SlideShare a Scribd company logo
1 of 20
Download to read offline
OpenSAMM in the Real World:
                      Pitfalls Discovered and Treasure
                          Collected Along the Way
                      Philip J. Beyer - Texas Education Agency
                                    philip.beyer@tea.state.tx.us   @pjbeyer
                                    Scott Stevens - Denim Group
                                          sstevens@denimgroup.com



Copyright 2011 by Texas Education
Agency. All rights reserved.                        LASCON 2011               http://lanyrd.com/shgmf   1
Overview
•     Background
•     The Manual
•     The Premise
•     Treasures and Pitfalls
•     Game Over




Copyright 2011 by Texas Education
Agency. All rights reserved.          LASCON 2011   http://lanyrd.com/shgmf   2
About
• Phil Beyer
         – Information Security Officer
         – Consulting background
• Scott Stevens
         – Project Manager
         – Application development background
• TEA
         – ~700 employees
         – ~1200 school districts
         – ~5 million students

Copyright 2011 by Texas Education
Agency. All rights reserved.        LASCON 2011   http://lanyrd.com/shgmf   3
Where Did TEA Start?
• Application Security Program already
  established
         – Some policies & procedures
         – Initial training & exposure to concepts
         – Historically siloed approach
• Outsourcing for subject matter expertise



Copyright 2011 by Texas Education
Agency. All rights reserved.            LASCON 2011   http://lanyrd.com/shgmf   4
Where Do You Start?
•     Establish your Application Security Program
•     Be the Champion (or find one)
•     Make sure your Team Gets It
•     Have a Roadmap to Maturity




Copyright 2011 by Texas Education
Agency. All rights reserved.               LASCON 2011   http://lanyrd.com/shgmf   5
The Manual
                                    Business Functions




Copyright 2011 by Texas Education
Agency. All rights reserved.               LASCON 2011   http://lanyrd.com/shgmf   6
The Manual
                                    Security Practices




Copyright 2011 by Texas Education
Agency. All rights reserved.              LASCON 2011    http://lanyrd.com/shgmf   7
The Manual
               Phases
1. The Early Levels
2. Racking Up Some
   Points
3. Hitting Your Stride
4. Bigger Treasures,
   Deeper Pits
    The End Game

Copyright 2011 by Texas Education
Agency. All rights reserved.
The Premise
• It has already started
• Shortcuts don’t exist
         – No cheat codes
         – No invincibility
         – No God mode
• There are Pitfalls
• There are Treasures

Copyright 2011 by Texas Education
Agency. All rights reserved.           LASCON 2011   http://lanyrd.com/shgmf   9
The Early Levels (Phase 1)
                                    Treasures
• A Map
         – Not necessarily THE Map, but
           something to get started
         – An organizational roadmap is a
           powerful thing
• Some Running Room
         – Awareness in the organization is
           increasing


Copyright 2011 by Texas Education                    http://lanyrd.com/shgmf
                                      LASCON 2011
Agency. All rights reserved.                                              10
The Early Levels (Phase 1)
                                     Pitfalls
• The Log
         – You can’t stand still
         – Move through Phase 1 so you
           don’t get rolled over
• Inertia
         – Getting started is just plain hard
         – Determining who should play is
           also hard

Copyright 2011 by Texas Education                    http://lanyrd.com/shgmf
                                      LASCON 2011
Agency. All rights reserved.                                              11
Racking Up Some Points (Phase 2)
                      Treasures
• Silver Bars
         – Development teams begin to
           appreciate the security problem


• The Ladder
         – More of the team is involved in
           practicing security
         – You’ve found a new way around
           the alligator-infested pond
Copyright 2011 by Texas Education                 http://lanyrd.com/shgmf
                                    LASCON 2011
Agency. All rights reserved.                                           12
Racking Up Some Points (Phase 2)
                       Pitfalls
• The Alligator
         – There’s a dangerous thing there
           on the screen
         – Threats are real, and now they
           see some of them too
• More Players
         – Other people are going to play
           your game
         – They may not play as { nice |
           carefully | safely } as you
Copyright 2011 by Texas Education                 http://lanyrd.com/shgmf
                                    LASCON 2011
Agency. All rights reserved.                                           13
Hitting Your Stride (Phase 3)
                                 Treasures
• Gold Bars
         – Better visibility instills confidence
           in Management
• The Compass
         – The Program has direction
         – From requirements to
           maintenance, a formal process
           starts to emerge


