This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "Summit 2011 Working Sessions/Session094"
From OWASP
Sandra Paiva (talk | contribs) |
|||
(9 intermediate revisions by 6 users not shown) | |||
Line 2: | Line 2: | ||
|- | |- | ||
− | | summit_session_attendee_name1 = | + | | summit_session_attendee_name1 = Tony UcedaVelez |
− | | summit_session_attendee_email1 = | + | | summit_session_attendee_email1 = [email protected] |
− | | summit_session_attendee_username1 = | + | | summit_session_attendee_username1 = Tony UcedaVelez |
− | | summit_session_attendee_company1= | + | | summit_session_attendee_company1= VerSprite |
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed1= | | summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed1= | ||
− | | summit_session_attendee_name2 = | + | | summit_session_attendee_name2 = John Menerick |
− | | summit_session_attendee_email2 = | + | | summit_session_attendee_email2 = [email protected] |
− | | summit_session_attendee_username2 = | + | | summit_session_attendee_username2 = John Menerick |
− | | summit_session_attendee_company2= | + | | summit_session_attendee_company2= NetSuite |
− | | summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed2= | + | | summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed2= (remote) |
− | | summit_session_attendee_name3 = | + | | summit_session_attendee_name3 = Daniel Brzozowski |
− | | summit_session_attendee_email3 = | + | | summit_session_attendee_email3 = [email protected] |
− | | summit_session_attendee_username3 = | + | | summit_session_attendee_username3 = Daniel Brzozowski |
| summit_session_attendee_company3= | | summit_session_attendee_company3= | ||
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed3= | | summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed3= | ||
− | | summit_session_attendee_name4 = | + | | summit_session_attendee_name4 = Alexandre Miguel Aniceto |
− | | summit_session_attendee_email4 = | + | | summit_session_attendee_email4 = [email protected] |
− | | summit_session_attendee_username4 = | + | | summit_session_attendee_username4 = Alexandre Miguel Aniceto |
− | | summit_session_attendee_company4= | + | | summit_session_attendee_company4= Willway |
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed4= | | summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed4= | ||
Line 130: | Line 130: | ||
|- | |- | ||
− | | short_working_session_description= | + | | short_working_session_description=This OWASP Working Session will explore the Simplified SDL and its 16 security practices implementation guidance (see reference materials below). The Simplified SDL is a platform-agnostic process for implementing proven application security practices in any size organization. |
+ | This working group will discuss the feasibility of creating one or more practical, platform-specific resource libraries for each of the security practices in the 16 steps of the Simplified SDL. Further, we will discuss prioritization of the 16 Practices for organizations implementing security in an incremental fashion. | ||
|- | |- | ||
Line 151: | Line 152: | ||
|- | |- | ||
− | | summit_session_objective_name1= | + | | summit_session_objective_name1= Discuss additional reference materials and identifying publicly-available tools targeting a variety of platforms (web, OSX, Unix, mobile platforms, etc) in an effort to provide practical, platform-specific implementation guidance for each of the security practices in the 16 Steps of the Simplified SDL. |
− | | summit_session_objective_name2 = | + | | summit_session_objective_name2 = Define the practical “crawl/walk/run” steps for adopting the 16 Practices of the Simplified SDL for development organizations of any size. |
| summit_session_objective_name3 = | | summit_session_objective_name3 = | ||
Line 176: | Line 177: | ||
| working_session_additional_details = | | working_session_additional_details = | ||
+ | Reference materials: [http://go.microsoft.com/?linkid=9708425 Simplified SDL paper] & [http://blogs.msdn.com/b/sdl/archive/2011/01/26/only-16-security-practices-implementation-guidance-included.aspx 16 Steps blog post]. | ||
|- | |- | ||
− | |summit_session_deliverable_name1 = | + | |summit_session_deliverable_name1 = Identify 1-2 target platforms and potential locations for a library of platform-specific guidance and tools associated with each of the 16 practices of the Simplified SDL. |
− | |summit_session_deliverable_name2 = | + | |summit_session_deliverable_name2 = Identify OWASP contributors who are willing to help build the content for #1. |
− | |summit_session_deliverable_name3 = | + | |summit_session_deliverable_name3 = Define the practical “crawl/walk/run” steps for adopting the 16 Practices of the Simplified SDL for development organizations of any size. |
|summit_session_deliverable_name4 = | |summit_session_deliverable_name4 = |
Latest revision as of 04:31, 9 February 2011
Global Summit 2011 Home Page
Global Summit 2011 Tracks
Microsoft's SDL in 16 steps (and lessons learned) | ||||||
---|---|---|---|---|---|---|
Please see/use the 'discussion' page for more details about this Working Session | ||||||
Working Sessions Operational Rules - Please see here the general frame of rules. |
WORKING SESSION IDENTIFICATION | ||||||
---|---|---|---|---|---|---|
Short Work Session Description | This OWASP Working Session will explore the Simplified SDL and its 16 security practices implementation guidance (see reference materials below). The Simplified SDL is a platform-agnostic process for implementing proven application security practices in any size organization.
This working group will discuss the feasibility of creating one or more practical, platform-specific resource libraries for each of the security practices in the 16 steps of the Simplified SDL. Further, we will discuss prioritization of the 16 Practices for organizations implementing security in an incremental fashion. | |||||
Related Projects (if any) |
| |||||
Email Contacts & Roles | Chair Jeremy Dallman @ |
Operational Manager |
Mailing list Subscription Page |
WORKING SESSION SPECIFICS | ||||||
---|---|---|---|---|---|---|
Objectives |
| |||||
Venue/Date&Time/Model | Venue/Room OWASP Global Summit Portugal 2011 |
Date & Time
|
Discussion Model participants and attendees |
|
---|
WORKING SESSION OPERATIONAL RESOURCES | ||||||
---|---|---|---|---|---|---|
Projector, whiteboards, markers, Internet connectivity, power |
|
---|
WORKING SESSION ADDITIONAL DETAILS | ||||||
---|---|---|---|---|---|---|
Reference materials: Simplified SDL paper & 16 Steps blog post. |
WORKING SESSION OUTCOMES / DELIVERABLES | ||
---|---|---|
Proposed by Working Group | Approved by OWASP Board | |
After the Board Meeting - fill in here. | ||
Identify OWASP contributors who are willing to help build the content for #1. |
After the Board Meeting - fill in here. | |
After the Board Meeting - fill in here. | ||
After the Board Meeting - fill in here. | ||
After the Board Meeting - fill in here. | ||
After the Board Meeting - fill in here. | ||
After the Board Meeting - fill in here. | ||
After the Board Meeting - fill in here. |
Working Session Participants
(Add you name by clicking "edit" on the tab on the upper left side of this page)
WORKING SESSION PARTICIPANTS | ||||||
---|---|---|---|---|---|---|
Name | Company | Notes & reason for participating, issues to be discussed/addressed | ||||
Tony UcedaVelez @ |
VerSprite |
| ||||
John Menerick @ |
NetSuite |
(remote) | ||||
Daniel Brzozowski @ |
| |||||
Alexandre Miguel Aniceto @ |
Willway |
| ||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
| |||||
|
|