This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "Women In AppSec"

From OWASP
Jump to: navigation, search
m (Global AppSec Conferences)
(Removed and/or updated aged content for the Committee)
Line 1: Line 1:
 
=WELCOME=
 
=WELCOME=
  
==Women in Application Security Program==
+
==Women in Application Security Committee==
  
The purpose of the Women in AppSec Program is to increase the visibility and participation of women in application security. The program was successfully launched in 2011 at AppSec USA, and the aim is to run the program at every OWASP Global AppSec going forward. Most recently, at AppSec EU in Amsterndam in May 2015, a program with the theme "Women in AppSec - Making it Happen" was launched and both a panel and a workshop were included at the event.
+
The purpose of Women in AppSec (WIA) Committee is to develop leadership, promote active membership and participation, and contributions by women in application security professional communities, globally and locally.
  
The Women in AppSec program is for any OWASP member who believes that diversity is important to the success of the organization, as well as for women looking to learn more about AppSec or who want to make career connections with like-minded colleagues.  This includes female undergraduate and graduate students, instructors, and professionals who are dedicated to information security or application development.  
+
The Women in AppSec program is for anyone who believes that diversity is important to the success of the organization, as well as for women looking to learn more about AppSec or who want to make career connections with like-minded colleagues.  This includes female undergraduate and graduate students, instructors, and professionals who are dedicated to information security or application development.  
  
'''AppSec USA 2015'''<br>
 
Currently, there is an effort to plan activities for AppSec USA 2015. Volunteers are eagerly sought to support the program at AppSec USA! We are especially excited to invite the founders of the '''InfoSec Girls''' initiative to the AppSec USA 2015 conference. To bring InfoSec Girls to AppSec USA, we need to raise $7500. We are very close to our goal and know that with the support of the OWASP community, we can easily get there! Donations above and beyond our goal will be used for future WIA programs around the world. <BR><br>'''Donate now:'''<br>
 
  
<paypal>Women In AppSec</paypal>
+
=WIA PURPOSE AND SCOPE=
 +
 
 +
==Purpose==
 +
 
 +
The purpose of Women in AppSec (WIA) Committee is to develop leadership, promote active membership and participation, and contributions by women in application security professional communities, globally and locally.
 +
 
 +
==Scope==
 +
 
 +
The scope for OWASP WIA Committee falls into the following areas:
 +
 
 +
# Attract women to OWASP, as active members, contributors and leaders.
 +
# Offer opportunities for women to become engaged in AppSec and related professional communities.
 +
# Provide inclusive targeted application security programs for all women learners.
 +
# Provide inclusive training and mentorship for all interested OWASP women.
 +
# Provide financial support to OWASP women members through scholarships, sponsorships, and grant making.
 +
# Pursue fundraising, advancement and development to secure financial support for OWASP WIA activities..
 +
# Integrate WIA track and related activities into OWASP events at all levels.
 +
# Cultivate women for community leadership, speakers for conferences, thought leadership, learning leaders, and local chapter events.
 +
# Collaborate with other committees and initiatives as needs present.
 +
# Collaborate with local OWASP Chapters and Global OWASP leadership, including but not limited to offering advisory support to local and global OWASP leadership for WIA advancement and collaboratively building pro-WIA OWASP communities.
 +
# Develop other special projects and events designed to further the purpose of WIA.
  
'''Want to find out more?'''<br> Join the weekly meeting - reach out via the [http://www.tfaforms.com/308703 Contact Form] or [mailto:[email protected] OWASP Support]. Fill out the survey to let us know how you'd like to participate! https://www.surveymonkey.com/r/SRNLD7H
+
=FIND US=
  
Regional conferences are also encouraged to host the Women in AppSec program. Contact us via the [http://www.tfaforms.com/308703 Contact Form] or [mailto:[email protected] OWASP Support] to discuss how to successfully run a program at your event.
+
==Email List==
  
{|
+
[https://lists.owasp.org/mailman/listinfo/appsec_usa_women_in_security WIA List and Archive]
|-
 
