This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "Minneapolis St Paul"

From OWASP
Jump to: navigation, search
m (Updating formatting.)
(Upcoming Meetings)
Line 5: Line 5:
  
 
== Upcoming Meetings ==
 
== Upcoming Meetings ==
<h3>March OWASP Meeting – Dan Cornell<br />
+
<h3>April OWASP Meeting – Gunnar Peterson<br />
Vulnerability Management in an Application Security World</h3>
+
OWASP Top Ten Web Services</h3>
  
Monday March 16, 2009, 5:30 p.m.
+
Monday, April 27, 2009, 6:00 p.m.
  
Identifying application-level vulnerabilities via penetration tests and code reviews is only the first step in actually addressing the underlying risk.  Managing vulnerabilities for applications is more challenging than dealing with traditional infrastructure-level vulnerabilities because they typically require the coordination of security teams with application development teams and require security managers to secure time from developers during already-cramped development and release schedules. In addition, fixes require changes to custom application code and application-specific business logic rather than the patches and configuration changes that are often sufficient to address infrastructure-level vulnerabilities.
+
What do Web apps, Web 2.0, Cloud Computing, SOA, and Rest all have in common? They all use Web services for functionality, data access and integration. Unfortunately, by default Web services also lack a security model. The OWASP Top Ten Web Services goes into the technical details of the vulnerabilities, remediations, and examples of common
  
This presentation details many of the pitfalls organizations encounter while trying to manage application-level vulnerabilities as well as outlines strategies security teams can use for communicating with development teams.  Similarities and differences between security teams’ practice of vulnerability management and development teams’ practice of defect management will be addressed in order to facilitate healthy communication between these groups.
+
Web services security issues like authentication and authorization flaws, how sensitive data is disclosed, and why security standards like WS-Security and SAML can be your best friend or your worst nightmare.
  
 
=== Speaker Bio ===  
 
=== Speaker Bio ===  
Dan Cornell has over ten years of experience architecting, developing and securing web-based software systems. As a Principal of Denim Group, he leads the organization's technology team overseeing methodology development and project execution for Denim Group's customers. He also heads the Denim Group application security research team, investigating the application of secure coding and development techniques to the improvement of web based software development methodologies. He is also the primary author of sprajax, Denim Group's open source tool for assessing the security of AJAX-enabled web applications.  
+
Gunnar Peterson Managing Principal Arctec Group, a Twin Cities based consulting and training firm. He is also Visiting Scientist at Carnegie Mellon University Software Engineering Institute, editor for IEEE Security & Privacy Journal "Build Security In," and lead on OWASP Top Ten Web Services. He maintains a popular information security blog at http://1raindrop.typepad.com
  
 
=== Where/When ===
 
=== Where/When ===
Date: Monday March 16, 2009<br />
+
Date: Monday, April 27, 2009<br />
Time: 5:30 p.m.<br />
+
Time: 6:00 p.m.<br />
  
Location:  MEC M.1600, (1st Floor of the Management Education Center)
+
Location:  L3000 - third Floor of the Library Building, Wheelock Whitney Hall, Minneapolis Community and Technical College (Room and building change from last meeting.)
<br />Minneapolis Community and Technical College / Metro State University http://www.minneapolis.edu/campusmaps/
 
  
 
Address: 1501 Hennepin Avenue, Minneapolis, MN 55403<br  />
 
Address: 1501 Hennepin Avenue, Minneapolis, MN 55403<br  />
  
Directions: http://www.minneapolis.edu/directions.cfm - The building entrance is at the corner of 13th St and Harmon Pl.
+
Directions: http://www.minneapolis.edu/campusmaps/index.cfm or http://www.minneapolis.edu/directions.cfm
  
 
=== Agenda ===
 
=== Agenda ===
5:30 pm – Networking and optional sign-in for CISSP credits<br />
+
5:30 pm – Room opens for Networking<br />
6:00 pm - Introduction and Welcome: OWASP chapter updates<br />
+
6:00pm - Welcome: OWASP chapter updates, Conference Announcement!<br />
6:15 pm Dan Cornell<br />
+
6:30pm Gunnar Peterson – OWASP Top Ten Web Services<br />
 
8:00 pm - Upcoming Events reminder and meeting wrap-up
 
8:00 pm - Upcoming Events reminder and meeting wrap-up
 +
 +
Email [email protected] if you plan to attend so we can order enough refreshments.
  
 
===Thank You===
 
===Thank You===
 
+
[http://strategicit.org/center/ Center for Strategic Information Technology and Security] for sponsoring our meeting location.
Center for Strategic Information Technology and Security for sponsoring our meeting location.
 
