This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "Summit 2011 Working Sessions/Session085"

From OWASP
Jump to: navigation, search
 
(6 intermediate revisions by 3 users not shown)
Line 2: Line 2:
 
|-
 
|-
  
| summit_session_attendee_name1 =  
+
| summit_session_attendee_name1 = Lucas C. Ferreira
| summit_session_attendee_email1 =  
+
| summit_session_attendee_email1 = [email protected]
| summit_session_attendee_username1 =  
+
| summit_session_attendee_username1 = sapao
 
| summit_session_attendee_company1=
 
| summit_session_attendee_company1=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed1=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed1=
  
| summit_session_attendee_name2 =  
+
| summit_session_attendee_name2 = Vlatko Kosturjak
| summit_session_attendee_email2 =  
+
| summit_session_attendee_email2 = [email protected]
| summit_session_attendee_username2 =  
+
| summit_session_attendee_username2 = kost
 
| summit_session_attendee_company2=
 
| summit_session_attendee_company2=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed2=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed2=
Line 131: Line 131:
  
 
| short_working_session_description=
 
| short_working_session_description=
 +
The purpose of this session is to bring together the various document project leaders and other interested parties to discuss the establishment of a common document numbering system. This will also require that applicable document projects have a similar structure, at least in the areas associated with the numbering. That means this session will drive revisions to current projects. Additionally, this is an opportunity to discuss the overall alignment of the release document projects and how they fit into a secure development life cycle.
 +
 +
Some of the document projects that would benefit from this activity include the following, but there are several others not listed :
 +
*[[OWASP Secure Coding Practices - Quick Reference Guide|OWASP Secure Coding Practices - Quick Reference Guide]].........(What to do - Requirements),
 +
*[[OWASP Guide Project|OWASP Development Guide]].......................................(How to do it – Coding guidance),
 +
*[[:Category:OWASP Ruby on Rails Security Guide V2|OWASP Ruby on Rails Security Guide V2]].........................(How to do it – Ruby specific),
 +
*[[OWASP Testing Project|OWASP Testing Guide]]...........................................(How to test it – Pen Testing),
 +
*[[:Category:OWASP Code Review Project|OWASP Code Review Guide]].......................................( How to test it – Code Review),
 +
*[[:Category:OWASP Application Security Verification Standard Project|OWASP Application Security Verification Standard Project]]......(Verify and rate what was done),
  
 
|-
 
|-
Line 151: Line 160:
 
|-
 
|-
  
| summit_session_objective_name1=  
+
| summit_session_objective_name1 = Discuss and review current document project structures and key elements.
  
| summit_session_objective_name2 =  
+
| summit_session_objective_name2 = Review proposal to align to ASVS and discuss whether the current version of ASVS provides an adequate baseline.
  
| summit_session_objective_name3 =  
+
| summit_session_objective_name3 = Review other options for structure and numbering.
  
| summit_session_objective_name4 =  
+
| summit_session_objective_name4 = Develop a draft structure and numbering plan.
  
| summit_session_objective_name5 =
+
| summit_session_objective_name5 = Discuss any dependencies which may exist, such as common nomenclature and definitions.
  
 
|-
 
|-
Line 183: Line 192:
 
|-
 
|-
  
|summit_session_deliverable_name1 =  
+
|summit_session_deliverable_name1 = A written recommendation for a unified category and numbering system for applicable document projects.
  
|summit_session_deliverable_name2 =  
+
|summit_session_deliverable_name2 = Agreement from applicable document project leaders to adopt the finalized version of the system.
  
|summit_session_deliverable_name3 =  
+
|summit_session_deliverable_name3 = An implementation plan discussing when projects will implement the new system.
  
 
|summit_session_deliverable_name4 =  
 
|summit_session_deliverable_name4 =  
Line 207: Line 216:
 
| summit_session_leader_name2 = Matteo Meucci
 
| summit_session_leader_name2 = Matteo Meucci
 
| summit_session_leader_email2 = [email protected]
 
| summit_session_leader_email2 = [email protected]
| summit_session_leader_username2 =  
+
| summit_session_leader_username2 = Mmeucci
  
 
| summit_session_leader_name3 = Vishal Garg
 
| summit_session_leader_name3 = Vishal Garg
 
| summit_session_leader_email3 = [email protected]
 
| summit_session_leader_email3 = [email protected]
| summit_session_leader_username3 =  
+
| summit_session_leader_username3 = Vishal_Garg
  
 
|-
 
|-
  
| operational_leader_name1 =  
+
| operational_leader_name1 = Jim Manico
| operational_leader_email1 =  
+
| operational_leader_email1 = [email protected]
| operational_leader_username1 =  
+
| operational_leader_username1 = jmanico
  
 
|-
 
|-

Latest revision as of 10:29, 8 February 2011

Global Summit 2011 Home Page
Global Summit 2011 Tracks

WS. metrics.jpg Common structure and numbering for all guides
Please see/use the 'discussion' page for more details about this Working Session
Working Sessions Operational Rules - Please see here the general frame of rules.
WORKING SESSION IDENTIFICATION
Short Work Session Description The purpose of this session is to bring together the various document project leaders and other interested parties to discuss the establishment of a common document numbering system. This will also require that applicable document projects have a similar structure, at least in the areas associated with the numbering. That means this session will drive revisions to current projects. Additionally, this is an opportunity to discuss the overall alignment of the release document projects and how they fit into a secure development life cycle.

Some of the document projects that would benefit from this activity include the following, but there are several others not listed :

Related Projects (if any)


Email Contacts & Roles Chair
Keith Turpin @
Matteo Meucci @
Vishal Garg @
Operational Manager
Jim Manico @
Mailing list
Subscription Page
WORKING SESSION SPECIFICS
Objectives
  1. Discuss and review current document project structures and key elements.
  2. Review proposal to align to ASVS and discuss whether the current version of ASVS provides an adequate baseline.
  3. Review other options for structure and numbering.
  4. Develop a draft structure and numbering plan.
  5. Discuss any dependencies which may exist, such as common nomenclature and definitions.

Venue/Date&Time/Model Venue/Room
OWASP Global Summit Portugal 2011
Date & Time


Discussion Model
participants and attendees

WORKING SESSION OPERATIONAL RESOURCES
Projector, whiteboards, markers, Internet connectivity, power

WORKING SESSION ADDITIONAL DETAILS
The presence on this session of the participants of the Working Sessions below is advisable
WORKING SESSION OUTCOMES / DELIVERABLES
Proposed by Working Group Approved by OWASP Board

A written recommendation for a unified category and numbering system for applicable document projects.

After the Board Meeting - fill in here.

Agreement from applicable document project leaders to adopt the finalized version of the system.

After the Board Meeting - fill in here.

An implementation plan discussing when projects will implement the new system.

After the Board Meeting - fill in here.

After the Board Meeting - fill in here.

After the Board Meeting - fill in here.

After the Board Meeting - fill in here.

After the Board Meeting - fill in here.

After the Board Meeting - fill in here.

Working Session Participants

(Add you name by clicking "edit" on the tab on the upper left side of this page)

WORKING SESSION PARTICIPANTS
Name Company Notes & reason for participating, issues to be discussed/addressed
Lucas C. Ferreira @


Vlatko Kosturjak @