OWASP New Zealand Day 2020



19th - 21st February 2020 - Auckland

=Introduction=

Introduction
We are proud to announce the eleventh OWASP New Zealand Day conference, to be held at the University of Auckland on Friday, February 21st, 2020. OWASP New Zealand Day is a one-day conference dedicated to information security, with an emphasis on secure architecture and development techniques to help Kiwi developers build more secure applications.

There will be two streams throughout the day. The first stream will include introductory talks on application and information security topics, as well as on policy, compliance, and risk management. The second stream will primarily address deeper technical topics.

Who is it for?


 * Web Developers
 * Security Professionals and Enthusiasts
 * Program and Project Managers
 * Business Analysts
 * Requirements Analysts
 * Software Testers

Conference structure
Date: Friday, 21 February 2020

Time: 9:00am - 6:30pm

Cost: FREE

The main conference is on Friday, the 21st of February, and will have two streams in both the morning and the afternoon:

Stream One:


 * Introductory Topics
 * Program Management, Policy, Compliance, Risk Management

Stream Two:


 * Technical Topics

We are also exploring the possibility of holding a third, half-day stream, for talks focusing on OWASP Tools and Projects.

Keynote Speaker
We are excited to announce that Jim Manico, founder of Manicode Security and a co-leader of the OWASP Application Security Verification Standard (ASVS), Top Ten Proactive Controls, and Cheat Sheets Projects, will present our opening keynote.

Training
In addition to the main conference on Friday, we are pleased to be offer training opportunities on Wednesday and Thursday, at the same venue. Course details, including registration, will be added as they become available.

Training Fees: $1250.00 for two-day sessions; $625.00 for one-day sessions; $325.00 for half-day sessions (plus EventBrite fees)

General
The eleventh OWASP New Zealand Day will be happening thanks to the support provided by the University of Auckland, which will kindly offer the same facilities as those we used in previous years. The main conference will continue to be free, thanks to the generous support of our sponsors.

For any comments, feedback or observations, please don't hesitate to [mailto:new-zealand-day@owasp.org contact us].

Registration
Registration will open on 15 December 2019.

Please join our low volume Google Groups mailing list to be notified as further schedule information becomes available, and/or follow us on Twitter @owaspnz.

Important dates
For those of you booking flights, ensure you can be at the venue by 8:30am. The conference will end by 6:30pm. However, we will have post-conference drinks at a local drinking establishment for those interested. We will also hold a special Pre-Conference Reception on Thursday evening for speakers, trainers, sponsors, and conference volunteers - if you are planning to be in one of those groups, plan your travel accordingly.

Places to eat and drink on the day
The University published a handy map (in 2018), to help you find places to eat around campus:

Some of the options available:  The Deli - Located on Level 1 of the Owen G. Glenn Building - This is closest, but will probably have long lines Mojo Symonds - also on campus Shakey Isles - coffee and food across the road on the corner of Symonds & Alfred St The CBD - walk up and over Albert Park to get to the CBD with many great food options  Fort Street has burgers, kebabs, and KFC High Street & Lorne Street have lots of little cafes and restaurants  Subway, Starbucks, St. Pierre's Sushi & Pita Pit - walk up Symonds Street</li> Vulture’s Lane is a popular pub with the InfoSec crowd, there are more seats downstairs</li> The Bluestone Room - also a popular pub just across Queen St</li> </ul>

Conference Sponsors
For more information on our Premier Sponsors, please visit our About Our Sponsors page

Silver Sponsors
Follow us on Twitter (@owaspnz)

OWASP New Zealand on Facebook

=Call for Presentations=

'''The Call for Presentations closes on 15th December. Visit PaperCall to submit yours.'''

Call for Presentations
OWASP New Zealand Day conferences attract a high quality of speakers from a variety of security disciplines, including architects, Web developers and engineers, system administrators, penetration testers, policy specialists and more.

