SlideShare une entreprise Scribd logo
1  sur  43
Télécharger pour lire hors ligne
OWASP & More
State of OWASP 2015
https://www.owasp.org
https://2015.appsecusa.org
Twitter: @owasp, @appsecusa
Tobias Gondrom – Board Chair
Paul Ritchie – OWASP Executive Director
Noreen Whysel – OWASP Community Manager
Claudia Casanova – OWASP Project Coordinator
Sept. 24, 2015
State of OWASP
• Welcome: A “brief story” about OWASP
• Updates from our Executive Director,
Community Manager and Projects Coordinator
• Q&A
Who is OWASP?
Free & Open
Governed by rough
consensus & running
code
Abide by a code of
ethics (see ethics)
Not-for-profit
Not driven by
commercial
interests
Risk based approach
Our Purpose & Our Core Values
OPEN: Everything at OWASP is radically
transparent from our finances to our code.
INNOVATION: OWASP encourages and
supports innovation/experiments for
solutions to software security challenges.
GLOBAL: Anyone around the world is
encouraged to participate in the OWASP
community.
INTEGRITY: OWASP is an honest and
truthful, vendor agnostic, global community.
Our Core Values
Our Purpose: The OWASP Foundation will be the thriving global community that
drives visibility and evolution in the safety and security of the world’s software.
Strengthen OWASP chapters and
increase Chapter’s abilities to
spread message of OWASP through
locally organized and run events.
Mature the OWASP Projects
Platform: Provide the OWASP
projects community a mature
project platform to encourage
senior developers to participate in
the various and many OWASP
projects.
Build a scalable OWASP training
program that spreads security
training around the world
Strategic Goals for 2015
130
Active Projects
268
Active Chapters
44,000+
participants mailing lists
88+
Government & Industry Citations!
100+
Academic Supporters
55
Paid Corporate Memberships
2458 Members
Our Strong OWASP Operations Team
• Executive Director: Paul Ritchie
• Operations Director: Kate
Hartmann
• Membership and Business
Liaison: Kelly Santalucia
• Event Manager: Laura Grau
• Projects: Claudia Casanovas
• Community Manager: Noreen
Whysel
• Accounting: Alison Shrader
• IT Admin: Matt Tesauro
(Contractor)
• Graphic Design: Hugo Costa
(Contractor)
13
OWASP – chapter meetings and conferences
around the world
Thanks to our sponsors and supporters:
Contributing
Sponsors:
Premium Sponsors:
OWASP is about you!
Free to use
Free to participate
Free to contribute
Join and help to make the Web, make
the world more secure!
… join a chapter
… join a project
… join the global community list
… share the security knowledge.
Mission
• Our mission is to make software security visible, so
that individuals and organizations worldwide can
make informed decisions about true software
security risks
• How’d we do in 2014? See Annual Report themed
“Growing, Learning, Sharing, Leading”
Strategic Goals & Metrics - 2015
• Chapter Development
• Volunteer Management
• Training
• Supporting & Maturing the Project Platform
• Finances
Chapter Development - 2015
• Our Global Footprint
• 28 New Chapters
• 8 Chapters Restarted
• More Chapter &
Project Leader
Training on Friday
Note Recent
New Chapters
in Africa
Volunteer Management
• Project Review Task Force Actively looking for Volunteers
• Over 25 Co-marketing agreements ‘signed’ with Speaker or
free Booth space at outside event for OWASP Volunteers
• Wiki Volunteer & Initiatives page updated with Volunteer
opportunities at University and 25 Chapter Leader openings
Training – Our Reach is Global
AppSec USA-SF 2015
• 1200 attendees
• 253 Training attendees
• 75+ Speakers
AppSecEU 2015
• 585 attendees
• 133 Training attendees
• 57 Speakers
LATAM 2015
• 724 attendees
• 42 Training attendees
• 70 Speakers
Training – Chapters Gone Wild (w/Training)
• AppSec-California Training 7 classes, 36 registrations
• NYC Hack Day Training 1 class, 19 registrations
• OWASP New Zealand Day 1 class, 12 registrations
• LATAM Tour 6 classes, 42 training attendees
• AppSecEU 13 classes, 133 registrations
• OWASP CONfidence (Krakow) 5 classes, (6 trainers/classes on website)
• OWASP SAMM Summit (Dublin) ~30 registrations, 10 paid
• OWASP Dublin Training Day 3 classes, 78 registrations
• …..And so many more
Project Innovation & Output
• New projects added
• Updates & outputs on 2015
• Project Maturity update
• Project Summit & Summer of Code
• Bossie Award for Open Source Tools
– Highlighted: ZAP, Xenotix XSS, O-Saft, OWTF
Project Highlights – 2015
• 2 Project Summits held during AppSec Conferences to maximize participation
• OWASP’s own Summer Code Sprint hosted to support Projects
• Project Coordinator – Claudia updating the New Project & Project Review process & docs
• CISO Guide translated into Spanish
• Dependancy Check 1.2.9 released
• Dependancy Track 1.0.0 released
• Vicnum Project updated
• OWASP SAMM Project Summit – Dublin March 2015
• AppSensor – CISO Briefing released
• ZAP 2.4.0 released
• ZAP w/Docker introduction released
• ASVS version XX released
• OWASP KALP Mobile Project initiated
• OWASP Seraphimdroid project, version 2 released
OWASP Finances – Overall Strong & Growing
See Annual Report for Details
Full Financial Transparency &
Reports found on the OWASP Wiki
Financial Snapshot
GROWTH 2013 - 2016
Conferences remain excellent channel
for Training & Community sharing
• 65% of Income & 50% of Expenses
Projects / Chapter Funding
represented ~$255K in 2015 with
potential growth to the $300-400K
range in 2016.
26
