This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "Bay Area"

From OWASP
Jump to: navigation, search
(Thursday, January, 24th)
Line 3: Line 3:
 
NEXT EVENT:
 
NEXT EVENT:
  
== Thursday, October 4th ==
+
'''NEXT EVENT:  January, 24th @ 6PM - PG&E Building'''
 +
  
 +
OWASP Bay Area will host its next meeting at the Pacific Gas & Electric on Thursday, January 24.  As usual attendance is free and food and beverages will be provided.  This will be an awesome event and a great opportunity to network with industry peers.  The event is open to the public; please forward this invite to your colleagues and friends who are interested in computer and application security. 
  
'''Agenda and Presentations:'''  
+
'''Agenda and Presentations:'''
 +
6:00pm - 6:30pm ... Check-in and Holiday Reception (food & beverages)
 +
6:30pm - 7:15pm ... ''Securing Flash® & Flex® Applications'' – Erick Lee, Adobe Systems
 +
7:15pm - 8:00pm ... ''Application Security and PCI Compliance'' – Jim Cowing, Digital Resource Group
 +
8:00pm - 8:30pm ... Networking Session
  
6:00pm – 6:30pm          Check-in and Reception (food and beverages)
+
'''Venue:'''
 +
Pacific Gas & Electric
 +
245 Market Street
 +
San Francisco, CA  94105
  
6:30pm – 7:15pm          "ModSecurity - Open Source Web Application Firewall" - Ivan Rustic
+
''Securing Flash and Flex Applications''
  
7:15pm – 7:30pm          Break & Networking Session
+
'''Presented by:''' Erick Lee, Adobe Systems
  
7:30pm – 8:15pm          "An Analysis of Emerging Security Vulnerabilities & the Impact to Business" - Neil Daswani
+
''Application Security and PCI Compliance''
  
8:15pm – 8:30pm          Q & A
+
'''Presented by:''' James Cowing, CPA, CISSP, QSA, QPASP, Managing Director, Digital Resource Group
  
'''Venue:'''
+
'''Abstract:''' Application security has greatly influenced the Payment Card Industry’s (PCI) efforts to reduce risk through the Data Security Standards. This talk will give you real world experiences on how organizations are addressing the application security requirements and what is coming in the near future.  Topics will include:                                                                                                                                                                                                                                           
  
Golden Gate University
+
·        PCI DSS Requirement 6: “Develop and maintain secure systems and applications” (with special attention to the June 30th deadline for Application firewalls)  
Room 2203
 
536 Mission Street
 
(Between 1st & 2nd Streets or Montgomery Street BART Station)
 
San Francisco, CA 94105-2968
 
  
 +
·        How the new Payment Application Data Security Standard (PA-DSS) reported to release this calendar quarter effects merchants, service providers and the application development community
  
Please RSVP through this link:  http://www.eventbrite.com/event/74194919:
+
·        Requirements for testing including application-layer penetration tests
  
''
+
'''Bio:''' As the original founder of DRG in 1997, James Cowing leads DRG's Information Security Consulting practice. With over ten years of security consulting experience and twenty years of financial services industry experience, Mr. Cowing has helped thousands of government, financial services, ecommerce, enterprise, and health care companies maneuver through the often complex and stringent security compliance requirements of their respective industry. Mr. Cowing is a seasoned payment card industry professional, renowned speaker and trusted security advisor to industry leading financial institutions, merchants, and service providers. He holds a CPA certification in California and Hawaii, an MBA in Finance and a BA from UCLA in Economics. Mr. Cowing served as the co-chair of the Security Committee for the Financial Services Technology Consortium (FSTC) and is currently a member of ISACA, ISSA, Computer Security Institute and the American Institute of Certified Public Accountants (AICPA) Information Technology Division.
“Open Source Web Application Firewall”'' by Ivan Rustic
 
 
'''Bio:'''
 
If we hear so much about web application firewalls and their role as a first line of defense in protecting our web applications, a large amount of credit has to go to Ivan Ristic. Ivan Ristic is the creator of ModSecurity (an open source web application firewall and intrusion detection/prevention engine). He started playing in the webappsec space sometime around 2002 and working seriously since 2004. Based out of London, UK, he works for Breach Security. He is currently in charge of the ModSecurity product line, which includes ModSecurity, sensor appliances based around it and management appliances. Ivan also wrote Apache Security for O'Reilly, a web security guide for administrators, system architects, and programmers. Prior to web application security, he has worked as a developer, system architect and technical director in the software development industry.
 