! width="400" align="left" |
 
! width="400" align="left" |
 
|-
 
| align="left" | [[Image:WiAAPAC3.jpg| left|330px]]  <br />
 
| align="left" | [[Image:IMG_5579.JPG|left|325px]]
 
| align="left" | [[Image:WiAAPAC2.jpg|left|330px]]
 
  
|}
+
==Twitter==
  
==Contact Us==
+
[https://twitter.com/owaspwia @OWASPWIA]
  
If you are interested in another piece of OWASP design for your event or project, please let us know by using the [http://owasp4.owasp.org/contactus.html OWASP Contact Us form].
+
==Slack Channel==
  
==Links==
+
[https://owasp.slack.com/messages/C2NUH1J5B/ WIA Slack Channel]
*[https://www.isc2.org/PressReleaseDetails.aspx?id=11240 (ISC)²® Report Reveals Women's Perspective and Skills are Transforming the Information Security Industry October 29, 2013].
 
  
*[https://www.youtube.com/watch?v=62i4o15NbgA&list=PLpr-xdpM8wG8ODR2zWs06JkMmlRiLyBXU&index=42 Women in AppSec Panel at AppSec USA 2013: Women in Information Security: Who Are We? Where Are We Going? Why? -- Joan Goodchild (Audio Only)]
 
  
=ABOUT THE PROGRAM=
+
=PREVIOUS WIA ACTIVITIES=
  
The OWASP Foundation, in recognition of value to both organizations and society, is working to support and enhance programs that increase the participation of women in the field of information and application security. The OWASP Foundation Women in AppSec Program provides merit-based funding for women to attend participating OWASP AppSec conferences. OWASP’s current program objective is to encourage female students at both the undergraduate and graduate levels, instructors, and professional working women who are dedicated to a career in information security and/or application development, to expand their skills and pursue application security. Interested applicants are encouraged to apply to the program running within their region of residence.<br>
+
== AppSec USA 2015 ==
  
 
'''AppSec USA 2015'''<br>
 
'''AppSec USA 2015'''<br>
Line 45: Line 54:
 
Sponsorship opportunities for commercial organizations and OWASP chapters are also available.
 
Sponsorship opportunities for commercial organizations and OWASP chapters are also available.
  
=PREVIOUS WIA ACTIVITIES=
+
'''AppSec USA 2015'''<br>
 +
Currently, there is an effort to plan activities for AppSec USA 2015. Volunteers are eagerly sought to support the program at AppSec USA! We are especially excited to invite the founders of the '''InfoSec Girls''' initiative to the AppSec USA 2015 conference. To bring InfoSec Girls to AppSec USA, we need to raise $7500. We are very close to our goal and know that with the support of the OWASP community, we can easily get there! Donations above and beyond our goal will be used for future WIA programs around the world. <BR><br>'''Donate now:'''<br>
  
 
== AppSec EU 2015 ==
 
== AppSec EU 2015 ==
Line 59: Line 69:
 
Learn more about the program here: http://2013.appsecusa.org/2013/activities/owasp-women-in-application-security-appsec-program/index.html  
 
Learn more about the program here: http://2013.appsecusa.org/2013/activities/owasp-women-in-application-security-appsec-program/index.html  
  
==WIA Attendee Sponsorship==
 
 
In the past, when we have offered sponsorships, we have typically had two winners selected for the sponsorship award; however, the number of winners depends on how much you can afford to sponsor. We recommend that you raise $3000 USD for each winner, at least. In the past, we have given each winner a free conference pass, one free training, and free travel and accommodation to attend the event.
 
[[Image:IMG_5746.JPG|right|500x260px]]
 
Below is the list of eligibility criteria used to select WIA sponsorship winners at AppSec USA 2013.
 
 
* Has provided 2 responsive contacts as reference, and both references are familiar with the candidate, application security, and OWASP.
 
* Both references have provided letters of recommendation.
 
* Has relevant/appropriate achievement goals for attending the conference.
 
* Is the applicant from the region that the conference is taking place in.
 
* Has background in volunteering for OWASP or similar organizations.
 
* Has participated in one of OWASP's programs or activities?
 
* Is either studying, wishing to study, working in AppSec, or interested in working in AppSec.
 
* Has financial need.
 
* Is a paid OWASP member, and/or employer/school is an OWASP sponsor.
 
* Has an interest in exploring application security
 
 
We encourage you to create your own set of criteria that will fit the Women In AppSec that you are planning within your region. The criteria above is meant to be a guideline of what has been used in the past.
 