Project Funding & Chapter Funding
Where’s the Info?
• Need Project Funding?
• Need Chapter Funding?
• Got a Chapter Budget, need
reimbursement?
• Submit here
https://www.owasp.org/index.php
/Funding
OWASP Northern Virginia
@OWASPNoVA
OWASP DC
@OWASPDC
The Big Reveal – AppSec US in 2016
• OWASP AppSec EU 2016: Rome in June
• OWASP AppSec USA 2016:
Washington DC – September
– Hosted by No.Virginia & WashDC Chapters
Community Update
Noreen Whysel
Community Manager
September 24, 2015
Chapter Development
• 28 new chapters started in 2015
• 8 chapters restarted
• 26 chapters inactivated (some in process of restarting)
• 1 merged chapter (Kenya/Nairobi)
• 3 chapter splits (Spain, Argentina, Sweden)
• 53 new leaders added, including restarts
• 120+ cases & conversations with chapter leaders worldwide
Communications
• Community News Flash
• Social Media Announcements
• Mailing Lists
• SalesForce Messaging
• Personal Correspondence
Community News Flash
• First issue April 2015
• Sent to owasp-leaders and owasp-community lists
• Switched to Vertical Response in August 2015
• August 2015
– Sent to: 1,282
– Opens (257): 20.05%
– Clicks (52): 4.06%
– Bounces (13): 1.01%
– Unsubscribes (0): 0.00%
• September 2015
– Sent to: 1,269
– Opens (255): 20.09%
– Clicks (26): 2.05%
– Bounces (3): .24%
– Unsubscribes (1): 0.08%
Social Media
• Twitter (as of 8/31/2015)
– 4014 tweets
– 325 following
– 56,819 followers
• Facebook
– 9,062 Page Likes
– 8,839 Group Members
• LinkedIn
– 22,730 group members
– 12,800 followers
• Slack
– 399 members
– 76 channels
• Meetup
– 54 “OWASP” Meetup
Groups
– 13,328 Members
– 1,416 Expressed Interest
– 50 Cities
– 17 Countries
Chapter Leader Workshops
Room F, Pacific Concourse
• Thurs 10:30AM - People and Capital
• Thurs 11:30AM - I’m a Leader. Now What?
• Friday 10:30AM - What’s In Your Toolbox?
• Friday 11:30AM - OWASP Wiki Edit-a-thon
• Friday afternoon - Flex sessions, continue the conversation
Projects & Initiative Update
Claudia Aviles Casanovas
Project Coordinator
September 20, 2015
Project Task Force Recent Activity
Pending Graduation Review: (Submitted Last Week)
OWASP Security Shepherd
OWASP Seraphimdroid Project
OWASP Security Logging
New Incubator Projects Project Added:
• OWASP ZSC Tool Project
• OWASP Mth3I3m3nt Framework Project
Recent Project that Graduated to the next Level:
• Benchmark Tool Project
Review Results: Moved from Incubator Project To Lab Project
Projects Graduated from Incubator to Lab in June 2015
Category: Documentation
• OWASP Internet of Things To Ten Project
• OWASP Pro Active Controls
• OWASP Top 10 Privacy Risks_Project
• OWASP Reverse Engineering and Code_Modification Prevention
Project
Category: Code
• Mobile Application Security Project
• OWASP Security Python Project
Project Summit USA 2015
Projects Participating:
• OWASP Code Review Guide – Gary Robinson & Larry Coklin
• OWASP ASVS & OWASP Pro Active Controls – Jim Manico
• OWASP Python Security Project – Enrico Branca
• OWASP Security Shepherd – Mark Denihan
• OWASP Security Knowledge – Glenn Ten Cate
• OWASP PodCast – Mark Miller
• OWASP WAFEC (Starting up Activity)– Tony Turner
• OWASP O2 – Michael Hidalgo
Project Summit USA 2015
Project Name Project Leader Did the Project Summit
help your Project?
Did you Accomplish it? Deliverable
OWASP Security Shepherd Mark Denihan
Pol Mac Cana
Updated the GitHub Wiki pages to a
state where new users can easily add
Translation support to Shepherd
components, add new language
tranlations without difficulty and create
new Security Shepherd levels with the
new specifications made in V3. Also
created new Security Shepherd level
templates. Eliminated issues that were
blocking the progress of the Security
Shepherd Docker File.
These last two week’s OWASP Summer Code Sprint 2015 mentors and students have wrapped up
activities.
Originally Received 39 Proposals and were able to select 8 Students for the Summer Code Sprint
2015. The selections was difficult due to competitive proposals.
Results: All 8 Students passed the Final Evaluations.
Feedback & Experience:
• Amazing Performance!
• OWASP Seraphimdroid Project is now able to apply for a Project Review Graduation
due to the work done with the student.
• Project’s quality robustness increased like never over the past 2 months!
• Excellent work and worked beyond the original plan!
• Gained a contributor for the Hackademic Project.
• High level of dedication with excellent results
• Students were happy to work with such great mentors and excited about the projects.
Results Final Evaluations
Fabio Cerullo, Initiative Leader
Summer Code Sprint 2015 Participation
Fabio Cerullo, Initiative Leader
Project Name Mentors Students
OWASP OWTF Abraham Aranguren, Tao Sauvage,
Bharadwaj Machiraju
Arun Sori, Alexandra Sandulescu, Viyat
Bhlalodia
OWASP Seraphimdroid John Melton Kartik Kholic
OWASP APPSensor Nikola Milosevic Sumanth Damaria
OWASP Hackademic Spyros Gasteratos, Paul Chaignon Anirudh Anand, Minhaz AV, Tapasweni
Pathak
Project Updates
• OWASP Project Task Force
• Project Summit USA
• How to Start A New Project
• OWASP Project Dasboard
• OWASP 2014 Project Handbook
– Project Funding Request Form
– Project Spending Policy
Community Q&A
https://www.owasp.org
https//2015.appsecusa.org
Twitter: @owasp, @appsecusa
Open OWASP Board Meeting
Friday, Sep-25, 18:00 – 20:00 PDT
Room A - Pacific Level.
Learn, meet, share and ….
… have a great time!
https//2015.appsecusa.org
Twitter: @appsecusa