Copyright 2011 by Texas Education                  http://lanyrd.com/shgmf
                                    LASCON 2011
Agency. All rights reserved.                                            14
Hitting Your Stride (Phase 3)
                                  Pitfalls
• The Scorpion
         – Better informed Management
           may sting
• The Wall
         – A different kind of obstacle will
           block your path
         – Developers and Operators may
           not enjoy working together
           more closely
Copyright 2011 by Texas Education                 http://lanyrd.com/shgmf
                                    LASCON 2011
Agency. All rights reserved.                                           15
Bigger Treasures, Deeper Pits (Phase 4)
              Treasures
• The Bridge
         – Get rid of that Rope and jeer at
           the Alligators as you walk across
         – The whole Program is working
           together to build securely and
           verify aggressively




Copyright 2011 by Texas Education                 http://lanyrd.com/shgmf
                                    LASCON 2011
Agency. All rights reserved.                                           16
Bigger Treasures, Deeper Pits (Phase 4)
                Pitfalls
• The Hole
         – Compliance is not Security
         – Don’t let Management fall into the
           trap at this stage of the game… It
           can be a pretty deep pit




Copyright 2011 by Texas Education                 http://lanyrd.com/shgmf
                                    LASCON 2011
Agency. All rights reserved.                                           17
The End Game (Phases 5 & 6)
                             Treasures
• Shangri-La
         – You’ve reached the mystical,
           harmonious valley; a
           permanently happy land
           isolated from the outside world
         – I’d tell you how it feels, but we
           haven’t gotten there yet



Copyright 2011 by Texas Education                 http://lanyrd.com/shgmf
                                    LASCON 2011
Agency. All rights reserved.                                           18
It’s Time to Play
• Build a Mature Software Assurance Program
• Measure and Report Your Progress
• Have Fun!




Copyright 2011 by Texas Education                       http://lanyrd.com/shgmf
                                          LASCON 2011
Agency. All rights reserved.                                                 19
Resources
• OWASP – Open Web Application Security Project
         – http://www.owasp.org/
• OpenSAMM - Software Assurance Maturity Model
         – http://www.opensamm.org/

• Attribution
         – All OpenSAMM images are licensed under the Creative Commons
           Attribution-Share Alike 3.0 License.



Copyright 2011 by Texas Education                            http://lanyrd.com/shgmf
                                      LASCON 2011
Agency. All rights reserved.                                                      20

More Related Content

More from Philip Beyer

Choose to Lead: The Information Security Profession Needs You!
Choose to Lead: The Information Security Profession Needs You!Choose to Lead: The Information Security Profession Needs You!
Choose to Lead: The Information Security Profession Needs You!Philip Beyer
 
Risk Explained... in 5 Minutes or Less
Risk Explained... in 5 Minutes or LessRisk Explained... in 5 Minutes or Less
Risk Explained... in 5 Minutes or LessPhilip Beyer
 
The Myth of a Perfect Security Program ... The Reality of Eternal Life
The Myth of a Perfect Security Program ... The Reality of Eternal LifeThe Myth of a Perfect Security Program ... The Reality of Eternal Life
The Myth of a Perfect Security Program ... The Reality of Eternal LifePhilip Beyer
 
(Consulting) Couch to CISO: A Security Leader's First 100 Days and Beyond
(Consulting) Couch to CISO: A Security Leader's First 100 Days and Beyond(Consulting) Couch to CISO: A Security Leader's First 100 Days and Beyond
(Consulting) Couch to CISO: A Security Leader's First 100 Days and BeyondPhilip Beyer
 
Secure SDLC in the Real World: Pitfalls Discovered and Treasure Collected Alo...
Secure SDLC in the Real World: Pitfalls Discovered and Treasure Collected Alo...Secure SDLC in the Real World: Pitfalls Discovered and Treasure Collected Alo...
Secure SDLC in the Real World: Pitfalls Discovered and Treasure Collected Alo...Philip Beyer
 
Lean and (Prepared for) Mean: Application Security Program Essentials
Lean and (Prepared for) Mean: Application Security Program EssentialsLean and (Prepared for) Mean: Application Security Program Essentials
Lean and (Prepared for) Mean: Application Security Program EssentialsPhilip Beyer
 

More from Philip Beyer (6)

Choose to Lead: The Information Security Profession Needs You!
Choose to Lead: The Information Security Profession Needs You!Choose to Lead: The Information Security Profession Needs You!
Choose to Lead: The Information Security Profession Needs You!
 