''
 
“An Analysis of Emerging Security Vulnerabilities & the Impact to Business”'' by Neil Daswani
 
  
'''Abstract:'''
+
Please RSVP by responding to this email or visit ''http://owaspjan2008.eventbrite.com''
This talk discusses how IT professionals can go about learning what they need to know to prevent the most significant emerging data security vulnerabilities, and the impact these vulnerabilities are having on electronic commerce.  It will review how attacks such as XSRF (Cross-Site-Request-Forgery) and SQL Injection work, and how to defend against them.  It will present some industry-wide statistics on software security vulnerabilities reported to various databases, and emerging trends in the field of software security.  Finally, it will discuss the current state of security education, and provide pointers to certification programs, books, and organizations where you and your colleagues can learn more.
 
  
'''Bio:'''
+
Special thanks to Pacific Gas & Electric for hosting this event.
Neil has served in a variety of research , development, teaching, and managerial roles at Google, Stanford University , DoCoMo USA Labs, Yodlee, and Bellcore (now Telcordia Technologies).  His areas of expertise include security, wireless data technology, and peer-to-peer systems. He has published extensively in these areas, frequently gives talks at industry and academic conferences, and has been granted several U.S. patents. He received a Ph.D. and a master's in computer science from Stanford University , and earned a bachelor's in computer science with honors with distinction from Columbia University.
 

Revision as of 04:04, 11 January 2008

OWASP San Francisco

Welcome to the San Francisco chapter homepage. The chapter leader is Robi Papp


Participation

OWASP Foundation (Overview Slides) is a professional association of global members and is open to anyone interested in learning more about software security. Local chapters are run independently and guided by the Chapter_Leader_Handbook. As a 501(c)(3) non-profit professional association your support and sponsorship of any meeting venue and/or refreshments is tax-deductible. Financial contributions should only be made online using the authorized online chapter donation button. To be a SPEAKER at ANY OWASP Chapter in the world simply review the speaker agreement and then contact the local chapter leader with details of what OWASP PROJECT, independent research or related software security topic you would like to present on.

Sponsorship/Membership

Btn donate SM.gif to this chapter or become a local chapter supporter. Or consider the value of Individual, Corporate, or Academic Supporter membership. Ready to become a member? Join Now BlueIcon.JPG


NEXT EVENT:

NEXT EVENT: January, 24th @ 6PM - PG&E Building


OWASP Bay Area will host its next meeting at the Pacific Gas & Electric on Thursday, January 24. As usual attendance is free and food and beverages will be provided. This will be an awesome event and a great opportunity to network with industry peers. The event is open to the public; please forward this invite to your colleagues and friends who are interested in computer and application security.

Agenda and Presentations: 6:00pm - 6:30pm ... Check-in and Holiday Reception (food & beverages) 6:30pm - 7:15pm ... Securing Flash® & Flex® Applications – Erick Lee, Adobe Systems 7:15pm - 8:00pm ... Application Security and PCI Compliance – Jim Cowing, Digital Resource Group 8:00pm - 8:30pm ... Networking Session

Venue: Pacific Gas & Electric 245 Market Street San Francisco, CA 94105

Securing Flash and Flex Applications

Presented by: Erick Lee, Adobe Systems

Application Security and PCI Compliance

Presented by: James Cowing, CPA, CISSP, QSA, QPASP, Managing Director, Digital Resource Group

Abstract: Application security has greatly influenced the Payment Card Industry’s (PCI) efforts to reduce risk through the Data Security Standards. This talk will give you real world experiences on how organizations are addressing the application security requirements and what is coming in the near future. Topics will include:

· PCI DSS Requirement 6: “Develop and maintain secure systems and applications” (with special attention to the June 30th deadline for Application firewalls)

· How the new Payment Application Data Security Standard (PA-DSS) reported to release this calendar quarter effects merchants, service providers and the application development community

· Requirements for testing including application-layer penetration tests

Bio: As the original founder of DRG in 1997, James Cowing leads DRG's Information Security Consulting practice. With over ten years of security consulting experience and twenty years of financial services industry experience, Mr. Cowing has helped thousands of government, financial services, ecommerce, enterprise, and health care companies maneuver through the often complex and stringent security compliance requirements of their respective industry. Mr. Cowing is a seasoned payment card industry professional, renowned speaker and trusted security advisor to industry leading financial institutions, merchants, and service providers. He holds a CPA certification in California and Hawaii, an MBA in Finance and a BA from UCLA in Economics. Mr. Cowing served as the co-chair of the Security Committee for the Financial Services Technology Consortium (FSTC) and is currently a member of ISACA, ISSA, Computer Security Institute and the American Institute of Certified Public Accountants (AICPA) Information Technology Division.

Please RSVP by responding to this email or visit http://owaspjan2008.eventbrite.com

Special thanks to Pacific Gas & Electric for hosting this event.