Contenu connexe

Tendances

Menofia UN -Mobile Security
Menofia UN -Mobile SecurityMenofia UN -Mobile Security
Menofia UN -Mobile Security
Ahmed Samara
 
Programatori cu capul in nori
Programatori cu capul in noriProgramatori cu capul in nori
Programatori cu capul in nori
Alex Popescu
 
[OWASP Poland Day] Embedding security into SDLC + GDPR
[OWASP Poland Day] Embedding security into SDLC + GDPR[OWASP Poland Day] Embedding security into SDLC + GDPR
[OWASP Poland Day] Embedding security into SDLC + GDPR
OWASP
 

Tendances (20)

CSS 17: NYC - Stories from the SOC
CSS 17: NYC - Stories from the SOCCSS 17: NYC - Stories from the SOC
CSS 17: NYC - Stories from the SOC
 
MultPoint Ltd.company overview 2014 3214 short version
MultPoint Ltd.company overview 2014 3214 short version MultPoint Ltd.company overview 2014 3214 short version
MultPoint Ltd.company overview 2014 3214 short version
 
Menofia UN -Mobile Security
Menofia UN -Mobile SecurityMenofia UN -Mobile Security
Menofia UN -Mobile Security
 
CSS 17: NYC - Realities of Security in the Cloud
CSS 17: NYC - Realities of Security in the CloudCSS 17: NYC - Realities of Security in the Cloud
CSS 17: NYC - Realities of Security in the Cloud
 
Security O365 Using AI-based Advanced Threat Protection
Security O365 Using AI-based Advanced Threat ProtectionSecurity O365 Using AI-based Advanced Threat Protection
Security O365 Using AI-based Advanced Threat Protection
 
Programatori cu capul in nori
Programatori cu capul in noriProgramatori cu capul in nori
Programatori cu capul in nori
 
Outpost24 webinar - Demystifying Web Application Security with Attack Surface...
Outpost24 webinar - Demystifying Web Application Security with Attack Surface...Outpost24 webinar - Demystifying Web Application Security with Attack Surface...
Outpost24 webinar - Demystifying Web Application Security with Attack Surface...
 
CSS 17: NYC - Protecting your Web Applications
CSS 17: NYC - Protecting your Web ApplicationsCSS 17: NYC - Protecting your Web Applications
CSS 17: NYC - Protecting your Web Applications
 
The cyber house of horrors - securing the expanding attack surface
The cyber house of horrors -  securing the expanding attack surfaceThe cyber house of horrors -  securing the expanding attack surface
The cyber house of horrors - securing the expanding attack surface
 
How to Test for The OWASP Top Ten
 How to Test for The OWASP Top Ten How to Test for The OWASP Top Ten
How to Test for The OWASP Top Ten
 
#ALSummit: Cyber Resiliency: Surviving the Breach
#ALSummit: Cyber Resiliency: Surviving the Breach#ALSummit: Cyber Resiliency: Surviving the Breach
#ALSummit: Cyber Resiliency: Surviving the Breach
 
Mitigating the Top 5 Cloud Security Threats
Mitigating the Top 5 Cloud Security ThreatsMitigating the Top 5 Cloud Security Threats
Mitigating the Top 5 Cloud Security Threats
 
Сергей Харюк (Украина). Проверка безопасности приложений на платформе iOS
Сергей Харюк (Украина). Проверка безопасности приложений на платформе iOSСергей Харюк (Украина). Проверка безопасности приложений на платформе iOS
Сергей Харюк (Украина). Проверка безопасности приложений на платформе iOS
 