Risk Explained... in 5 Minutes or Less
Risk Explained... in 5 Minutes or LessRisk Explained... in 5 Minutes or Less
Risk Explained... in 5 Minutes or Less
 
The Myth of a Perfect Security Program ... The Reality of Eternal Life
The Myth of a Perfect Security Program ... The Reality of Eternal LifeThe Myth of a Perfect Security Program ... The Reality of Eternal Life
The Myth of a Perfect Security Program ... The Reality of Eternal Life
 
(Consulting) Couch to CISO: A Security Leader's First 100 Days and Beyond
(Consulting) Couch to CISO: A Security Leader's First 100 Days and Beyond(Consulting) Couch to CISO: A Security Leader's First 100 Days and Beyond
(Consulting) Couch to CISO: A Security Leader's First 100 Days and Beyond
 
Secure SDLC in the Real World: Pitfalls Discovered and Treasure Collected Alo...
Secure SDLC in the Real World: Pitfalls Discovered and Treasure Collected Alo...Secure SDLC in the Real World: Pitfalls Discovered and Treasure Collected Alo...
Secure SDLC in the Real World: Pitfalls Discovered and Treasure Collected Alo...
 
Lean and (Prepared for) Mean: Application Security Program Essentials
Lean and (Prepared for) Mean: Application Security Program EssentialsLean and (Prepared for) Mean: Application Security Program Essentials
Lean and (Prepared for) Mean: Application Security Program Essentials
 

Recently uploaded

04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptxHampshireHUG
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Scriptwesley chun
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processorsdebabhi2
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonetsnaman860154
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...Martijn de Jong
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationRadu Cotescu
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking MenDelhi Call girls
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsMaria Levchenko
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdfhans926745
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfEnterprise Knowledge
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityPrincipled Technologies
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024The Digital Insurer
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Drew Madelung
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century educationjfdjdjcjdnsjd
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsJoaquim Jorge
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking MenDelhi Call girls
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)wesley chun
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreternaman860154
 

Recently uploaded (20)

04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 

OpenSAMM in the Real World: Pitfalls Discovered and Treasures Collected Along the Way

