This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Global Industry Committee

From OWASP
Revision as of 17:13, 5 January 2010 by Clerkendweller (talk | contribs) (Meetings: 2010 added)

Jump to: navigation, search

The Global Industry Committee was created during the OWASP EU Summit in Portugal. The primary purpose of the Global Industry Committee is to work with industry executives to gather requirements from industry, work with Membership, Projects and others.

Mission Statement

To expand awareness of and promote the inclusion of software security best practices in Industry, Government, Academia and regulatory agencies and be a voice for industry. We will accomplish this through outreach; including presentations, development of position papers and collaborative efforts with other entities. Powerpoint of Accomplishments


Committee Plan

Step 1: Identify specific organizations worth working with to spread the OWASP gospel

Step 2: Prioritize the proposed liasons based on potential impact, and also realistic likelihood of the organization actively working with us

Step 3: Execute, leveraging global OWASP resources as much as possible to maximize impact

Step 4: Evaluate progress & repeat Step 1-3

Committee Members

Board Member Rep: Tom Brennan

Committee Members:

Name Email Location
Joe Bernik US
Rex Booth rex.booth 'at' gt dot com US
David Campbell dcampbell 'at' owasp dot org US
Alexander Fry alexander.fry 'at' owasp dot org US
Georg Hess georg.hess 'at' artofdefence dot com Germany
Eoin Keary eoin.keary 'at' owasp dot org Ireland
Yiannis Pavlosoglou yiannis 'at' owasp dot org UK
Colin Watson colin.watson 'at' owasp dot org UK

OWASP Employees:

  • Alison
  • Kate Hartman

Getting Involved

Mailing List

Join our mailing list

Meetings

The next Global Industry Committee meeting will be:

  • Tuesday 5 January 2010 at 19:00 hrs (7pm) GMT (Conference call number: 1.800.851.3547 x3738751)

Previous meeting minutes are:

Membership

Membership explains how to become an OWASP organization supporter or individual member.

You don't have to be an OWASP Member or Committee Member to contribute - the current committee members joined for a 12 month term - see How to Join a Committee and Global Committee Pages.

Other ongoing initiatives

Current Activity

Work in Progress

The current activities being undertaken:

Task Deadline Type Status Description Who
ENISA Cloud Computing Common Assurance Metrics 2010 Standards New Work with Category:OWASP Cloud ‐ 10 Project to contribute to the development of Common Assurance Metrics for ENISA's Cloud Computing Information Assurance Framework. See also the Cloud Computing Risk Assessment report. CW
Personal Information Online COP 5 Mar 2010 Legislation In Progress Provide response to UK Information Commissioner's Office draft "Personal Information Online Code of Practice" CW
Secure POS Vendor Alliance (SPVA) - Outreach In Progress Begin dialogue about possibility of working together DC

