This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "Global Industry Committee"

From OWASP
Jump to: navigation, search
(SP-800 53 Rev 3 status updated and moved the completed / April summary PPT added / SP 800-118 added)
(Thank you added)
 
(258 intermediate revisions by 14 users not shown)
Line 1: Line 1:
'''The Global Industry Committee was created during the OWASP EU Summit in Portugal. The primary purpose of the Global Industry Committee is to work with industry executives to gather requirements from industry, work with Membership, Projects and others.'''
+
__NOTOC__
 +
{{Global_Committee_Retirement}}
  
==Mission Statement==
+
Thank you to everyone who participated in, and contributed to, the Global Industry Committee up until 1st April 2013.
  
''To expand awareness of and promote the inclusion of software security best practices in Industry, Government, Academia and regulatory agencies.  We will accomplish this through outreach; including presentations, development of position papers and collaborative efforts with other entities.''
+
==== About the Committee ====
  
 +
=== Mission Statement ===
  
==Committee Plan==
+
The Global Industry Committee was created during the OWASP EU Summit in Portugal. '''The OWASP Global Industry Committee (GIC) shall expand awareness of and promote the inclusion of software security best practices in Industry, Government, Academia and regulatory agencies and be a voice for industry. This will be accomplished through outreach; including presentations, development of position papers and collaborative efforts with other entities.'''  The committee is governed by the [[Global Industry Committee Governance]] document.
 +
<br>
  
DRAFT PLAN
 
  
Step 1:
+
=== Committee Members ===
[[Industry:Organizations_for_Outreach|Identify specific organizations]] worth working with to spread the OWASP gospel
+
<br>Members:  
  
Step 2:
+
{| class="prettytable FCK__ShowTableBorders"
Prioritize the proposed liasons based on potential impact, and also realistic likelyhood of the organization actively working with us
+
|-
 +
! Name
 +
! Email
 +
! Location
 +
|-
 +
| Tobias Gondrom
 +
| tobias.gondrom 'at' owasp dot org
 +
| HK, UK and DE
 +
|-
 +
| Rex Booth
 +
| rex.booth 'at' owasp dot org
 +
| DC, USA
 +
|-
 +
| Mauro Flores
 +
| mauro.flores 'at' owasp dot org
 +
| Uruguay
 +
|-
 +
| Alexander Fry
 +
| alexander.fry 'at' owasp dot org
 +
| USA
 +
|-
 +
| Eoin Keary
 +
| eoin.keary 'at' owasp dot org
 +
| Dublin, Ireland
 +
|-
 +
| Mateo Martinez
 +
| mateo.martinez 'at' owasp dot org
 +
| Uruguay
 +
|-
 +
| Colin Watson
 +
| colin.watson 'at' owasp dot org
 +
| UK
 +
|-
 +
| Marco Morana
 +
| marco.m.morana 'at' citi dot com
 +
| Italy
 +
|-
 +
| Christian Papathanasiou
 +
| christian.papathanasiou 'at' owasp dot org
 +
| Greece
 +
|}
  
Step 3:
 
Execute, leveraging global OWASP resources as much as possible to maximize impact
 
  
Step 4:
+
'''§ The committee chair is Tobias Gondrom.'''  The previous chairs were:  
Evaluate progress & repeat Step 1-3
 
  
==Committee Members==
+
*Rex Booth (July 2011 to September 2012)
 +
*Joe Bernik (Feb 2011 to July 2011)
 +
*Yiannis Pavlosoglou (Nov 2010 to Jan 2011)
 +
*Colin Watson (Nov 2009 to Oct 2010)
  
Board Member Rep: [mailto:[email protected] Tom Brennan]
 
  
Committee Members:
+
Former members of the committee:
 +
*David Campbell
 +
*Georg Hess
 +
*Eoin Keary
 +
*Yiannis Pavlosoglou
 +
*Joe Bernik
 +
*Nishi Kumar
 +
*Lorna Alamri
 +
*Sherif Koussa
  
* [mailto:[email protected] Rex Booth]  (U.S.)
 