 
=PLANNING A WIA EVENT=
 
==Planning a WIA Event==
 
 
The majority of the planning involved in running the Women in AppSec Program occurs before the conference or regional event. Below, you will find a brief outline of the tasks your team will have to take on.
 
 
'''Planning & Selection Team'''<br>
 
 
The first step you will need to take care of is the selection of your planning and selection team. These are the individuals that will be helping you manage the pre-event planning process and the selection of the sessions during the event. You will typically need a team of 5-6 people. The selection committee will then be broken down into several sub-teams of one to two people who will then work on sponsorship, marketing, the grading process, and the call for entries.
 
 
'''Sub-Team Roles'''<br>
 
 
''Sponsorship''
 
 
Two people should be responsible for developing the materials and seeking out sponsorships for the program. They will be in charge of creating the sponsorship packages, flyers, and seeking      out sponsorship from other chapters and organizations.
 
 
''Marketing''
 
 
At least two people should be responsible for marketing the event. Their job will consist of putting together press releases, keeping the event planners updated on progress, and
 
communicating progress to the overall community. They will also be responsible for getting the message out when the team is ready to start accepting applicants.
 
 
'''Budget'''<br>
 
As mentioned above, it is up to your team to decide what it is you wish to do during the event - that will determine the budget.
 
 
'''Sponsorship'''<br>
 
It is very important to start reaching out to the overall OWASP community and their corporate contacts as potential sponsorship leads. Develop a Sponsorship Strategy and put together a sponsorship flyer outlining the program, what you are seeking, and the benefits of sponsorship. Give incentive for sponsorship and details about the program to get potential sponsors interested. Make sure to include the successes of past Women in AppSec conference events. Once you have your materials and sponsorship packages sorted, you can get started with sponsorship seeking activities.
 
 
==During the conference==
 
Be sure the engage the women attending the conference in the sessions you have organized: encourage them to not only attend but to be active participants. It's not all about the women try and encourage some men to get involved and attend also, for this initiative to be successful it must be inclusive.
 
 
==Post-Conference==
 
 
After the conference, it is very important to gather feedback from the participants to make sure they enjoyed the experience. Ask them for a brief description about their experience, with a picture attached for the website. Then write up a review and lessons learned page to document the experience with the program. Make sure to include what can be improved upon in the future.
 
 
==Global AppSec Conferences==
 
 
[[Image:Appsec_APAC.jpg|right|x375px]]
 
OWASP AppSec conferences bring together industry, government, security researchers, and practitioners to discuss the state of the art in software security. This series was launched in the United States in 2004 and Europe in 2005. Global AppSec conferences are held annually in North America, Latin America, Europe, and Asia Pacific. Additionally, regional events are held in locations such as Brazil, China, India, Ireland, Israel, and Washington D.C just to name a few. The aim of the foundation is to bring the Women in AppSec Program to all of our regional and global events.
 
 
'''AppSec APAC'''
 
 
The AppSec APAC global conference takes place in the Asian-Pacific region. This conference is a reunion of local software security leaders, and aims to present cutting-edge ideas to attendees. OWASP events attract a worldwide audience interested in “what’s next”, and this global conference is no different. The conference is expected to draw 200-250 technologists each year from Government, Financial Services, Media, Pharmaceuticals, Healthcare, Technology, and many more. Women from the Asia-Pacific region are encouraged to apply to the program taking place during AppSec APAC.
 
 
'''AppSec EU'''
 
 
The AppSec EU global conference take place in the European region. Executives from Fortune 500 firms along with technical thought leaders such as security architects and lead developers, travel to hear the cutting-edge ideas presented by the software security industry's top talent. This conference is expected to draw 400-500 attendees each year from various regions within the Europe and beyond. Women from the European region are encouraged to apply to the program taking place during AppSec EU Research
 
 
'''AppSec Latam'''
 
 
The AppSec LATAM global conference takes place in the Latin American region. AppSec LATAM is a reunion of Latin American, software security leaders, providing a platform to discuss, participate in, and innovate within the software security industry. The conference is expected to draw 200-250 attendees from the Latin American region and beyond. Women in the Latin American region are encouraged to apply to the program taking place during AppSec LATAM.
 