Completed Items

Task Completed Type Status Description Who
NIST SP 800-37 Revision 1 FPD Review Project 30 Dec 2009 Standards Closed Provide response to "NIST SP 800-37 Revision 1 Final Public Draft, Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach" RB
CREST CRESTCon 15 Dec 2009 Outreach Closed Already an oversubscribed event, YP & CW have been placed on the reserve list. Update: Positions secured for the 15th. YP
SDL Pro Network 30 Nov 2009 Outreach Closed Contact SDL Pro Network to discuss if there are opportunities for OWASP to become involved or connected in some way CW
Draft NIST IR 7628 25 Nov 2009 Standards Closed Provide response to "NIST IR 7628 Draft Smart Grid Cyber Security Strategy and Requirements" CW
Appsec DC 2009 10-13 Nov 2009 Outreach Closed Conference organisation - special effort to engage with US Federal sector RB
UK Ministry of Justice - Legislation Closed Ask to be added to official consultation list CW
IT-SA 13-15 Oct 2009 Outreach Closed OWASP booth at trade show GH
OWASP AppSec Germany 2009 13 Oct 2009 Outreach Closed Conference organisation GH
US Library of Congress 28 Sep 2009 Outreach Closed Presentation about OWASP RB
OWASP Ireland AppSec 2009 10 Sep 2009 Outreach Closed Conference organisation EK
OWASP Citations 7 Sep 2009 Other Closed Identify and record the most important references to OWASP in official, or otherwise important, documents. Page created at: Industry:Citations CW
US Library of Congress 26 Aug 2009 Outreach Closed Presentation about OWASP RB
OWASP webcast at Brighttalk Data and Privacy in Web 2.0 Summit 13 Aug 2009 Outreach Closed Deliver OWASP presentation on XSS, client side exploitation, and countermeasures. DC
SAFECode Secure Development Practices (update to Oct 2008 version) 31 Jul 2009 Standards Closed Response to SAFECode "Fundamental Practices for Secure Software Development: A Guide to the Most Effective Secure Development Practices in Use Today." CW
OWASP CSA Project 8 Jul 2009 Standards Closed Response to RFC Cloud Security Alliance Guidance v1.0 TB
Scotland 25 Jun 2009 Outreach Closed Presentation about the Global Industry Committee, its role and recent activities (presentation slides File:Owasp-scotland-industry-committee-june-2009.ppt and written notes File:Owasp-scotland-industry-committee-june-2009-notes.pdf) CW
OWASP Presentation at CFP Con 2009 1 Jun 2009 Outreach Closed Deliver presentation on web threats and countermeasures. See CFP tutorial page grep OWASP for more info. DC
ENISA Who-Is-Who Directory - Outreach Closed Contact ENISA regarding OWASP inclusion in directory (in progress). Encourage European chapter leaders to contact their ENISA liaison officers (completed). Contact UK liaison officer on behalf of London, Leeds and Scotland chapters. CW
IIL Insurance Institute of London 2 Jun 2009 Outreach Closed Contact IIL regarding future input to their publication Insurance Aspects of E-Commerce CW
Draft NIST SP 800-118 29 May 2009 Standards Closed Provide response to "Draft NIST Special Publication 800-118 Guide to Enterprise Password Management" CW/EK/RB/DC
German IT Industry Association 15 May 2009 Outreach Closed Presentation on OWASP GH
Outreach Presentation to Frontier Airlines 7 May 2009 Outreach Closed Provide outreach presentation covering fundamentals of AppSec and Intro to OWASP DC
DPC BS 10012 31 Mar 2009 Standards Closed Provide response to "BS 10012 Specification for the management of personal information in compliance with the Data Protection Act 1998" Draft for Public Comment (DPC) CW
Draft NIST SP 800-53 Revision 3 27 Mar 2009 Standards Closed Provide response to "Draft NIST Special Publication 800-53 (Revision 3) Recommended Security Controls for Federal Information Systems and Organizations" RB
Draft NIST SP 800-122 13 Mar 2009 Standards Closed Provide response to "Draft NIST Special Publication 800-122 Guide to Protecting the Confidentiality of Personally Identifiable Information (PII)" CW
London 12 Mar 2009 Outreach Closed Presentation about the Global Industry Committee, its role and recent activities (presentation slides File:Owasp-london-industry-committee-march-2009.ppt and written notes File:Owasp-london-industry-committee-march-2009-notes.pdf) CW
Digital Britain Interim Report 11 Mar 2009 Legislation Closed Provide response to UK Government's "Digital Britain Interim Report Jan 2009" CW
SnowFROC Front Range 5 Mar 2009 Outreach Closed Conference organisation DC
US Department of Commerce 25 Feb 2009 Outreach Closed Presentation about OWASP to Economic Security Working Group RB
DPC BS 8878:2009 31 Jan 2009 Standards Closed Provide response to "BS 8878:2009 Web accessibility. Building accessible experiences for disabled people" Draft for Public Comment (DPC) Puneet/CW
AppSec Presentation Delivered to Infragard, Dec 2008 Dec 2008 Outreach Closed Infragard is a collaboration between the US FBI and maintainers of critical infrastructure. Presentation here. Email DC for full PPT with speaker notes DC
The Register Google Analytics — Yes, it is a security risk Nov 2008 Outreach Closed Co-ordination of response and provision of comments from OWASP leaders about risk of JavaScript on Barack Obama's website DC

General Presentations and Reports

Summit_2009

Summaries (for inclusion into other full OWASP presentations):


Other Global Committees