Network Security in 2016
Network Security in 2016Network Security in 2016
Network Security in 2016
 
[OWASP Poland Day] Embedding security into SDLC + GDPR
[OWASP Poland Day] Embedding security into SDLC + GDPR[OWASP Poland Day] Embedding security into SDLC + GDPR
[OWASP Poland Day] Embedding security into SDLC + GDPR
 
Data encryption for Ruby web applications - Dmytro Shapovalov (RUS) | Ruby Me...
Data encryption for Ruby web applications - Dmytro Shapovalov (RUS) | Ruby Me...Data encryption for Ruby web applications - Dmytro Shapovalov (RUS) | Ruby Me...
Data encryption for Ruby web applications - Dmytro Shapovalov (RUS) | Ruby Me...
 
Andrew Useckas Csa presentation hacking custom webapps 4 3
Andrew Useckas Csa presentation   hacking custom webapps 4 3Andrew Useckas Csa presentation   hacking custom webapps 4 3
Andrew Useckas Csa presentation hacking custom webapps 4 3
 
Cyber Resiliency
Cyber ResiliencyCyber Resiliency
Cyber Resiliency
 
Journey to the Cloud: Securing Your AWS Applications - April 2015
Journey to the Cloud: Securing Your AWS Applications - April 2015Journey to the Cloud: Securing Your AWS Applications - April 2015
Journey to the Cloud: Securing Your AWS Applications - April 2015
 
Wrangle 2016: Seeing Behaviors as Humans Do: Uncovering Hidden Patterns in Ti...
Wrangle 2016: Seeing Behaviors as Humans Do: Uncovering Hidden Patterns in Ti...Wrangle 2016: Seeing Behaviors as Humans Do: Uncovering Hidden Patterns in Ti...
Wrangle 2016: Seeing Behaviors as Humans Do: Uncovering Hidden Patterns in Ti...
 

En vedette

En vedette (20)

Owasp top-ten-mapping-2015-05-lwc
Owasp top-ten-mapping-2015-05-lwcOwasp top-ten-mapping-2015-05-lwc
Owasp top-ten-mapping-2015-05-lwc
 
Web hackingtools 2015
Web hackingtools 2015Web hackingtools 2015
Web hackingtools 2015
 
Appsecurity, win or loose
Appsecurity, win or looseAppsecurity, win or loose
Appsecurity, win or loose
 
OWASP AppSec USA 2015, San Francisco
OWASP AppSec USA 2015, San FranciscoOWASP AppSec USA 2015, San Francisco
OWASP AppSec USA 2015, San Francisco
 
OWASP Top 10 Proactive Controls
OWASP Top 10 Proactive ControlsOWASP Top 10 Proactive Controls
OWASP Top 10 Proactive Controls
 
OWASP 2015 AppSec EU ZAP 2.4.0 and beyond..
OWASP 2015 AppSec EU ZAP 2.4.0 and beyond..OWASP 2015 AppSec EU ZAP 2.4.0 and beyond..
OWASP 2015 AppSec EU ZAP 2.4.0 and beyond..
 
Rebooting Software Development - OWASP AppSecUSA
Rebooting Software Development - OWASP AppSecUSA Rebooting Software Development - OWASP AppSecUSA
Rebooting Software Development - OWASP AppSecUSA
 
Web Application Security | A developer's perspective - Insecure Direct Object...
Web Application Security | A developer's perspective - Insecure Direct Object...Web Application Security | A developer's perspective - Insecure Direct Object...
Web Application Security | A developer's perspective - Insecure Direct Object...
 
Owasp Au Rev4
Owasp Au Rev4Owasp Au Rev4
Owasp Au Rev4
 
OWASP Top 10 A4 – Insecure Direct Object Reference
OWASP Top 10 A4 – Insecure Direct Object ReferenceOWASP Top 10 A4 – Insecure Direct Object Reference
OWASP Top 10 A4 – Insecure Direct Object Reference
 
Owasp top 10 security threats
Owasp top 10 security threatsOwasp top 10 security threats
Owasp top 10 security threats
 
OWASP OWTF - Summer Storm - OWASP AppSec EU 2013
OWASP OWTF - Summer Storm - OWASP AppSec EU 2013OWASP OWTF - Summer Storm - OWASP AppSec EU 2013
OWASP OWTF - Summer Storm - OWASP AppSec EU 2013
 
OWASP Free Training - SF2014 - Keary and Manico
OWASP Free Training - SF2014 - Keary and ManicoOWASP Free Training - SF2014 - Keary and Manico
OWASP Free Training - SF2014 - Keary and Manico
 
RSA Europe 2013 OWASP Training
RSA Europe 2013 OWASP TrainingRSA Europe 2013 OWASP Training
RSA Europe 2013 OWASP Training
 
OWASP Top Ten in Practice
OWASP Top Ten in PracticeOWASP Top Ten in Practice
OWASP Top Ten in Practice
 