 
'''AppSec USA'''
 
 
The AppSec USA global conference takes place in the North American region. AppSec USA is a world-class software security conference for technologists, auditors, risk managers, and entrepreneurs, gathering the world's top practitioner, to share the latest research and practices. This conference is expected to draw over 300 attendees within the North American region. AppSec USA is typically OWASP's biggest conference of the year so women are encouraged to apply to the program taking place during AppSec USA if they live or will be traveling from within North America.
 
 
=APPSEC USA 2015=
 
The Women in AppSec (WIA) program is for all OWASP members who believe that diversity is important to the success of an organization, as well as for women who want to make career connections with like-minded colleagues. We encourage you to attend our session on Thursday at 3:30pm in Room F, featuring the founders of InfoSec Girls, Apoorva Giri and Shruthi Kamath.<br>
 
 
We also invite you to join us for our networking and “Birds of a Feather” sessions on on Thursday in WIA meeting room . Stop by anytime between 10:00am and 3:30pm to meet other members and learn more about the WIA program. You can also suggest a discussion topic on the sign-up at the room entrance. <br><br>
 
Interested in getting involved? [http://www.tfaforms.com/308703 Contact Form] or [mailto:[email protected] OWASP Support].
 
 
'''About InfoSec Girls'''<br>
 
Based in India, [https://infosecgirls.in/ InfoSec Girls] educates women about information security both at the community level and as a career option. Their kickoff event at C0c0n 2014 in Kochi, Kerala attracted 130 women and was the first event of it’s kind in the region. 
 
 
Founders Apoorva Giri and Shruthi Kamath have spoken extensively on cybersecurity and women’s issues in India. Their efforts to bring awareness of cybersecurity to a wider audience has empowered women and girls to consider security careers as well as protect themselves online. They are also members of OWASP WIA.
 
 
At AppSec USA in September, they will inspire and inform your organization’s diversity and education programs, as well as give individual OWASP members ideas on how they can contribute to the application security education effort. <br>
 
 
'''Sponsorship opportunities''' <br>
 
Sponsorship opportunities for commercial organizations and OWASP chapters are available.  Please email Lisa Ly and Kerry Jo Richards ([email protected]; [email protected]) for more information about sponsorship packages.
 
 
=PAST WINNERS=
 
 
==Previous Women in AppSec Winners==
 
==Previous Women in AppSec Winners==
 
Following their experience at AppSec, winners are encouraged to write a short piece about their experience at the conference and their participation in the Women in AppSec program. Here, they outline their experience with the Women in AppSec Program in their own words.  
 
Following their experience at AppSec, winners are encouraged to write a short piece about their experience at the conference and their participation in the Women in AppSec program. Here, they outline their experience with the Women in AppSec Program in their own words.  
Line 201: Line 121:
 
|}
 
|}
 
<br>
 
<br>
 
 
=WIA SPONSORS=
 
We'd like to offer a warm thanks to the individuals and organizations that have sponsored the OWASP Women in Technology project. <br>
 
==Diamond Sponsors==
 
<br>
 
[[File:Netflix_Logo_Print_FourColorCMYK_Small.png]]<br>
 
==Platinum Sponsors==
 
==Gold Sponsors==
 
[[File:Business e.png|none|thumb]]
 
 
==Silver Sponsors==
 
<br><br>
 
[[File:Owasp-bangalore-logo.png]]  <br><br>
 
'''OWASP BOSTON'''<br><br>‎
 
'''OWASP CHICAGO'''<br><br>‎
 
'''OWASP DENVER'''<br><br>‎
 
[[File:Owasp_logo_ireland_small.jpg‎]]  '''OWASP Dublin-Ireland'''  <br><br>
 
'''OWASP GERMANY'''<br><br>‎
 
[[File:Owaspjapan.png]]  <br><br>
 
[[File:New_OWASP_LA_Logo-08-2014.jpg]] <br><br>
 
'''OWASP MINNEAPOLIS ST. PAUL'''<br><br>
 
'''OWASP NETHERLANDS'''<br><br>
 
[[File:Owaspnyc.jpeg]]'''OWASP NYC'''<br><br>
 
'''OWASP NORWAY'''<br><br>
 
 
=SPONSOR WIA=
 
==Sponsor WIA==
 
We'd like to offer a warm thanks to the individuals and organizations that have sponsored the OWASP Women in Technology project. If your organization would like to discuss sponsorship, please email Lisa Ly and Kerry Jo Richards ([email protected]; [email protected]) for more information.<br>
 