* David Campbell: dcampbell 'at' owasp dot org (U.S.)
 
* [mailto:[email protected] Georg Hess] (Germany)
 
* [mailto:[email protected] Eoin Keary] (Ireland)
 
* [mailto:[email protected] Colin Watson] (UK)
 
  
OWASP Employees:
 
* Alison
 
* Kate Hartman
 
  
==Getting Involved==
+
==== Meetings and Getting Involved ====
  
=== Mailing List ===
+
=== Mailing List ===
  
[http://lists.owasp.org/mailman/listinfo/global_industry_committee Join our mailing list]
+
[http://lists.owasp.org/mailman/listinfo/global_industry_committee Join our mailing list] - this is the best way to find out what's going on day-to-day, and to provide input.
  
=== Meetings ===
 
  
The next Global Industry Committee meeting will be:
+
=== Meetings  ===
 +
Currently, the Global Industry Committee conference call meetings approximately every 4 weeks and last no longer than an hour.
  
* TBC (Conference Bridge: 1-866-534-4754)
 
  
Host Code: check calendar invite
+
The '''next Global Industry Committee meeting''' will be:  
 +
'''Monday Oct-15, 2012, 18:00 UTC / GMT.'''
  
Guest Code: 192341
+
Global Meeting Time Planner - [http://www.timeanddate.com/worldclock/fixedtime.html?iso=20121015T19&p1=136&ah=1 Click Here]
  
 +
'''Meeting agenda'''
 +
* CISO Guide
 +
* CISO Survey
 +
* Industry Table at AppSec US
 +
* industry bodies contacts?
 +
* ...?
  
Previous meeting minutes are:
 
  
* [[Industry:Minutes 2009-01-23|23 Jan 2009]]
+
Minutes of previous meetings are:
 +
* [[Industry: Minutes_2013-03-01|1.March 2013]]
 +
* December 2012 (call on the CISO Guide and CISO Survey project)
 +
* October 2012
 +
*[[Industry:Minutes_2012-06-13|13 June 2012]]
 +
* 19 April 2012
 +
* 02 September 2011
 +
* 28 July 2011
 +
*[[Industry:Minutes_2011-06-16|16 June 2011]]
 +
*[[Industry:Minutes_2011-05-13|13 May 2011]]
 +
*[[Industry:Minutes_2011-04-29|29 Apr 2011]]
 +
*[[Industry:Minutes_2011-04-08|08 Apr 2011]]
 +
*[[Industry:Minutes 2011-03-18|18 Mar 2011]] ([[Media:GIC_Meeting_Minutes_03182011.pdf| PDF of 18 Mar 2011 Meeting Minutes]])
 +
*[[Industry:Minutes 2011-03-04|04 Mar 2011]] ([[Media:GIC_Meeting_Minutes_03042011.pdf| PDF of 04 Mar 2011 Meeting Minutes]]) ([https://spreadsheets.google.com/ccc?key=0ApZ9zE0hx0LNdEpRbVhBUEljMGpLNnVJa0FHeWZwMkE&hl=en&authkey=CPjLgdwN Proposed GIC Budget for 2011])
 +
*[[Industry:Minutes 2011-02-25|25 Feb 2011]] ([[Media:GIC_Meeting_Minutes_02252011.pdf| PDF of 25 Feb 2011 Meeting Minutes]])
 +
*[[Media:Summit2011-industry-committee-outcomes.pdf|9 Feb 2011]] (Summit outcomes)
 +
*[[Industry:Minutes 2010-08-17|17 Aug 2010]] (also [http://www.owasp.org/images/0/0d/Gic_call_17aug2010.mp3 MP3 recording of the call])
 +
*[[Industry:Minutes 2010-05-18|18 May 2010]]
 +
*[[Industry:Minutes 2010-01-05|05 Jan 2010]] (also [http://www.owasp.org/images/a/a3/Owasp_gic_call_5jan10.mp3 MP3 recording of the call])
 +
*[[Industry:Minutes 2009-01-23|23 Jan 2009]]
 +
* 16 Dec 2010
  
=== Membership ===
+
=== Membership ===
  
[[Membership]] explains how to become an OWASP organization supporter or individual member.  
+
[[Membership]] explains how to become an OWASP organization supporter or individual member. But you don't have to be an OWASP Member or Committee Member to contribute.  
  