We would like a variety of technical levels in the presentations submitted, corresponding to the three focus areas of the conference:

Track One:


 * Introductions to various Information Security topics, and the OWASP projects
 * Policy, Compliance and Risk Management

Track Two:
 * Technical topics

Introductory talks should appeal to an intermediate to experienced software developer, without requiring a solid grounding in application security or knowledge of OWASP projects. These talks should be engaging, encourage developers to learn more about information security, and give them techniques that they can immediately return to work and apply to their jobs.

This being an OWASP conference, the selection process for talks in Track One will give priority to those related to OWASP's Projects, Tools, and Guidance (check out the current [OWASP Project Inventory](https://www.owasp.org/index.php/Category:OWASP_Project#tab=Project_Inventory) for more information). If multiple submissions are received related to the same OWASP Project/Tool, preference will be given to speakers actively involved as leaders or members of the respective project teams.

Technical topics are running all day and should appeal to two audiences - experienced software security testers or researchers, and software developers who have a “OWASP Top Ten” level of understanding of web attacks and defences. You could present a lightning, short or long talk on something you have researched, developed yourself, or learnt in your travels. Ideally the topics will have technical depth or novelty so that the majority of attendees learn something new.

We would also like to invite talks that will appeal to those interested in the various non-technical topics that are important in our industry. These talks could focus on the development of policies, dealing with compliance obligations, managing risks within an enterprise, or other issues that could appeal to those in management roles.

We encourage presentations to have a strong component on fixing and prevention of security issues. We are looking for presentations on a wide variety of security topics, including but not limited to:


 * Web application security
 * Mobile security
 * Cloud security
 * Secure development
 * Vulnerability analysis
 * Threat modelling
 * Application exploitation
 * Exploitation techniques
 * Threat and vulnerability countermeasures
 * Platform or language security (JavaScript, NodeJS, .NET, Java, RoR, Python, etc)
 * Penetration Testing
 * Browser and client security
 * Application and solution architecture security
 * PCI DSS
 * Risk management
 * Security concepts for C*Os, project managers and other non-technical attendees
 * Privacy controls

The submission will be reviewed by the OWASP New Zealand Day conference committee and the highest voted talks will be selected and invited for presentation.

PLEASE NOTE:


 * Due to limited funds availability, the conference budget does not include a plan to cover expenses for international speakers. However, as part of the Diversity Fund, we will have funds available to subsidise _local_ expenses (airport taxis, and hotel in Auckland) for international speakers and attendees, on a limited need basis.
 * If you are selected as a speaker, and your company is willing to cover travel and accommodation costs, the company will be recognised as a "Supporting Sponsor" of the event.

Please submit your presentation on PaperCall.

Submission Deadline: Friday, 15th November 2019 for first-round consideration; Final Deadline: Sunday, 15th December.

Applicants will be notified in the following week after the deadline, whether they were successful or not.

=Training - 19-20 February=

Training
Training Registration opens on Sunday, December 15

In addition the main conference on Friday, we are pleased to be offer nine (9) training opportunities on Wednesday and Thursday, at the same venue. Course details, including registration, are as follows:

Attacking and Defending Containerised Apps and Serverless Tech
Dates: Wednesday and Thursday, 19 - 20 February 2020

Time: 8:45 a.m. - 5:30 p.m.

Instructors: Nithin Jois and Sharath Kumar Ramdas

Instructors' Organisation: we45

Registration Fee: $1,250.00 (plus EventBrite fees)

Training Registration Page

Building Secure APIs and Web Applications
Dates: Wednesday and Thursday, 19 - 20 February 2020

Time: 8:45 a.m. - 5:30 p.m. each day

Instructors: Jim Manico and Georgia Weidman

Instructors' Organisations: Manicode Security,Shevirah, Inc.

Jim's OWASP Affiliations: Co-Leader, OWASP Application Security Verification Standard (ASVS) Project and OWASP Proactive Controls Project

Registration Fee: $1,250.00 (plus EventBrite fees)

Training Registration Page

-

Advanced Pwning & Fixing of Node.js Apps: Shells, Injections, and Fun!
Date: Wednesday, 19 February 2020

Time: 8:45 a.m. - 5:30 p.m.