  • 1. OpenSAMM in the Real World: Pitfalls Discovered and Treasure Collected Along the Way Philip J. Beyer - Texas Education Agency philip.beyer@tea.state.tx.us @pjbeyer Scott Stevens - Denim Group sstevens@denimgroup.com Copyright 2011 by Texas Education Agency. All rights reserved. LASCON 2011 http://lanyrd.com/shgmf 1
  • 2. Overview • Background • The Manual • The Premise • Treasures and Pitfalls • Game Over Copyright 2011 by Texas Education Agency. All rights reserved. LASCON 2011 http://lanyrd.com/shgmf 2
  • 3. About • Phil Beyer – Information Security Officer – Consulting background • Scott Stevens – Project Manager – Application development background • TEA – ~700 employees – ~1200 school districts – ~5 million students Copyright 2011 by Texas Education Agency. All rights reserved. LASCON 2011 http://lanyrd.com/shgmf 3
  • 4. Where Did TEA Start? • Application Security Program already established – Some policies & procedures – Initial training & exposure to concepts – Historically siloed approach • Outsourcing for subject matter expertise Copyright 2011 by Texas Education Agency. All rights reserved. LASCON 2011 http://lanyrd.com/shgmf 4
  • 5. Where Do You Start? • Establish your Application Security Program • Be the Champion (or find one) • Make sure your Team Gets It • Have a Roadmap to Maturity Copyright 2011 by Texas Education Agency. All rights reserved. LASCON 2011 http://lanyrd.com/shgmf 5
  • 6. The Manual Business Functions Copyright 2011 by Texas Education Agency. All rights reserved. LASCON 2011 http://lanyrd.com/shgmf 6
  • 7. The Manual Security Practices Copyright 2011 by Texas Education Agency. All rights reserved. LASCON 2011 http://lanyrd.com/shgmf 7
  • 8. The Manual Phases 1. The Early Levels 2. Racking Up Some Points 3. Hitting Your Stride 4. Bigger Treasures, Deeper Pits The End Game Copyright 2011 by Texas Education Agency. All rights reserved.
  • 9. The Premise • It has already started • Shortcuts don’t exist – No cheat codes – No invincibility – No God mode • There are Pitfalls • There are Treasures Copyright 2011 by Texas Education Agency. All rights reserved. LASCON 2011 http://lanyrd.com/shgmf 9
  • 10. The Early Levels (Phase 1) Treasures • A Map – Not necessarily THE Map, but something to get started – An organizational roadmap is a powerful thing • Some Running Room – Awareness in the organization is increasing Copyright 2011 by Texas Education http://lanyrd.com/shgmf LASCON 2011 Agency. All rights reserved. 10
  • 11. The Early Levels (Phase 1) Pitfalls • The Log – You can’t stand still – Move through Phase 1 so you don’t get rolled over • Inertia – Getting started is just plain hard – Determining who should play is also hard Copyright 2011 by Texas Education http://lanyrd.com/shgmf LASCON 2011 Agency. All rights reserved. 11
  • 12. Racking Up Some Points (Phase 2) Treasures • Silver Bars – Development teams begin to appreciate the security problem • The Ladder – More of the team is involved in practicing security – You’ve found a new way around the alligator-infested pond Copyright 2011 by Texas Education http://lanyrd.com/shgmf LASCON 2011 Agency. All rights reserved. 12
  • 13. Racking Up Some Points (Phase 2) Pitfalls • The Alligator – There’s a dangerous thing there on the screen – Threats are real, and now they see some of them too • More Players – Other people are going to play your game – They may not play as { nice | carefully | safely } as you Copyright 2011 by Texas Education http://lanyrd.com/shgmf LASCON 2011 Agency. All rights reserved. 13
  • 14. Hitting Your Stride (Phase 3) Treasures • Gold Bars – Better visibility instills confidence in Management • The Compass – The Program has direction – From requirements to maintenance, a formal process starts to emerge Copyright 2011 by Texas Education http://lanyrd.com/shgmf LASCON 2011 Agency. All rights reserved. 14
  • 15. Hitting Your Stride (Phase 3) Pitfalls • The Scorpion – Better informed Management may sting • The Wall – A different kind of obstacle will block your path – Developers and Operators may not enjoy working together more closely Copyright 2011 by Texas Education http://lanyrd.com/shgmf LASCON 2011 Agency. All rights reserved. 15
  • 16. Bigger Treasures, Deeper Pits (Phase 4) Treasures • The Bridge – Get rid of that Rope and jeer at the Alligators as you walk across – The whole Program is working together to build securely and verify aggressively Copyright 2011 by Texas Education http://lanyrd.com/shgmf LASCON 2011 Agency. All rights reserved. 16
  • 17. Bigger Treasures, Deeper Pits (Phase 4) Pitfalls • The Hole – Compliance is not Security – Don’t let Management fall into the trap at this stage of the game… It can be a pretty deep pit Copyright 2011 by Texas Education http://lanyrd.com/shgmf LASCON 2011 Agency. All rights reserved. 17
  • 18. The End Game (Phases 5 & 6) Treasures • Shangri-La – You’ve reached the mystical, harmonious valley; a permanently happy land isolated from the outside world – I’d tell you how it feels, but we haven’t gotten there yet Copyright 2011 by Texas Education http://lanyrd.com/shgmf LASCON 2011 Agency. All rights reserved. 18
  • 19. It’s Time to Play • Build a Mature Software Assurance Program • Measure and Report Your Progress • Have Fun! Copyright 2011 by Texas Education http://lanyrd.com/shgmf LASCON 2011 Agency. All rights reserved. 19
  • 20. Resources • OWASP – Open Web Application Security Project – http://www.owasp.org/ • OpenSAMM - Software Assurance Maturity Model – http://www.opensamm.org/ • Attribution – All OpenSAMM images are licensed under the Creative Commons Attribution-Share Alike 3.0 License. Copyright 2011 by Texas Education http://lanyrd.com/shgmf LASCON 2011 Agency. All rights reserved. 20