OWASP Open SAMM
OWASP Open SAMMOWASP Open SAMM
OWASP Open SAMM
 
2013 OWASP Top 10
2013 OWASP Top 102013 OWASP Top 10
2013 OWASP Top 10
 
Basic of SSDLC
Basic of SSDLCBasic of SSDLC
Basic of SSDLC
 
The OWASP Zed Attack Proxy
The OWASP Zed Attack ProxyThe OWASP Zed Attack Proxy
The OWASP Zed Attack Proxy
 
[Wroclaw #5] OWASP Projects: beyond Top 10
[Wroclaw #5] OWASP Projects: beyond Top 10[Wroclaw #5] OWASP Projects: beyond Top 10
[Wroclaw #5] OWASP Projects: beyond Top 10
 

Similaire à State of OWASP 2015

Similaire à State of OWASP 2015 (20)

AppSecUSA 2015 Chapter Leader Workshops
AppSecUSA 2015 Chapter Leader WorkshopsAppSecUSA 2015 Chapter Leader Workshops
AppSecUSA 2015 Chapter Leader Workshops
 
Managing Experimentation in a Continuously Deployed Environment
Managing Experimentation in a Continuously Deployed EnvironmentManaging Experimentation in a Continuously Deployed Environment
Managing Experimentation in a Continuously Deployed Environment
 
E-Learning -The Future: Developing Regional E-Learning Materials by Partnerin...
E-Learning -The Future: Developing Regional E-Learning Materials by Partnerin...E-Learning -The Future: Developing Regional E-Learning Materials by Partnerin...
E-Learning -The Future: Developing Regional E-Learning Materials by Partnerin...
 
Introduction & trends - Journal Publishing in SA
Introduction & trends - Journal Publishing in SAIntroduction & trends - Journal Publishing in SA
Introduction & trends - Journal Publishing in SA
 
Year 2015
Year 2015Year 2015
Year 2015
 
OpenStack 2015 Marketing Plan
OpenStack 2015 Marketing PlanOpenStack 2015 Marketing Plan
OpenStack 2015 Marketing Plan
 
Better Software, Better Practices, Better Research
Better Software, Better Practices, Better ResearchBetter Software, Better Practices, Better Research
Better Software, Better Practices, Better Research
 
Oslo Innovation Week 2016 Event Organizers Meet-up
Oslo Innovation Week 2016 Event Organizers Meet-upOslo Innovation Week 2016 Event Organizers Meet-up
Oslo Innovation Week 2016 Event Organizers Meet-up
 
Wikis Are Wonderful - Or Are They
Wikis Are Wonderful - Or Are TheyWikis Are Wonderful - Or Are They
Wikis Are Wonderful - Or Are They
 
The Agile and Open Source Way (AgileTour Brussels)
The Agile and Open Source Way (AgileTour Brussels)The Agile and Open Source Way (AgileTour Brussels)
The Agile and Open Source Way (AgileTour Brussels)
 
An introduction to weADAPT
An introduction to weADAPT An introduction to weADAPT
An introduction to weADAPT
 
DevOps maturity models Knowit and DASA
DevOps maturity models Knowit and DASADevOps maturity models Knowit and DASA
DevOps maturity models Knowit and DASA
 
UKSG Conference 2016 Breakout Session - Jisc open access services to support ...
UKSG Conference 2016 Breakout Session - Jisc open access services to support ...UKSG Conference 2016 Breakout Session - Jisc open access services to support ...
UKSG Conference 2016 Breakout Session - Jisc open access services to support ...
 
Enabling DevOps for enterprise
Enabling DevOps for enterpriseEnabling DevOps for enterprise
Enabling DevOps for enterprise
 
Webinar: Role of Open Source in the Digital Journey
Webinar: Role of Open Source in the Digital JourneyWebinar: Role of Open Source in the Digital Journey
Webinar: Role of Open Source in the Digital Journey
 
Experiences with the Apache Software Foundation
Experiences with the Apache Software Foundation Experiences with the Apache Software Foundation
Experiences with the Apache Software Foundation
 
Laimonas Lileika - Hybrid Project Management: Excellence Behind a Buzzword
Laimonas Lileika - Hybrid Project Management: Excellence Behind a BuzzwordLaimonas Lileika - Hybrid Project Management: Excellence Behind a Buzzword
Laimonas Lileika - Hybrid Project Management: Excellence Behind a Buzzword
 
R consortium update EARL London Sept 2017
R consortium update EARL London Sept 2017R consortium update EARL London Sept 2017
R consortium update EARL London Sept 2017
 
R Consortium update for EARL Boston Oct 2017
R Consortium update for EARL Boston Oct 2017R Consortium update for EARL Boston Oct 2017
R Consortium update for EARL Boston Oct 2017
 
Backing Library Operations with Open Source Applications
Backing Library Operations with Open Source ApplicationsBacking Library Operations with Open Source Applications
Backing Library Operations with Open Source Applications
 

Dernier

Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Chandigarh Call girls 9053900678 Call girls in Chandigarh
 
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
@Chandigarh #call #Girls 9053900678 @Call #Girls in @Punjab 9053900678
 
Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝
soniya singh
 
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
Call Girls In Delhi Whatsup 9873940964 Enjoy Unlimited Pleasure
 
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort ServiceCall Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
9953056974 Low Rate Call Girls In Saket, Delhi NCR
 

Dernier (20)

Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.
 