 
'''Sponsorship Packages for AppSec USA 2015:'''<br>
 
'''Silver:''' Donate $500 or more, get your company name and logo on the WIA Wiki Sponsorship Tab from now until June 2016. (10 sponsorships available)<br>
 
'''Gold:''' Donate $1500 or more, get your company name and logo on the WIA Wiki Sponsorship Tab from now until June 2016 and put your literature on the table in the WIA meeting room at AppSec USA (8 sponsorships available).<br>
 
'''Platinum:''' Donate $2500 or more, all of the above place a banner stand in the WIA meeting room at AppSec USA and have your company logo/social handle on the screen at the WIA session. (5 Sponsorships available).<br>
 
'''Diamond:''' Donate $3500 or more, all of the above plus introduce the WIA speakers at the AppSec USA WIA session. (1 Sponsorship available).
 
 
=CONTACT US=
 
 
==Contact Us==
 
 
If you are interested in another piece of OWASP design for your event or project, please let us know by using the [http://owasp4.owasp.org/contactus.html OWASP Contact Us form].
 
 
<headertabs></headertabs>
 

Revision as of 20:55, 20 June 2017

WELCOME

Women in Application Security Committee

The purpose of Women in AppSec (WIA) Committee is to develop leadership, promote active membership and participation, and contributions by women in application security professional communities, globally and locally.

The Women in AppSec program is for anyone who believes that diversity is important to the success of the organization, as well as for women looking to learn more about AppSec or who want to make career connections with like-minded colleagues. This includes female undergraduate and graduate students, instructors, and professionals who are dedicated to information security or application development.


WIA PURPOSE AND SCOPE

Purpose

The purpose of Women in AppSec (WIA) Committee is to develop leadership, promote active membership and participation, and contributions by women in application security professional communities, globally and locally.

Scope

The scope for OWASP WIA Committee falls into the following areas:

  1. Attract women to OWASP, as active members, contributors and leaders.
  2. Offer opportunities for women to become engaged in AppSec and related professional communities.
  3. Provide inclusive targeted application security programs for all women learners.
  4. Provide inclusive training and mentorship for all interested OWASP women.
  5. Provide financial support to OWASP women members through scholarships, sponsorships, and grant making.
  6. Pursue fundraising, advancement and development to secure financial support for OWASP WIA activities..
  7. Integrate WIA track and related activities into OWASP events at all levels.
  8. Cultivate women for community leadership, speakers for conferences, thought leadership, learning leaders, and local chapter events.
  9. Collaborate with other committees and initiatives as needs present.
  10. Collaborate with local OWASP Chapters and Global OWASP leadership, including but not limited to offering advisory support to local and global OWASP leadership for WIA advancement and collaboratively building pro-WIA OWASP communities.
  11. Develop other special projects and events designed to further the purpose of WIA.

FIND US

Email List

WIA List and Archive

Twitter

@OWASPWIA

Slack Channel

WIA Slack Channel


PREVIOUS WIA ACTIVITIES

AppSec USA 2015

AppSec USA 2015
The Women in AppSec (WIA) program is for all OWASP members who believe that diversity is important to the success of an organization, as well as for women who want to make career connections with like-minded colleagues. We encourage you to attend our session on Thursday at 3:30pm in Room F, featuring the founders of InfoSec Girls, Apoorva Giri and Shruthi Kamath.

We also invite you to join us for our networking and “Birds of a Feather” sessions on on Thursday in WIA meeting room . Stop by anytime between 10:00am and 3:30pm to meet other members and learn more about the WIA program. You can also suggest a discussion topic on the sign-up at the room entrance.

Sponsorship opportunities for commercial organizations and OWASP chapters are also available.

AppSec USA 2015
Currently, there is an effort to plan activities for AppSec USA 2015. Volunteers are eagerly sought to support the program at AppSec USA! We are especially excited to invite the founders of the InfoSec Girls initiative to the AppSec USA 2015 conference. To bring InfoSec Girls to AppSec USA, we need to raise $7500. We are very close to our goal and know that with the support of the OWASP community, we can easily get there! Donations above and beyond our goal will be used for future WIA programs around the world.

