt;
: December 3rd, 2007 - Interdisciplinary Center (IDC) Herzliya, Israel&lt;br /&gt;
&lt;br /&gt;
; November 2007 - [[OWASP &amp;amp; WASC AppSec 2007 Conference | OWASP &amp;amp; WASC AppSec U.S. 2007 - San Jose, California]]&lt;br /&gt;
: November 12-15 - at eBay in San Jose, CA. (view [[7th_OWASP_AppSec_Conference_-_San_Jose_2007/Agenda#OWASP_.26_WASC_AppSec_2007_Conference_Schedule_-_Nov_14-15_.28San_Jose_2007.29|agenda and presentations]])&lt;br /&gt;
&lt;br /&gt;
; September 2007 - [[OWASP_AppSec_Asia_2007 | OWASP AppSec Asia 2007 - Taiwan]]&lt;br /&gt;
: September 27 - in Taipei, Taiwan. &lt;br /&gt;
&lt;br /&gt;
; May 2007 - [[OWASP_AppSec_Europe_2007_-_Italy | OWASP AppSec Europe 2007 - Italy]]&lt;br /&gt;
: May 15th-17th - in Milan, Italy. (view [[OWASP_AppSec_Europe_2007_-_Italy/Agenda|agenda and presentations]])&lt;br /&gt;
&lt;br /&gt;
=== 2004-2006 ===&lt;br /&gt;
&lt;br /&gt;
; October 2006 - [[OWASP AppSec Seattle 2006| OWASP AppSec U.S. 2006 - Seattle, Washington]]&lt;br /&gt;
: October 16th-18th - in Seattle, Washington. (view [[OWASP_AppSec_Seattle_2006/Agenda|agenda and presentations]]) &lt;br /&gt;
&lt;br /&gt;
; May 2006 - [[OWASP AppSec Europe 2006| OWASP AppSec Europe 2006 - Belgium ]]&lt;br /&gt;
: Held in Leuven, Belgium (view [[AppSec Europe 2006/Agenda|agenda and presentations]])&lt;br /&gt;
&lt;br /&gt;
; October 2005 - [[OWASP AppSec Washington 2005|OWASP AppSec U.S. 2005 - Washington D.C.]]&lt;br /&gt;
: Held at NIST in Gaithersburg, MD (view [[AppSec Washington 2005/Agenda|agenda and presentations]])&lt;br /&gt;
&lt;br /&gt;
; April 2005 - [[OWASP AppSec Europe 2005|OWASP AppSec Europe 2005 - London]]&lt;br /&gt;
: Held at Royal Holloway University in London (view [[AppSec Europe 2005/Agenda|agenda and presentations]])&lt;br /&gt;
&lt;br /&gt;
; November 2004 - [[OWASP AppSec NYC 2004|OWASP AppSec U.S. 2004 - New York City]]&lt;br /&gt;
: Held at Stevens Institute in New Jersey (view [[AppSec NYC 2004|agenda and presentations]])&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
More [http://www.owasp.org/index.php/Category:OWASP_AppSec_Conference-archive Conference Archives - Click Here]&amp;lt;/center&amp;gt;&lt;/div&gt;</summary>
		<author><name>Sbarnum</name></author>	</entry>

	</feed>