You don't have to be an OWASP Member or Committee Member to contribute - the current committee members joined for a 12 month term - see [[How to Join a Committee]] and [[Global Committee Pages]].
+
The current committee members joined for a 12 month term - see [[How to Join a Committee]] and [[Global Committee Pages]]. We would especially welcome new members who can widen our geographic coverage (e.g. Africa, Asia and South America) and who have time to contribute proactively.  
  
  
==Current Activity==
+
==== Current Activity ====
  
=== Work in Progress ===
 
  
The current activities being undertaken:
+
=== Work in Progress  ===
  
{| class="prettytable"
+
The current activities being undertaken:
! Task
+
 
! Deadline
+
{| class="prettytable FCK__ShowTableBorders"
! Type
+
|-
! Status
+
! Task  
! Description
+
! Deadline  
 +
! Type  
 +
! Status  
 +
! Description  
 
! Who
 
! Who
 
|-
 
|-
| [[Industry:Draft NIST SP 800-118|Draft NIST SP 800-118]]
+
| Nominet Consultation
| 29 May 2009
+
| Jan 2013
 
| Standards
 
| Standards
 
| New
 
| New
| Provide response to "Draft NIST Special Publication 800-118 Guide to Enterprise Password Management"
+
| Submit response to proposed security aspects of Nominet's [http://www.nominet.org.uk/how-participate/policy-development/current-policy-discussions-and-consultations/consultation-new-uk consultation on a new .uk domain name service]
| 'TBC'
+
| CW
 
|-
 
|-
| [[Industry:NIST SP 800-53 CAG|NIST SP 800-53 CAG]]
 
| 'TBD'
 
| Standards
 
| Started
 
| Translating the Top 10 into a format requested by SANS for inclusion in a new [http://www.sans.org/cag/ Consensus Audit Guidelines] (CAG)
 
| David/Rex
 
|}
 
 
=== Completed Items ===
 
 
{| class="prettytable"
 
! Task
 
! Completed
 
! Type
 
! Status
 
! Description
 
! Who
 
 
|-
 
|-
| [[Industry:DPC BS 10012|DPC BS 10012]]
+
| ENISA Who-Is-Who Directory
| 31 Mar 2009
+
| Sep 2012
| Standards
+
| Outreach
| Closed
+
| New
| Provide response to "BS 10012 Specification for the management of personal information in compliance with the Data Protection Act 1998" Draft for Public Comment (DPC)
+
| Request update to ENISA Who-Is-Who directory ([http://www.enisa.europa.eu/publications/who-is-who-directory-2011 2011 version]) for OWASP and OWASP UK; promote other EU chapters to submit information
| Colin
+
| CW
 
|-
 
|-
| [[Industry:Draft NIST SP 800-53 Revision 3|Draft NIST SP 800-53 Revision 3]]
+
| [https://www.owasp.org/index.php/Industry:DECC_Smart_Metering_Implementation Smart Metering Implementation Draft Licence Condition Relating to Security]
| 27 Mar 2009
+
| 18 Jul 2012
 
| Standards
 
| Standards
 
| Closed
 
| Closed
| Provide response to "Draft NIST Special Publication 800-53 (Revision 3) Recommended Security Controls for Federal Information Systems and Organizations"
+
| Submit response to UK smart meter security consultation
| Rex/David
+
| CW, TG
 
|-
 
|-
| [[Industry:Draft NIST SP 800-122|Draft NIST SP 800-122]]
+
| Industry Outreach Sessions at OWASP AppSec EU 2012
| 13 Mar 2009
+
| 12 Jul 2012
| Standards
+
| Outreach
 