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
 
Russian Call Girls Pune (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...
Russian Call Girls Pune  (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...Russian Call Girls Pune  (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...
Russian Call Girls Pune (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...
 
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
 
Al Barsha Night Partner +0567686026 Call Girls Dubai
Al Barsha Night Partner +0567686026 Call Girls  DubaiAl Barsha Night Partner +0567686026 Call Girls  Dubai
Al Barsha Night Partner +0567686026 Call Girls Dubai
 
Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Pratap Nagar Delhi 💯Call Us 🔝8264348440🔝
 
Call Now ☎ 8264348440 !! Call Girls in Rani Bagh Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Rani Bagh Escort Service Delhi N.C.R.Call Now ☎ 8264348440 !! Call Girls in Rani Bagh Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Rani Bagh Escort Service Delhi N.C.R.
 
Top Rated Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...
Top Rated  Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...Top Rated  Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...
Top Rated Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...
 
Call Now ☎ 8264348440 !! Call Girls in Sarai Rohilla Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Sarai Rohilla Escort Service Delhi N.C.R.Call Now ☎ 8264348440 !! Call Girls in Sarai Rohilla Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Sarai Rohilla Escort Service Delhi N.C.R.
 
Real Men Wear Diapers T Shirts sweatshirt
Real Men Wear Diapers T Shirts sweatshirtReal Men Wear Diapers T Shirts sweatshirt
Real Men Wear Diapers T Shirts sweatshirt
 
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
 
Moving Beyond Twitter/X and Facebook - Social Media for local news providers
Moving Beyond Twitter/X and Facebook - Social Media for local news providersMoving Beyond Twitter/X and Facebook - Social Media for local news providers
Moving Beyond Twitter/X and Facebook - Social Media for local news providers
 
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.
 
Enjoy Night⚡Call Girls Dlf City Phase 3 Gurgaon >༒8448380779 Escort Service
Enjoy Night⚡Call Girls Dlf City Phase 3 Gurgaon >༒8448380779 Escort ServiceEnjoy Night⚡Call Girls Dlf City Phase 3 Gurgaon >༒8448380779 Escort Service
Enjoy Night⚡Call Girls Dlf City Phase 3 Gurgaon >༒8448380779 Escort Service
 
Ganeshkhind ! Call Girls Pune - 450+ Call Girl Cash Payment 8005736733 Neha T...
Ganeshkhind ! Call Girls Pune - 450+ Call Girl Cash Payment 8005736733 Neha T...Ganeshkhind ! Call Girls Pune - 450+ Call Girl Cash Payment 8005736733 Neha T...
Ganeshkhind ! Call Girls Pune - 450+ Call Girl Cash Payment 8005736733 Neha T...
 
(INDIRA) Call Girl Pune Call Now 8250077686 Pune Escorts 24x7
(INDIRA) Call Girl Pune Call Now 8250077686 Pune Escorts 24x7(INDIRA) Call Girl Pune Call Now 8250077686 Pune Escorts 24x7
(INDIRA) Call Girl Pune Call Now 8250077686 Pune Escorts 24x7
 
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
 
GDG Cloud Southlake 32: Kyle Hettinger: Demystifying the Dark Web
GDG Cloud Southlake 32: Kyle Hettinger: Demystifying the Dark WebGDG Cloud Southlake 32: Kyle Hettinger: Demystifying the Dark Web
GDG Cloud Southlake 32: Kyle Hettinger: Demystifying the Dark Web
 
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort ServiceCall Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
 
Russian Call Girls in %(+971524965298 )# Call Girls in Dubai
Russian Call Girls in %(+971524965298  )#  Call Girls in DubaiRussian Call Girls in %(+971524965298  )#  Call Girls in Dubai
Russian Call Girls in %(+971524965298 )# Call Girls in Dubai
 

