This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "Virginia"

From OWASP
Jump to: navigation, search
(Past Meetings)
(Next Meeting)
Line 6: Line 6:
 
== Next Meeting ==
 
== Next Meeting ==
  
Our next meeting will be on November 13 from 600pm until about 830pm.  The speakers will be:
+
Due to holidays, etc., the December meeting is canceledSee you in January!
 
 
''Nadya Bartol, Booz Allen Hamilton'': '''Framework for Software Assurance'''
 
 
 
Nadya's presentation will provide an update on the Software Assurance
 
Forum efforts to establish a comprehensive framework for software
 
assurance (SwA) and security measurement.  The Framework addresses
 
measuring achievement of SwA goals and objectives within the context of
 
individual projects, programs, or enterprises. It targets a variety of
 
audiences including executives, developers, vendors, suppliers, and
 
buyers.  The Framework leverages existing measurement methodologies,
 
including Practical Software and System Measurement (PSM); CMMI Goal,
 
Question, Indicator, Measure (GQ(I)M);  NIST SP 800-55 Rev1; and ISO/IEC
 
27004 and identifies commonalities among the methodologies to help
 
organizations integrate SwA measurement in their overall measurement
 
efforts cost-effectively and as seamlessly as possible, rather than
 
establish a standalone SwA measurement effort within an organization.
 
The presentation will provide an update on the SwA Forum Measurement
 
Working Group work, present the current version of the Framework and underlying measures
 
development and implementation processes, and propose example SwA
 
measures applicable to a variety of SwA stakeholdersThe presentation
 
will update the group on the latest NIST and ISO standards on
 
information security measurement that are being integrated into the
 
Framework as the standards are being developed.
 
 
 
''Paco Hope, Cigital'': '''The Web Security Testing Cookbook'''
 
 
 
The Web Security Testing Cookbook (O'Reilly & Associates, October 2008)
 
gives developers and testers the tools they need to make security
 
testing a regular part of their development lifecycle. Its recipe style
 
approach covers manual, exploratory testing as well automated techniques
 
that you can make part of your unit tests or regression cycle. The
 
recipes cover the basics like observing messages between clients and
 
servers, to multi-phase tests that script the login and execution of web
 
application features. This book complements many of the security texts
 
in the market that tell you what a vulnerability is, but not how to
 
systematically test it day in and day out. Leverage the recipes in this
 
book to add significant security coverage to your testing without adding
 
significant time and cost to your effort.
 
 
 
We hope to have a few copies to give away as autographed door prizes.
 
  
 
==Directions==
 
==Directions==

Revision as of 18:35, 14 November 2008

OWASP Washington VA

Welcome to the Washington VA chapter homepage. The chapter leader is Jeremy Epstein <paypal>Northern Virginia</paypal>


Participation

OWASP Foundation (Overview Slides) is a professional association of global members and is open to anyone interested in learning more about software security. Local chapters are run independently and guided by the Chapter_Leader_Handbook. As a 501(c)(3) non-profit professional association your support and sponsorship of any meeting venue and/or refreshments is tax-deductible. Financial contributions should only be made online using the authorized online chapter donation button. To be a SPEAKER at ANY OWASP Chapter in the world simply review the speaker agreement and then contact the local chapter leader with details of what OWASP PROJECT, independent research or related software security topic you would like to present on.

Sponsorship/Membership

Btn donate SM.gif to this chapter or become a local chapter supporter. Or consider the value of Individual, Corporate, or Academic Supporter membership. Ready to become a member? Join Now BlueIcon.JPG


Next Meeting

Due to holidays, etc., the December meeting is canceled. See you in January!

Directions

To Booz Allen's One Dulles facility:

13200 Woodland Park Road Herndon, VA 20171

From Tyson's Corner:

  1. Take LEESBURG PIKE / VA-7 WEST
  2. Merge onto VA-267 WEST / DULLES TOLL ROAD (Portions Toll)
  3. Take the VA-657 Exit (Exit Number 10 towards Herndon / Chantilly)
  4. Take the ramp toward CHANTILLY
  5. Turn Left onto CENTERVILLE ROAD (at end of ramp)
  6. Turn Left onto WOODLAND PARK ROAD (less than 1⁄2 mile)
  7. End at 13200 WOODLAND PARK ROAD

Past Meetings

For our October 2008 meeting, we had two fascinating talks relating to forensics.

Dave Merkel, Mandiant: Enterprise Grade Incident Management - Responding to Persistent Threats

Dave Merkel is Vice President of Products at Mandiant, a leading provider of information security services, education and products. Mr. Merkel has worked in the information security and incident response industry for over 10 years. His background includes service as a federal agent in the US Air Force and over 7 years experience directing security operations at America Online. He currently oversees the product business at Mandiant, and is in charge of building Mandiant Intelligent Response - an enterprise incident response solution. But no, he won't be selling you anything today.

Slides available: [[1] ]

Inno Eroraha, NetSecurity: [Responding to the Digital Crime Scene: Gathering Volatile Data

Inno Eroraha is the founder and chief strategist of NetSecurity Corporation, a company that provides digital forensics, hands-on security consulting, and Hands-on How-To® training solutions that are high-quality, timely, and customer-focused. In this role, Mr. Eroraha helps clients plan, formulate, and execute the best security and forensics strategy that aligns with their business goals and priorities. He has consulted with Fortune 500 companies, IRS, DHS, VA, DoD, and other entities.

Slides available: [[2] ]