This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Summit 2011 Working Sessions/Session094

From OWASP
Revision as of 01:49, 9 February 2011 by Jeremy Dallman (talk | contribs) (note to attendees)

Jump to: navigation, search

Global Summit 2011 Home Page
Global Summit 2011 Tracks

WS. mitigation.jpg Microsoft's SDL in 16 steps (and lessons learned)
Please see/use the 'discussion' page for more details about this Working Session
Working Sessions Operational Rules - Please see here the general frame of rules.
WORKING SESSION IDENTIFICATION
Short Work Session Description

[[NOTICE FROM JEREMY DALLMAN: Unfortnately this session was added late in the OWASP Summit planning and the technical resources have not been put in place to accomodate me managing the conversation remotely. My sincerest apologies for the late notice, but we are going to have to postpone this conversation until a later event. I look forward to that time. If you would like to contact me directly, please email me at [email protected]. thank you.]]

This OWASP Working Session will explore the Simplified SDL and its 16 security practices implementation guidance (see reference materials below). The Simplified SDL is a platform-agnostic process for implementing proven application security practices in any size organization. This working group will discuss the feasibility of creating one or more practical, platform-specific resource libraries for each of the security practices in the 16 steps of the Simplified SDL. Further, we will discuss prioritization of the 16 Practices for organizations implementing security in an incremental fashion.

Related Projects (if any)


Email Contacts & Roles Chair
Jeremy Dallman @

Operational Manager
Mailing list
Subscription Page
WORKING SESSION SPECIFICS
Objectives
  1. Discuss additional reference materials and identifying publicly-available tools targeting a variety of platforms (web, OSX, Unix, mobile platforms, etc) in an effort to provide practical, platform-specific implementation guidance for each of the security practices in the 16 Steps of the Simplified SDL.
  2. Define the practical “crawl/walk/run” steps for adopting the 16 Practices of the Simplified SDL for development organizations of any size.

Venue/Date&Time/Model Venue/Room
OWASP Global Summit Portugal 2011
Date & Time


Discussion Model
participants and attendees

WORKING SESSION OPERATIONAL RESOURCES
Projector, whiteboards, markers, Internet connectivity, power

WORKING SESSION ADDITIONAL DETAILS
Reference materials: Simplified SDL paper & 16 Steps blog post.
WORKING SESSION OUTCOMES / DELIVERABLES
Proposed by Working Group Approved by OWASP Board

Identify 1-2 target platforms and potential locations for a library of platform-specific guidance and tools associated with each of the 16 practices of the Simplified SDL.

After the Board Meeting - fill in here.

Identify OWASP contributors who are willing to help build the content for #1.

After the Board Meeting - fill in here.

Define the practical “crawl/walk/run” steps for adopting the 16 Practices of the Simplified SDL for development organizations of any size.

After the Board Meeting - fill in here.

After the Board Meeting - fill in here.

After the Board Meeting - fill in here.

After the Board Meeting - fill in here.

After the Board Meeting - fill in here.

After the Board Meeting - fill in here.

Working Session Participants

(Add you name by clicking "edit" on the tab on the upper left side of this page)

WORKING SESSION PARTICIPANTS
Name Company Notes & reason for participating, issues to be discussed/addressed
Tony UcedaVelez @
VerSprite

John Menerick @
NetSuite
(remote)
Daniel Brzozowski @


Alexandre Miguel Aniceto @
Willway