State of OWASP 2015

  • 1. OWASP & More State of OWASP 2015 https://www.owasp.org https://2015.appsecusa.org Twitter: @owasp, @appsecusa Tobias Gondrom – Board Chair Paul Ritchie – OWASP Executive Director Noreen Whysel – OWASP Community Manager Claudia Casanova – OWASP Project Coordinator Sept. 24, 2015
  • 2. State of OWASP • Welcome: A “brief story” about OWASP • Updates from our Executive Director, Community Manager and Projects Coordinator • Q&A
  • 3. Who is OWASP? Free & Open Governed by rough consensus & running code Abide by a code of ethics (see ethics) Not-for-profit Not driven by commercial interests Risk based approach
  • 4. Our Purpose & Our Core Values OPEN: Everything at OWASP is radically transparent from our finances to our code. INNOVATION: OWASP encourages and supports innovation/experiments for solutions to software security challenges. GLOBAL: Anyone around the world is encouraged to participate in the OWASP community. INTEGRITY: OWASP is an honest and truthful, vendor agnostic, global community. Our Core Values Our Purpose: The OWASP Foundation will be the thriving global community that drives visibility and evolution in the safety and security of the world’s software.
  • 5. Strengthen OWASP chapters and increase Chapter’s abilities to spread message of OWASP through locally organized and run events. Mature the OWASP Projects Platform: Provide the OWASP projects community a mature project platform to encourage senior developers to participate in the various and many OWASP projects. Build a scalable OWASP training program that spreads security training around the world Strategic Goals for 2015
  • 13. Our Strong OWASP Operations Team • Executive Director: Paul Ritchie • Operations Director: Kate Hartmann • Membership and Business Liaison: Kelly Santalucia • Event Manager: Laura Grau • Projects: Claudia Casanovas • Community Manager: Noreen Whysel • Accounting: Alison Shrader • IT Admin: Matt Tesauro (Contractor) • Graphic Design: Hugo Costa (Contractor) 13
  • 14. OWASP – chapter meetings and conferences around the world
  • 15. Thanks to our sponsors and supporters: Contributing Sponsors: Premium Sponsors:
  • 16. OWASP is about you! Free to use Free to participate Free to contribute Join and help to make the Web, make the world more secure! … join a chapter … join a project … join the global community list … share the security knowledge.
  • 17. Mission • Our mission is to make software security visible, so that individuals and organizations worldwide can make informed decisions about true software security risks • How’d we do in 2014? See Annual Report themed “Growing, Learning, Sharing, Leading”
  • 18. Strategic Goals & Metrics - 2015 • Chapter Development • Volunteer Management • Training • Supporting & Maturing the Project Platform • Finances
  • 19. Chapter Development - 2015 • Our Global Footprint • 28 New Chapters • 8 Chapters Restarted • More Chapter & Project Leader Training on Friday Note Recent New Chapters in Africa
  • 20. Volunteer Management • Project Review Task Force Actively looking for Volunteers • Over 25 Co-marketing agreements ‘signed’ with Speaker or free Booth space at outside event for OWASP Volunteers • Wiki Volunteer & Initiatives page updated with Volunteer opportunities at University and 25 Chapter Leader openings
  • 21. Training – Our Reach is Global AppSec USA-SF 2015 • 1200 attendees • 253 Training attendees • 75+ Speakers AppSecEU 2015 • 585 attendees • 133 Training attendees • 57 Speakers LATAM 2015 • 724 attendees • 42 Training attendees • 70 Speakers
  • 22. Training – Chapters Gone Wild (w/Training) • AppSec-California Training 7 classes, 36 registrations • NYC Hack Day Training 1 class, 19 registrations • OWASP New Zealand Day 1 class, 12 registrations • LATAM Tour 6 classes, 42 training attendees • AppSecEU 13 classes, 133 registrations • OWASP CONfidence (Krakow) 5 classes, (6 trainers/classes on website) • OWASP SAMM Summit (Dublin) ~30 registrations, 10 paid • OWASP Dublin Training Day 3 classes, 78 registrations • …..And so many more
  • 23. Project Innovation & Output • New projects added • Updates & outputs on 2015 • Project Maturity update • Project Summit & Summer of Code • Bossie Award for Open Source Tools – Highlighted: ZAP, Xenotix XSS, O-Saft, OWTF
  • 24. Project Highlights – 2015 • 2 Project Summits held during AppSec Conferences to maximize participation • OWASP’s own Summer Code Sprint hosted to support Projects • Project Coordinator – Claudia updating the New Project & Project Review process & docs • CISO Guide translated into Spanish • Dependancy Check 1.2.9 released • Dependancy Track 1.0.0 released • Vicnum Project updated • OWASP SAMM Project Summit – Dublin March 2015 • AppSensor – CISO Briefing released • ZAP 2.4.0 released • ZAP w/Docker introduction released • ASVS version XX released • OWASP KALP Mobile Project initiated • OWASP Seraphimdroid project, version 2 released
  • 25. OWASP Finances – Overall Strong & Growing See Annual Report for Details Full Financial Transparency & Reports found on the OWASP Wiki
  • 26. Financial Snapshot GROWTH 2013 - 2016 Conferences remain excellent channel for Training & Community sharing • 65% of Income & 50% of Expenses Projects / Chapter Funding represented ~$255K in 2015 with potential growth to the $300-400K range in 2016. 26
  • 27. Project Funding & Chapter Funding Where’s the Info? • Need Project Funding? • Need Chapter Funding? • Got a Chapter Budget, need reimbursement? • Submit here https://www.owasp.org/index.php /Funding