Donate now:

AppSec EU 2015

During AppSec EU there was a panel discussion and workshop supported by the Women in AppSec initiative. Through these sessions we hoped to encourage women to pursue a career in AppSec and help them realize it is an option for them. These sessions was be open to all so we can help build support for the women around us. Learn more here: http://2015.appsec.eu/women-in-application-security

Panel: "Women in AppSec - Making it Happen"
During this panel session we discussed what can be done to Make it Happen for Women in AppSec going forward. What have those currently working in the field done to Make it Happen for themselves and other women; what tips and advice do they have to help you do to make a career for yourself or encourage those around you (sister, friend, daughter, etc…) to pursue a career in AppSec? What can we as professionals can do to help encourage girls to go for a career in AppSec?

Workshop
During the workshop we introduced female attendees of the conference to what a career in App Sec can involve. We discussed application security and the many career paths available. We hope to build relationships that may lead to a mentoring program for these women.

AppSec USA 2013

Learn more about the program here: http://2013.appsecusa.org/2013/activities/owasp-women-in-application-security-appsec-program/index.html

Previous Women in AppSec Winners

Following their experience at AppSec, winners are encouraged to write a short piece about their experience at the conference and their participation in the Women in AppSec program. Here, they outline their experience with the Women in AppSec Program in their own words.

Carrie Schaper, 2013 Winner



Carrie Schaper Small.jpg "OWASP Appsec proved to be a great experience for me, uniting and interacting with friends, professionals, and colleagues from the Information Security space from across the US and Internationally whom were in attendance. The huge space and well organized functions such as the: trainings, expert talks, panels, bug-bounty, lock-picking village and social events all enhanced the conference experience. Participating on the Women in IT panel was a wonderful experience, as many women were in attendance and participated in collaborative discussions. OWASP Appsec held in NY this year, was a premier NY conference not to be missed. Thank you to OWASP, its attendees and organizers."


Nancy Lornston, 2013 Winner



Nancy Lorntson Small.jpg "AppSec 2013 was an awesome experience! Nowhere in the world can you find the top security experts all in one place at one time (and participate in a marriage proposal!). The conference presentations were well organized and the speakers were prepared to share pros, cons, successes and failures of their work in order to advance the application security domain. The variety of vendors was terrific as well.

The Women in AppSec panel was an opportunity to advance women's position in the community. Each speaker shared some very candid remarks about their personal experiences and by the end, it was clear that while more work needs to be done, there is a sincere interest by companies, universities and the industry in general to work on doing the things needed to attract more women to the profession.

The training course I attended (Open source tools) lived up to it's billing and I came away with several invaluable tips and strategies to improve our program.

A huge thank you to the Women in App Sec Panel and OWASP in general for this opportunity to attend the premier Application Security Conference in the world."


Tara Wilson, 2011 Winner



Tara wilson.jpg “Being fortunate enough to receive the Women in AppSec sponsorhsip is a unique and valuable experience. It is a great opportunity for women to have a chance to bolster their skills and dive deep into the world of application security. I found that attending the conference was not only a great way to experience what the OWASP community has to offer, but it also gives students a chance to network with a great group of people who are passionate about their field and willing to share a wealth of information.”


Chandni Bhowmik, 2011 Winner



Chandni bhowmik.jpg Chandni Bhowmik is currently completing an M.S. in Computer Security and Information Assurance at the Rochester Institute of Technology (RIT). Her first introduction to OWASP was through the project WebScarab during an application security lab last spring at RIT and her interest in OWASP grew ever since. Over the summer, she started programming open source web applications using built-in security features of Django and Python. She is interested in becoming an information security researcher, and hopes to leverage learning at OWASP AppSec USA 2011 in ad-hoc architecture, mobile platforms and over-all concepts of web application security. Besides secure programming, Chandni enjoys her current research involving digital image forensics and machine learning. In addition to attending school, she has interned in IT security and compliance at Paychex, a Rochester based payroll processing company, and gained industrial experience working an assistant systems engineer for Tata Consultancy Services, a global IT firm.