This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "Marco Morana"

From OWASP
Jump to: navigation, search
Line 1: Line 1:
 
OWASP Bio - <br>
 
OWASP Bio - <br>
 
Marco Morana serves the OWASP organization by leading the [http://www.owasp.org/index.php/Cincinnati USA Cincinnati chapter]. His contribution to OWASP as author include the [http://www.owasp.org/index.php/Application_Threat_Modeling application threat modeling methodology] of the [http://www.lulu.com/items/volume_64/5678000/5678680/13/print/5678680.pdf OWASP secure coding guide] the [http://www.owasp.org/index.php/Testing_Guide_Introduction introduction to the security testing methodology] and [http://www.owasp.org/index.php/How_to_value_the_real_risk_AoC value the real risk section] of the [http://www.owasp.org/index.php/Testing_Guide OWASP security testing guide]. As project reviewer, Marco contributed to review the [http://www.owasp.org/index.php/Category:OWASP_Source_Code_Review_OWASP_Projects_Project OWASP Source Code Review Project] and [http://www.owasp.org/index.php/Category:OWASP_Security_Analysis_of_Core_J2EE_Design_Patterns_Project OWASP Security Analysis of Core J2EE Design Patterns Project]. Marco has presented on the topic of software and application security at several [http://www.owasp.org/index.php/Cincinnati#2009_Presentations_.28Archived.29 local chapter meetings] and OWASP organized conferences in [http://www.slideshare.net/marco_morana/rochester-security-summit-presentation USA] and [http://www.owasp.org/index.php?title=Italy_OWASP_Day_2&setlang=es Italy] as well as at [http://www.slideshare.net/marco_morana/secure-code-reviews-presentation CSI] and [http://www.slideshare.net/marco_morana/software-security-business-case-presentation Blackhat] security conferences.  
 
Marco Morana serves the OWASP organization by leading the [http://www.owasp.org/index.php/Cincinnati USA Cincinnati chapter]. His contribution to OWASP as author include the [http://www.owasp.org/index.php/Application_Threat_Modeling application threat modeling methodology] of the [http://www.lulu.com/items/volume_64/5678000/5678680/13/print/5678680.pdf OWASP secure coding guide] the [http://www.owasp.org/index.php/Testing_Guide_Introduction introduction to the security testing methodology] and [http://www.owasp.org/index.php/How_to_value_the_real_risk_AoC value the real risk section] of the [http://www.owasp.org/index.php/Testing_Guide OWASP security testing guide]. As project reviewer, Marco contributed to review the [http://www.owasp.org/index.php/Category:OWASP_Source_Code_Review_OWASP_Projects_Project OWASP Source Code Review Project] and [http://www.owasp.org/index.php/Category:OWASP_Security_Analysis_of_Core_J2EE_Design_Patterns_Project OWASP Security Analysis of Core J2EE Design Patterns Project]. Marco has presented on the topic of software and application security at several [http://www.owasp.org/index.php/Cincinnati#2009_Presentations_.28Archived.29 local chapter meetings] and OWASP organized conferences in [http://www.slideshare.net/marco_morana/rochester-security-summit-presentation USA] and [http://www.owasp.org/index.php?title=Italy_OWASP_Day_2&setlang=es Italy] as well as at [http://www.slideshare.net/marco_morana/secure-code-reviews-presentation CSI] and [http://www.slideshare.net/marco_morana/software-security-business-case-presentation Blackhat] security conferences.  
Besides contributing to OWASP, Marco works as Sr. Technology Information Security Officer and VP for a large financial organization in North America with responsibilities in the definition of the software security coding standards, security architecture design reviews, review of source code analysis and vulnerability assessments for financial web applications and technical risk analysis in support of the business security managers. Marco's work on application and software security has been published on [http://issuu.com/insecure/docs/insecure-17 In-secure magazine],[http://www.darkreading.com/ Secure Enterprise], [http://www.issa.org/Members/Journals-Archive/2006.html ISSA Journal] and the [http://portal.acm.org/citation.cfm?id=349060 C/C++ Users journal] as well as [http://iac.dtic.mil/iatac/download/security.pdf DHS Software Security Assurance] and is currently co-authoring a book on [http://www.slideshare.net/marco_morana/application-threat-modeling-presentation Application Threat Modeling].  Marco’s ideas and strategies for writing secure software are posted on his blog: http://securesoftware.blogspot.com. For requesting Marco to speak at one of the OWASP chapters or application security conferences please refer to the [http://www.owasp.org/index.php/OWASP_on_the_Move OWASP on the move project herein] or contact Marco directly by email: [marco][dot][m][dot][morana][at][gmail][dot][com]
+
Besides contributing to OWASP, Marco works as Sr. Technology Information Security Officer and VP for a large financial organization in North America with responsibilities in the technical security reviews for projects during the SDLC that includes architecture design reviews, review of source code analysis and vulnerability assessments. Marco's work on application and software security has been published on [http://issuu.com/insecure/docs/insecure-17 In-secure magazine],[http://www.darkreading.com/ Secure Enterprise], [http://www.issa.org/Members/Journals-Archive/2006.html ISSA Journal] and the [http://portal.acm.org/citation.cfm?id=349060 C/C++ Users journal] as well as [http://iac.dtic.mil/iatac/download/security.pdf DHS Software Security Assurance] and is currently co-authoring a book on [http://www.slideshare.net/marco_morana/application-threat-modeling-presentation Application Threat Modeling].  Marco’s ideas and strategies for writing secure software are posted on his blog: http://securesoftware.blogspot.com. For requesting Marco to speak at one of the OWASP chapters or application security conferences please refer to the [http://www.owasp.org/index.php/OWASP_on_the_Move OWASP on the move project herein] or contact Marco directly by email: [marco][dot][m][dot][morana][at][gmail][dot][com]

Revision as of 15:39, 23 July 2010

OWASP Bio -
Marco Morana serves the OWASP organization by leading the USA Cincinnati chapter. His contribution to OWASP as author include the application threat modeling methodology of the OWASP secure coding guide the introduction to the security testing methodology and value the real risk section of the OWASP security testing guide. As project reviewer, Marco contributed to review the OWASP Source Code Review Project and OWASP Security Analysis of Core J2EE Design Patterns Project. Marco has presented on the topic of software and application security at several local chapter meetings and OWASP organized conferences in USA and Italy as well as at CSI and Blackhat security conferences. Besides contributing to OWASP, Marco works as Sr. Technology Information Security Officer and VP for a large financial organization in North America with responsibilities in the technical security reviews for projects during the SDLC that includes architecture design reviews, review of source code analysis and vulnerability assessments. Marco's work on application and software security has been published on In-secure magazine,Secure Enterprise, ISSA Journal and the C/C++ Users journal as well as DHS Software Security Assurance and is currently co-authoring a book on Application Threat Modeling. Marco’s ideas and strategies for writing secure software are posted on his blog: http://securesoftware.blogspot.com. For requesting Marco to speak at one of the OWASP chapters or application security conferences please refer to the OWASP on the move project herein or contact Marco directly by email: [marco][dot][m][dot][morana][at][gmail][dot][com]