| Closed
 
| Closed
| Provide response to "Draft NIST Special Publication 800-122 Guide to Protecting the Confidentiality of Personally Identifiable Information (PII)"
+
| Conduct industry outreach sessions at AppSec EU to educate about OWASP initiatives and solicit feedback
| Colin
+
| CW
 
|-
 
|-
| [[Industry:Digital Britain Interim Report|Digital Britain Interim Report]]
+
| [https://www.owasp.org/index.php/Application_Security_Guide_For_CISOs AppSec Guide For CISO]
| 11 Mar 2009
+
| June 2013
| Legislation
+
| Outreach
| Closed
+
| In progress, draft 75% completed
| Provide response to UK Government's "Digital Britain Interim Report Jan 2009"
+
| Guide to help CISOs (Chief Information Security Officers) to manage application security programs
| Colin
+
| MM
 
|-
 
|-
| [[Industry:DPC BS 8878:2009|DPC BS 8878:2009]]
+
| [https://www.owasp.org/index.php/Industry:GIC_CISO_Survey_2013 CISO Survey 2013 on Application Security - Draft]
| 31 Jan 2009
+
| Feb 2013
| Standards
+
| Outreach
| Closed
+
| In progress
| Provide response to "BS 8878:2009 Web accessibility. Building accessible experiences for disabled people" Draft for Public Comment (DPC)
+
|  
| Puneet/Colin
+
| TG
 
|-
 
|-
| AppSec Presentation Delivered to Infragard, Dec 2008
+
| Industry Outreach Sessions at OWASP AppSec US 2012
| Dec 2008
+
| 25 Oct 2012
 
| Outreach
 
| Outreach
 
| Closed
 
| Closed
| [http://www.infragard.net/ Infragard] is a collaboration between the US FBI and maintainers of critical infrastructure.  [http://docs.google.com/Present?docid=ddkr62qv_0cn7km4c3&skipauth=true Presentation here].  Email DC for full PPT with speaker notes
+
| Conduct industry outreach sessions at AppSec US to educate about OWASP initiatives and solicit feedback
| DC
+
| TG
 
|-
 
|-
 
|}
 
|}
  
=== General Presentations and Reports ===
+
=== Other ongoing initiatives  ===
 +
 
 +
*[http://www.owasp.org/index.php/Global_Industry_Committee-SIG Special Interest Groups] - Outreach to sector-specific critical infrastructures worldwide.
 +
*[http://www.owasp.org/index.php/Category:India OWASP India Advisory Board] - Regional panel contributing to the software outsourcing industry.
 +
*[http://www.owasp.org/index.php/Industry:Citations OWASP Citations] - References to OWASP in official, or otherwise important, documents.
 +
 
 +
 
 +
=== Completed Items  ===
 +
 
 +
[[Global_Industry_Committee/Completed_Initiatives|View the GIC's past initiatives]]
 +
 
 +
 
 +
==== GIC Records ====
 +
 
 +
 
 +
=== Committee Working Documents ===
 +
*'''[https://spreadsheets.google.com/spreadsheet/ccc?key=0ApZ9zE0hx0LNdEpRbVhBUEljMGpLNnVJa0FHeWZwMkE&hl=en_US&authkey=CPjLgdwN 2011 GIC Budget]
 +
* [https://spreadsheets.google.com/ccc?key=0ApZ9zE0hx0LNdEZ1NmNHRGZOX3E0V2F2T2lUZ0RyVkE&hl=en&authkey=CN3toL0F GIC Member Task List]
 +
* [https://docs.google.com/document/d/1ow_XZ_chhopu0yAYuMnmGXfdTRhlrKJEdqKZZ-pHloo/edit?hl=en&authkey=CPWb-csP Comprehensive List of Industry Verticals]
 +
* [http://code.google.com/p/owasp-cbt-project/downloads/list Security For Managers And Executives - Industry Outreach Presentation ]&nbsp;
 +
 