  
 
We currently are looking for a meeting sponsor for refreshments for the meeting and for the book give-away.
 
We currently are looking for a meeting sponsor for refreshments for the meeting and for the book give-away.

Revision as of 20:49, 18 April 2009

OWASP Minneapolis St Paul

Welcome to the Minneapolis St Paul chapter homepage. The chapter leader is [Kuai]


Participation

OWASP Foundation (Overview Slides) is a professional association of global members and is open to anyone interested in learning more about software security. Local chapters are run independently and guided by the Chapter_Leader_Handbook. As a 501(c)(3) non-profit professional association your support and sponsorship of any meeting venue and/or refreshments is tax-deductible. Financial contributions should only be made online using the authorized online chapter donation button. To be a SPEAKER at ANY OWASP Chapter in the world simply review the speaker agreement and then contact the local chapter leader with details of what OWASP PROJECT, independent research or related software security topic you would like to present on.

Sponsorship/Membership

Btn donate SM.gif to this chapter or become a local chapter supporter. Or consider the value of Individual, Corporate, or Academic Supporter membership. Ready to become a member? Join Now BlueIcon.JPG

<paypal>Minneapolis St Paul</paypal>


Upcoming Meetings

April OWASP Meeting – Gunnar Peterson
OWASP Top Ten Web Services

Monday, April 27, 2009, 6:00 p.m.

What do Web apps, Web 2.0, Cloud Computing, SOA, and Rest all have in common? They all use Web services for functionality, data access and integration. Unfortunately, by default Web services also lack a security model. The OWASP Top Ten Web Services goes into the technical details of the vulnerabilities, remediations, and examples of common

Web services security issues like authentication and authorization flaws, how sensitive data is disclosed, and why security standards like WS-Security and SAML can be your best friend or your worst nightmare.

Speaker Bio

Gunnar Peterson Managing Principal Arctec Group, a Twin Cities based consulting and training firm. He is also Visiting Scientist at Carnegie Mellon University Software Engineering Institute, editor for IEEE Security & Privacy Journal "Build Security In," and lead on OWASP Top Ten Web Services. He maintains a popular information security blog at http://1raindrop.typepad.com

Where/When

Date: Monday, April 27, 2009
Time: 6:00 p.m.

Location: L3000 - third Floor of the Library Building, Wheelock Whitney Hall, Minneapolis Community and Technical College (Room and building change from last meeting.)

Address: 1501 Hennepin Avenue, Minneapolis, MN 55403

Directions: http://www.minneapolis.edu/campusmaps/index.cfm or http://www.minneapolis.edu/directions.cfm

Agenda

5:30 pm – Room opens for Networking
6:00pm - Welcome: OWASP chapter updates, Conference Announcement!
6:30pm – Gunnar Peterson – OWASP Top Ten Web Services
8:00 pm - Upcoming Events reminder and meeting wrap-up

Email [email protected] if you plan to attend so we can order enough refreshments.

Thank You

Center for Strategic Information Technology and Security for sponsoring our meeting location.

We currently are looking for a meeting sponsor for refreshments for the meeting and for the book give-away.

OWASP & FLOSS Application Security Mini-Conference 2008 - October 21, 2008

Thanks to all who joined us on October 21, 2008 for a mini conference in October 2008 at University of Minnesota's Saint Paul campus. Our first conference was a great success, with around 150 people attending! We look forward to the next one.

Videos

Videos of several past meetings are available at https://www.owasp.org/index.php/Category:OWASP_Video#Videos

Most recent videos:

Dan Cornell - Vulnerability Management in an Application Security World - OWASP (MSP) - 16 March 2009 (1 hour, 52 minutes) | Slides (PDF)

Rick Ensenbach - Proactive Lifecycle Security Management - OWASP (MSP) - 16 February 2009 (Part 1 of 2 - 35 minutes) (Part 2 of 2 - 34 minutes) | Slides (PPT) | Handout: Service/System Security Plan template (DOC)

Kuai Hinojosa - OWASP MN Mini Conference Introduction - 21 October 2008 (3 minutes)

Upcoming Events

Secure360

Secure360 is an annual conference providing high quality educational sessions and networking opportunities while working to identify developing trends in risk management, physical security, governance, audit, information security, contingency planning and human capital.

DC612 meetings

DC612 meets the 2nd Thursday of the month
http://www.dc612.org/

Minneapolis - Saint Paul OWASP Board Members

President: Kuai Hinojosa
Vice President: Lorna Alamri
Secretary: Sam Buchanan