  • 28. OWASP Northern Virginia @OWASPNoVA OWASP DC @OWASPDC The Big Reveal – AppSec US in 2016 • OWASP AppSec EU 2016: Rome in June • OWASP AppSec USA 2016: Washington DC – September – Hosted by No.Virginia & WashDC Chapters
  • 29. Community Update Noreen Whysel Community Manager September 24, 2015
  • 30. Chapter Development • 28 new chapters started in 2015 • 8 chapters restarted • 26 chapters inactivated (some in process of restarting) • 1 merged chapter (Kenya/Nairobi) • 3 chapter splits (Spain, Argentina, Sweden) • 53 new leaders added, including restarts • 120+ cases & conversations with chapter leaders worldwide
  • 31. Communications • Community News Flash • Social Media Announcements • Mailing Lists • SalesForce Messaging • Personal Correspondence
  • 32. Community News Flash • First issue April 2015 • Sent to owasp-leaders and owasp-community lists • Switched to Vertical Response in August 2015 • August 2015 – Sent to: 1,282 – Opens (257): 20.05% – Clicks (52): 4.06% – Bounces (13): 1.01% – Unsubscribes (0): 0.00% • September 2015 – Sent to: 1,269 – Opens (255): 20.09% – Clicks (26): 2.05% – Bounces (3): .24% – Unsubscribes (1): 0.08%
  • 33. Social Media • Twitter (as of 8/31/2015) – 4014 tweets – 325 following – 56,819 followers • Facebook – 9,062 Page Likes – 8,839 Group Members • LinkedIn – 22,730 group members – 12,800 followers • Slack – 399 members – 76 channels • Meetup – 54 “OWASP” Meetup Groups – 13,328 Members – 1,416 Expressed Interest – 50 Cities – 17 Countries
  • 34. Chapter Leader Workshops Room F, Pacific Concourse • Thurs 10:30AM - People and Capital • Thurs 11:30AM - I’m a Leader. Now What? • Friday 10:30AM - What’s In Your Toolbox? • Friday 11:30AM - OWASP Wiki Edit-a-thon • Friday afternoon - Flex sessions, continue the conversation
  • 35. Projects & Initiative Update Claudia Aviles Casanovas Project Coordinator September 20, 2015
  • 36. Project Task Force Recent Activity Pending Graduation Review: (Submitted Last Week) OWASP Security Shepherd OWASP Seraphimdroid Project OWASP Security Logging New Incubator Projects Project Added: • OWASP ZSC Tool Project • OWASP Mth3I3m3nt Framework Project Recent Project that Graduated to the next Level: • Benchmark Tool Project Review Results: Moved from Incubator Project To Lab Project Projects Graduated from Incubator to Lab in June 2015 Category: Documentation • OWASP Internet of Things To Ten Project • OWASP Pro Active Controls • OWASP Top 10 Privacy Risks_Project • OWASP Reverse Engineering and Code_Modification Prevention Project Category: Code • Mobile Application Security Project • OWASP Security Python Project
  • 37. Project Summit USA 2015 Projects Participating: • OWASP Code Review Guide – Gary Robinson & Larry Coklin • OWASP ASVS & OWASP Pro Active Controls – Jim Manico • OWASP Python Security Project – Enrico Branca • OWASP Security Shepherd – Mark Denihan • OWASP Security Knowledge – Glenn Ten Cate • OWASP PodCast – Mark Miller • OWASP WAFEC (Starting up Activity)– Tony Turner • OWASP O2 – Michael Hidalgo
  • 38. Project Summit USA 2015 Project Name Project Leader Did the Project Summit help your Project? Did you Accomplish it? Deliverable OWASP Security Shepherd Mark Denihan Pol Mac Cana Updated the GitHub Wiki pages to a state where new users can easily add Translation support to Shepherd components, add new language tranlations without difficulty and create new Security Shepherd levels with the new specifications made in V3. Also created new Security Shepherd level templates. Eliminated issues that were blocking the progress of the Security Shepherd Docker File.
  • 39. These last two week’s OWASP Summer Code Sprint 2015 mentors and students have wrapped up activities. Originally Received 39 Proposals and were able to select 8 Students for the Summer Code Sprint 2015. The selections was difficult due to competitive proposals. Results: All 8 Students passed the Final Evaluations. Feedback & Experience: • Amazing Performance! • OWASP Seraphimdroid Project is now able to apply for a Project Review Graduation due to the work done with the student. • Project’s quality robustness increased like never over the past 2 months! • Excellent work and worked beyond the original plan! • Gained a contributor for the Hackademic Project. • High level of dedication with excellent results • Students were happy to work with such great mentors and excited about the projects. Results Final Evaluations Fabio Cerullo, Initiative Leader
  • 40. Summer Code Sprint 2015 Participation Fabio Cerullo, Initiative Leader Project Name Mentors Students OWASP OWTF Abraham Aranguren, Tao Sauvage, Bharadwaj Machiraju Arun Sori, Alexandra Sandulescu, Viyat Bhlalodia OWASP Seraphimdroid John Melton Kartik Kholic OWASP APPSensor Nikola Milosevic Sumanth Damaria OWASP Hackademic Spyros Gasteratos, Paul Chaignon Anirudh Anand, Minhaz AV, Tapasweni Pathak
  • 41. Project Updates • OWASP Project Task Force • Project Summit USA • How to Start A New Project • OWASP Project Dasboard • OWASP 2014 Project Handbook – Project Funding Request Form – Project Spending Policy
  • 42. Community Q&A https://www.owasp.org https//2015.appsecusa.org Twitter: @owasp, @appsecusa Open OWASP Board Meeting Friday, Sep-25, 18:00 – 20:00 PDT Room A - Pacific Level.
  • 43. Learn, meet, share and …. … have a great time! https//2015.appsecusa.org Twitter: @appsecusa