This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "OWASP ESAPI AppSecDC"

From OWASP
Jump to: navigation, search
Line 2: Line 2:
  
 
[[Image:JeffWilliams2.jpg|200px|thumb|right|Jeff Williams]]
 
[[Image:JeffWilliams2.jpg|200px|thumb|right|Jeff Williams]]
In an enterprise with hundreds or thousands of applications, securing one at a time is too expensive and takes too long. The goal of this session is to identify the strategies that most cost-effectively reduce risk over time. How do we craft an effective application security program using a combination of tools, standard controls, consultants, in-house teams, testers and auditors, and training. How can we manage the cost and risk over time – what metrics have proven to be effective in practice?
+
Application security is arguably the most difficult IT challenge facing organizations today. Chasing the 700 types of common weaknesses with scanners and static analysis is a losing proposition. Rather than chasing after these vulnerabilities, developers can address almost all of these problems with a set of 10 to 12 strong centralized security controls. To make it easier for developers to establish these controls, the Open Web Application Security Project (OWASP) Enterprise Security API (ESAPI) project has created a clean, intuitive, and open-source set of security controls across the most popular web platforms, including Java, .NET, PHP, Python, Cold Fusion, and ASP.NET. In this talk, Jeff will show you how to create an ESAPI for your organization that will solve the OWASP Top Ten vulnerabilities, increase assurance, and dramatically development and verification cut costs all at the same time.
 +
 
 +
 
  
 
== The speaker ==
 
== The speaker ==
Jeff Williams is the founder and CEO of [http://www.aspectsecurity.com/ Aspect Security], specializing exclusively in application security professional services. Jeff also serves as the volunteer Chair of the [http://www.owasp.org/ Open Web Application Security Project (OWASP)]. He has made extensive contributions to the application security community through OWASP, including writing the [[topten|Top Ten]], [[WebGoat]], [[legal|Secure Software Contract Annex]], [[ESAPI|Enterprise Security API]], [[OWASP Risk Rating Methodology]], and starting the worldwide [[chapters|local chapters program]]. If nothing else, Jeff is probably the tallest application security expert in the world and likes nothing better than discussing new ideas for changing the way we build software.
+
Jeff Williams ([[User:Jeff Williams|full bio]]) is the founder and CEO of [http://www.aspectsecurity.com/ Aspect Security], specializing exclusively in application security professional services. Jeff also serves as the volunteer Chair of the [http://www.owasp.org/ Open Web Application Security Project (OWASP)]. He has made extensive contributions to the application security community through OWASP, including writing the [[topten|Top Ten]], [[WebGoat]], [[legal|Secure Software Contract Annex]], [[ESAPI|Enterprise Security API]], [[OWASP Risk Rating Methodology]], and starting the worldwide [[chapters|local chapters program]]. If nothing else, Jeff is probably the tallest application security expert in the world and likes nothing better than discussing new ideas for changing the way we build software.
  
 
[[Category:OWASP_AppSec_DC_09]][[Category:OWASP_Conference_Presentations]]
 
[[Category:OWASP_AppSec_DC_09]][[Category:OWASP_Conference_Presentations]]

Revision as of 20:39, 11 November 2009

The presentation

Jeff Williams

Application security is arguably the most difficult IT challenge facing organizations today. Chasing the 700 types of common weaknesses with scanners and static analysis is a losing proposition. Rather than chasing after these vulnerabilities, developers can address almost all of these problems with a set of 10 to 12 strong centralized security controls. To make it easier for developers to establish these controls, the Open Web Application Security Project (OWASP) Enterprise Security API (ESAPI) project has created a clean, intuitive, and open-source set of security controls across the most popular web platforms, including Java, .NET, PHP, Python, Cold Fusion, and ASP.NET. In this talk, Jeff will show you how to create an ESAPI for your organization that will solve the OWASP Top Ten vulnerabilities, increase assurance, and dramatically development and verification cut costs all at the same time.


The speaker

Jeff Williams (full bio) is the founder and CEO of Aspect Security, specializing exclusively in application security professional services. Jeff also serves as the volunteer Chair of the Open Web Application Security Project (OWASP). He has made extensive contributions to the application security community through OWASP, including writing the Top Ten, WebGoat, Secure Software Contract Annex, Enterprise Security API, OWASP Risk Rating Methodology, and starting the worldwide local chapters program. If nothing else, Jeff is probably the tallest application security expert in the world and likes nothing better than discussing new ideas for changing the way we build software.