 +
 
 +
=== Monthly Reports ===
 +
*[https://docs.google.com/present/edit?id=0AZZ9zE0hx0LNZGczZ3B4YnpfMTJnMmh6ZjJmYg&hl=en_US Ppt template for Monthly Board Meeting updates]
 +
*[[Media:GIC_update_4_29_2011.pdf| May Industry Committee Update]]
 +
*[http://www.owasp.org/index.php/File:GIC_update.pptx April Industry Committee Update]
 +
 
 +
 
 +
===OWASP Summits and Working Sessions===
 +
*[https://docs.google.com/a/owasp.org/document/d/1WTTmmpc2bx3IZ9f5zU2ubTG_BrCxxrXzVHnUQUIzAWI/edit?hl=en_US Notes from Industry Outreach Sessions at AppSec EU - Dublin, 2011]
 +
*From Industry Outreach Session at 2011 AppSec EU - [https://docs.google.com/leaf?id=1UFf0Fuqhg_0u49E4s6iNxmEwNP8358M36sXs1mwLg3O3oQC7fFSwAxKMUoYW&hl=en_US Ppt presentation on CISO Survey, Rex Booth]
 +
*From Industry Outreach Session at 2011 AppSec EU -[https://docs.google.com/leaf?id=1ZFUaqj7fVSFm1BwEMnVCAS_Zi5xJUbugVHZP54hULIdEUYJYVkQ93vzsuY3o&hl=en_US Ppt presentation on Industry Outreach, Lorna Alamri]
 +
*[[Summit 2011]] ([[Media:Summit2011-industry-committee-outcomes.pdf|Working session outcomes]])
 +
*[[Summit 2009]]
 +
 
 +
 
 +
===About the GIC===
 +
 
 +
*Global Industry Committee Presentation [[Image:Owasp-summit2009-industry-committee.ppt]]
 +
 
  
Summaries (for inclusion into other full OWASP presentations):
+
===Summaries===
* April 2009 [[Image:Owasp-industry-committee-summary-april-2009.ppt]]
+
(for inclusion into other full OWASP presentations):  
* March 2009 [[Image:Owasp-industry-committee-summary-march-2009.ppt]]
 
  
 +
*Sep 2009 [[Image:Owasp-industry-committee-summary-september-2009.ppt]]
 +
*Jul 2009 [[Image:Owasp-industry-committee-summary-july-2009.ppt]]
 +
*May 2009 [[Image:Owasp-industry-committee-summary-may-2009.ppt]]
 +
*Apr 2009 [[Image:Owasp-industry-committee-summary-april-2009.ppt]]
 +
*Mar 2009 [[Image:Owasp-industry-committee-summary-march-2009.ppt]]
  
Other:
 
* 12 March 2009 - [[London]] - Presentation about the Global Industry Committee, its role and recent activities (presentation slides [[Image:Owasp-london-industry-committee-march-2009.ppt]] and written notes [[Image:Owasp-london-industry-committee-march-2009-notes.pdf]])
 
  
  
Other [http://www.owasp.org/index.php/Global_Committee_Pages Global Committees]
+
<headertabs/>
 +
<br>
 +
[http://lists.owasp.org/mailman/listinfo/global_industry_committee Join our mailing list] | [[How to Join a Committee]] | [[Global_Committee_Pages|Learn about other Global Committees]]

Latest revision as of 08:23, 2 April 2013

As of April 1, 2013 the Global Committees were retired in order to enable wider community involvement and volunteerism through the OWASP Global Initiatives. 

Want to get involved with OWASP, but not sure where to start? Check out the OWASP Global Initiatives Page.

Thank you to everyone who participated in, and contributed to, the Global Industry Committee up until 1st April 2013.

