This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "Summit 2011"

From OWASP
Jump to: navigation, search
Line 407: Line 407:
  
 
<headertabs />
 
<headertabs />
 +
 +
[[Category:Summit_2011]]

Revision as of 16:30, 2 December 2010


Welcome

OWASPGlobalSummitLogo-3THISONEHASTHEMOSTVOTESSOFAR.jpg

Dear OWASP Leaders and appsec community,


The Summit will be held February 8th-11th at CampoReal Resort in central Oeste Portugal, 38 km north of Lisbon and 18 km inland from the Atlantic Ocean. This will be the place where appsec experts meet, discuss, work, socialize, and set the roadmap for OWASP in coming years.

The Summit Activates *You*

Whereas the OWASP AppSec conferences are great places to listen to interesting talks, go for training, and meet with OWASP people, the Global Summit is the place where we all sit down together and take the time to discuss and work out plans, projects and solutions for the appsec future.

Examples of topics:

  • How should we support the OWASP projects?
  • How can we work with browser vendors to enhance security (see "Browser Day" tab above)?
  • How should the community reach out to developers and education institutions?
  • How often should we publish the OWASP Top 10?
  • How can OWASP support your chapter?

Organizing Committee

Lorna Alamri, Brad Causey, Justin Clarke, Paulo Coimbra, Dinis Cruz, Martin Knobloch, Dave Wichers, John Wilander, Jason Li, Tara Causey, Sarah Baso .

Who's Invited?

As an OWASP leader you are automatically invited to the summit, but we also welcome leading experts from industry and academia. Together we can create a more secure web. Check the "How Do I Join?" tab above for more info.


Operational guidelines

Following the first meeting of the Summit 2011 Organizational team, here are the current proposed operational guidelines:

  1. the summit is an annual event
  2. outside OWASP conference
  3. the summit should take place in January not later then begin of February
  4. the summit takes 3 to 4 days
  5. budget aim is US$ 150'000 US$ where 50'000 from OWASP and US$100'000 from sponsors
  6. attendees targets are:
    1. OWASP Funded:
      1. Board
      2. Committee Members
    2. Chapter / sponsor Funded:
      1. Chapter Leaders
    3. Project Leaders
  7. venue / location criteria (no decision on the venue)
    1. 1 key organizer in close contact with the venue
    2. hosting 30 to 100 people
    3. US$2'000 a head (flight/accommodation/food/beers)
    4. conference facilities
      1. multiple meeting rooms
      2. one big meeting room e.g. auditorium
      3. hotel with the conference facilities or conference venue within walking distance
      4. apartments if possible (to share apartments/rooms and save money)
      5. 4 to 5 star hotel
      6. local food supplier for apartment crashing
      7. has to be negotiated with the hotel
      8. max 50 km's form international airport
      9. sufficient Internet access!

Success factors (what indicates the summit as success)

  1. break even
  2. the summits are the place to go to discus about and working on Web Application Security
  3. review of the past year
  4. working sessions on committees, projects and industry sectors (e.g. browsers and frameworks)
    1. universities / education sessions
    2. committee member election
    3. board election
    4. strategic OWASP issues
    5. road map and action plans for the next 12 month

Other local Summit(s):

  • The conferences are free to organize small, conference bound summit
  • this are not sponsored by OWASP of OWASP summit budget


XSS Eradication

We will have a half day working session on Cross Site Scripting - specifically how OWASP can make 2011 the year of XSS... going away. How we help bring this about through contributing our knowledge to cornerstone projects, how we can raise the awareness through advocacy, and what we can do to ensure that OWASP and other freely available resources and made available to the wider community, and that they are aware of them.

Enterprise Web Defense Roundtable

How are enterprises defending web applications. Discussion of best practices, effective methods, and new ideas to enhance web application defense. (Session Leader: Michael Coates, Mozilla)

University Outreach

This summit will be the place to bring OWASP Educational Supporters together! What security major and minor educations are out there? How can OWASP participate and influence their curricula? How can the relationship between Universities and OWASP be standardized? What does OWASP have to offer Universities and what can they, in turn, expect from each other?

OWASP Projects

We will have a session on how OWASP should support, grow, and manage projects. This includes:
-Assessment criteria
-Orphaned projects
-Funding
-Marketing
-Commercial services



OWASP Around the World

OWASP is a fast growing global community. How should we support and manage this growth? During this session we'll look into issues of:

More Topics

You know how OWASP works – it's all up to you. Please edit this tab and enter topics we should cover during the Global Summit 2011! If you want you can add your name after each suggestion and we can work out the details with you.

  • Discussion on Douglas Crockford's bold statement that we should stop HTML5 development, fix XSS, and then start over. Is he right? How is OWASP active in the HTML5 development? Check this webcast, jump to 20:50 to hear the XSS part. /John Wilander
  • [Your topic here]

How Do I Join? / Mailing list

As an OWASP leader you are automatically invited to the summit. Cost to attend the summit is $800 USD (shared accommodations) plus travel expenses. Please see "Applying for Chapter and Project Funding" and "Letters and Summit Materials" tabs for more information on finding funding help for expenses.

The first thing to do is to join the Summit 2011 mailing list.

On the mailing list you'll get first hand information on how to register, exact dates, updates to the agenda, funding for your trip etc.

If you are a leading appsec expert from industry or academia but not yet an OWASP leader you can just contact John.Wilander at owasp.org and we'll try to get you in.

Social Events

It goes without saying – the summit is all about meeting people. So there will be a constant mixture of workshops, dinners, beers and wine. We like to think of the summit as a very social event in itself.


Summit Pricing and Reservations

PERSON(S) TICKET COMBINATION COST IN EUROS COST IN USD
Individual Summit Participant Ticket
(includes meals, no accommodation)
€260 EUR $350 USD
Individual Summit Participant Ticket
+ 4 Nights Shared Accommodation
€590 EUR $800 USD

The total cost for most attendees will be €590 EUR or $800 USD (Summit Participant Ticket + 4 Nights Shared Accommodation). Shared accommodations will be contained in multi-room villas which hold between four and six persons. You should expect to share a room in these villas - in fact, the shared experience has been cited as the most fun and beneficial part of the previous Summit.

A more detailed price chart with variations based on how many nights you will be staying, whether you want shared or private accommodations, and whether you have a companion is available below.