This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "Austin"

From OWASP
Jump to: navigation, search
Line 14: Line 14:
 
'''When:''' Thursday, January 17th, from 5-7pm
 
'''When:''' Thursday, January 17th, from 5-7pm
  
'''Where:''' Sherlocks Baker Street Pub and Grill at the corner of 183 and Burnett
+
'''Where:''' Sherlocks Baker Street Pub and Grill at the corner of 183 and Burnet
  
 
'''What is it?''' The Austin Security Professionals Happy Hour is a monthly gathering of information security professionals from the Austin area, jointly organized by OWASP and ISSA. It is a time to enjoy some drinks and food provided by our sponsors, and a good opportunity to get to know other InfoSec professionals. Come on down and hang out with a bunch of hackers and geeks!
 
'''What is it?''' The Austin Security Professionals Happy Hour is a monthly gathering of information security professionals from the Austin area, jointly organized by OWASP and ISSA. It is a time to enjoy some drinks and food provided by our sponsors, and a good opportunity to get to know other InfoSec professionals. Come on down and hang out with a bunch of hackers and geeks!

Revision as of 22:14, 14 January 2013

OWASP Austin

Welcome to the Austin chapter homepage. The chapter leadership includes: David Hughes, President/Conference Chair, Paul Griffith, Vice President,Josh Sokol, Board Member, James Wickett, Board Member, Rich Vazquez, Board Member, Greg Genung, Board Member


Participation

OWASP Foundation (Overview Slides) is a professional association of global members and is open to anyone interested in learning more about software security. Local chapters are run independently and guided by the Chapter_Leader_Handbook. As a 501(c)(3) non-profit professional association your support and sponsorship of any meeting venue and/or refreshments is tax-deductible. Financial contributions should only be made online using the authorized online chapter donation button. To be a SPEAKER at ANY OWASP Chapter in the world simply review the speaker agreement and then contact the local chapter leader with details of what OWASP PROJECT, independent research or related software security topic you would like to present on.

Sponsorship/Membership

Btn donate SM.gif to this chapter or become a local chapter supporter. Or consider the value of Individual, Corporate, or Academic Supporter membership. Ready to become a member? Join Now BlueIcon.JPG




January Austin Security Professionals Happy Hour, Sponsored by Trusteer

Please RSVP so we will have an idea of how many to expect!


When: Thursday, January 17th, from 5-7pm

Where: Sherlocks Baker Street Pub and Grill at the corner of 183 and Burnet

What is it? The Austin Security Professionals Happy Hour is a monthly gathering of information security professionals from the Austin area, jointly organized by OWASP and ISSA. It is a time to enjoy some drinks and food provided by our sponsors, and a good opportunity to get to know other InfoSec professionals. Come on down and hang out with a bunch of hackers and geeks!

RSVP: http://jan2013infosechappyhour.eventbrite.com


Our Sponsor: Trusteer

Boston-based Trusteer is the leading provider of endpoint cybercrime prevention solutions that protect businesses against advanced threats and prevent data breaches. Hundreds of organizations and millions of end users rely on Trusteer to protect critical endpoint applications on computers and mobile devices from advanced malware and spear-phishing attacks. Trusteer’s Cybercrime Prevention Architecture combines multi-layer security software with real-time threat intelligence to stop emerging threats that are invisible to legacy security solutions. To learn more about Trusteer solutions and customer success visit http://www.trusteer.com. Trusteer


RSVP: http://jan2013infosechappyhour.eventbrite.com



January OWASP Austin Chapter Meeting

When: January 29th from 11:30a - 1:00p

Who: Wendy Nather

Wendy Nather is Research Director of the 451 Research Enterprise Security Practice. With over 20 years of IT experience, she built and managed the IT security program at the Texas Education Agency, where she directed multimillion-dollar initiatives for a statewide external user base of over 50,000. She also provided security guidance for the datacenter consolidation of 27 Texas state agencies.

Wendy previously worked in various roles in the investment banking division of Swiss Bank Corp (now UBS). Based in Chicago, Zurich and London, she also served as the first IT Security Director for the EMEA region. She has spoken at various industry conferences in the US and abroad, and co-authored The Cloud Security Rules. She was also named one of Tripwire Inc.’s “Top 25 Influencers in Security.”


Topic: Data events, or why security is cloudier than you think.

Abstract: Data security doesn't involve just securing data at rest or in transit. It also needs to be secured in use ­ which means that at any point, the characteristics of the data can change. We call this situation a "data event," and it can mean that security requirements have to change as a result.

This is not the same thing as logging event data; this is taking into account changes in the combination, use or business context surrounding specific data. For example, a press release is confidential and requires a certain set of security policies in the areas of access control, DLP, key management (if encryption is involved), and so on. But once the business event occurs, the press release suddenly becomes the opposite of confidential, and all the policies have to change immediately as a result.

Data events can also occur when data elements are combined in particular ways so that they become covered by regulations. A query might produce a small enough sample size that it needs to be treated as protected information, or a doctor becomes a patient so that her name is now protected by HIPAA. Data events are often tied closely to the business context, and as such can mirror transactions and workflows.

Data events are important because traditional security policies have been applied to the current container of the data: this database is confidential because some rows are confidential, or this Word document requires access control (but its content can be copied and pasted somewhere else). Container-centric security is too static for today's high-speed, big-data, cloud-based (pick as many buzzwords as you like) processing.

This talk will describe the concept of data events, and will invite audience discussion on how security controls can be adapted to them.


Food: Oh yeah, Taco Deli time! Please RSVP so we'll be sure to have enough for all! Only those who RSVP will be eligible for any drawings/giveaways that may take place!


Location: National Instruments, 11500 N. Mopac.Building C

RSVP: http://owaspjanuary.eventbrite.com/


And if for some reason you cannot make it in person, make sure that you sign up for the GoToWebinar and join us virtually:


To Join the Webinar:

1. At the time listed above, click this link to join the Webinar: https://www.gotomeeting.com/register/891195518

Webinar ID: 891-195-518


Questions? call: David Hughes (512) 589-4623



Future Speakers and Events

  • January 17th, 2013 5:00 PM to 7:00 PM, Austin Security Professionals Happy Hour, Sherlocks @ 183 and Burnet
  • January 29th, 2013 -11:30 AM to 1 PM, Austin OWASP Meeting, Data events, or why security is cloudier than you think - Wendy Nather, 451 Group


  • October 24th-25th, 2013 - 8 AM to 5 PM - AppSec USA/LASCON 2012 in Austin, TX!
  • November 2012 - No Meeting (Happy Holidays!)
  • December 2012 - OWASP Holiday Party! (TBD)

How to add a new Austin article

You can follow the instructions to make a new Austin article. Please use the appropriate structure and follow the Tutorial. Be sure to paste the following at the end of your article to make it show up in the Austin category:

[[Category:Austin]]