About the Committee

Mission Statement

The Global Industry Committee was created during the OWASP EU Summit in Portugal. The OWASP Global Industry Committee (GIC) shall expand awareness of and promote the inclusion of software security best practices in Industry, Government, Academia and regulatory agencies and be a voice for industry. This will be accomplished through outreach; including presentations, development of position papers and collaborative efforts with other entities. The committee is governed by the Global Industry Committee Governance document.


Committee Members


Members:

Name Email Location
Tobias Gondrom tobias.gondrom 'at' owasp dot org HK, UK and DE
Rex Booth rex.booth 'at' owasp dot org DC, USA
Mauro Flores mauro.flores 'at' owasp dot org Uruguay
Alexander Fry alexander.fry 'at' owasp dot org USA
Eoin Keary eoin.keary 'at' owasp dot org Dublin, Ireland
Mateo Martinez mateo.martinez 'at' owasp dot org Uruguay
Colin Watson colin.watson 'at' owasp dot org UK
Marco Morana marco.m.morana 'at' citi dot com Italy
Christian Papathanasiou christian.papathanasiou 'at' owasp dot org Greece


§ The committee chair is Tobias Gondrom. The previous chairs were:

  • Rex Booth (July 2011 to September 2012)
  • Joe Bernik (Feb 2011 to July 2011)
  • Yiannis Pavlosoglou (Nov 2010 to Jan 2011)
  • Colin Watson (Nov 2009 to Oct 2010)


Former members of the committee:

  • David Campbell
  • Georg Hess
  • Eoin Keary
  • Yiannis Pavlosoglou
  • Joe Bernik
  • Nishi Kumar
  • Lorna Alamri
  • Sherif Koussa


Meetings and Getting Involved

Mailing List

Join our mailing list - this is the best way to find out what's going on day-to-day, and to provide input.


Meetings

Currently, the Global Industry Committee conference call meetings approximately every 4 weeks and last no longer than an hour.


The next Global Industry Committee meeting will be: Monday Oct-15, 2012, 18:00 UTC / GMT.

Global Meeting Time Planner - Click Here

Meeting agenda

  • CISO Guide
  • CISO Survey
  • Industry Table at AppSec US
  • industry bodies contacts?
  • ...?


Minutes of previous meetings are:

Membership

Membership explains how to become an OWASP organization supporter or individual member. But you don't have to be an OWASP Member or Committee Member to contribute.

The current committee members joined for a 12 month term - see How to Join a Committee and Global Committee Pages. We would especially welcome new members who can widen our geographic coverage (e.g. Africa, Asia and South America) and who have time to contribute proactively.


Current Activity

Work in Progress

The current activities being undertaken:

Task Deadline Type Status Description Who
Nominet Consultation Jan 2013 Standards New Submit response to proposed security aspects of Nominet's consultation on a new .uk domain name service CW
ENISA Who-Is-Who Directory Sep 2012 Outreach New Request update to ENISA Who-Is-Who directory (2011 version) for OWASP and OWASP UK; promote other EU chapters to submit information CW
Smart Metering Implementation Draft Licence Condition Relating to Security 18 Jul 2012 Standards Closed Submit response to UK smart meter security consultation CW, TG
Industry Outreach Sessions at OWASP AppSec EU 2012 12 Jul 2012 Outreach Closed Conduct industry outreach sessions at AppSec EU to educate about OWASP initiatives and solicit feedback CW
AppSec Guide For CISO June 2013 Outreach In progress, draft 75% completed Guide to help CISOs (Chief Information Security Officers) to manage application security programs MM
CISO Survey 2013 on Application Security - Draft Feb 2013 Outreach In progress TG
Industry Outreach Sessions at OWASP AppSec US 2012 25 Oct 2012 Outreach Closed Conduct industry outreach sessions at AppSec US to educate about OWASP initiatives and solicit feedback TG

Other ongoing initiatives


Completed Items

View the GIC's past initiatives


GIC Records

Committee Working Documents


Monthly Reports


OWASP Summits and Working Sessions


About the GIC


Summaries

(for inclusion into other full OWASP presentations):



Join our mailing list | How to Join a Committee | Learn about other Global Committees