Instructors: Abraham Aranguren and Anirudh Anand

Instructors' Organisation: 7A Security

Abraham's OWASP Affiliations: Co-Leader, OWASP Offensive Web Testing Framework (OWTF) Project

Anirudh's OWASP Affiliations: Contributor, OWASP OWTF Project and OWASP Hackademic Challenges Project

Registration Fee: $625.00 (plus EventBrite fees)

Training Registration Page

Mobile Security Testing Guide Hands-On: Android Edition
Date: Wednesday, 19 February 2020

Time: 8:45 a.m. - 5:30 p.m.

Instructor: Sven Schleier

Instructor's Organisation: Seven Consulting

Sven's OWASP Affiliations: Co-Leader, OWASP Mobile Security Testing Guide (MSTG) Project; Leader, OWASP Mobile Hacking Playground Project; Contributor, OWASP ASVS Project

Registration Fee: $625.00 (plus EventBrite fees)

Training Registration Page

---

Bootstrap and Improve Your SDLC with OWASP SAMM
Date: Thursday, 20 February 2020

Time: 8:45 a.m. - 5:30 p.m.

Instructors: John Ellingsworth

John's OWASP Affiliations: Contributor, OWASP Software Assurance Maturity Model (SAMM) Project

Registration Fee: $625.00 (plus EventBrite fees)

Training Registration Page

DevSecOps: Automating Security in DevOps
Date: Thursday, 20 February 2020

Time: 8:45 a.m. - 5:30 p.m.

Instructors: Anand Tiwari and Rohit Salecha

Instructors' Organisations: Anand Security, NotSoSecure

Registration Fee: $625.00 (plus EventBrite fees)

Training Registration Page

Mobile Security Testing Guide Hands-On: iOS Edition
Date: Thursday, 20 February 2020

Time: 8:45 a.m. - 5:30 p.m.

Instructor: Sven Schleier

Instructor's Organisation: Seven Consulting

Sven's OWASP Affiliations: Co-Leader, OWASP Mobile Security Testing Guide (MSTG) Project; Leader, OWASP Mobile Hacking Playground Project; Contributor, OWASP ASVS Project

Registration Fee: $625.00 (plus EventBrite fees)

Training Registration Page

Introduction to Fuzzing
Date: Thursday, 20 February 2020

Time: 8:45 a.m. - 12:30 p.m.

Instructor: Mishra Dhiraj

Registration Fee: $325.00 (plus EventBrite fees)

Training Registration Page

Security Uno: A Fun Way to Threat Model
Date: Thursday, 20 February 2020

Time: 1:45 - 5:30 p.m.

Instructors: Kendra Ash

Instructor's Organisation: Vacasa

Registration Fee: $325.00 (plus EventBrite fees)

Training Registration Page

-

Spaces will fill up fast, so get in quickly!

Check-in desk will be located in the Level 0 lobby (outside the Case Study Rooms), and will open at 8:00 a.m. each day

Morning and afternoon tea breaks will be provided; lunch will be on your own.

=Call for Volunteers=

We're always looking for a few good men and women, to assist with conference preparations and to help things go smoothly during the event.

Please contact John DiLeo ([mailto:john.dileo@owasp.org john.dileo@owasp.org]), if you're willing and able to help out.

Conference Committee
A few kind souls have already agreed to help out:


 * John DiLeo - Conference Chair, OWASP New Zealand Chapter Leader (Auckland)
 * Lech Janczewski - Conference Host Liaison, on-site Health & Safety contact - Associate Professor, University of Auckland School of Business
 * Kirk Jackson - Video post-production, OWASP New Zealand Chapter Leader (Wellington)
 * Austin Chamberlain
 * Teresa Chan
 * Paul Howarth
 * Anneke Smitheram
 * YOU - We're always looking for more help, both during advance preparations and on the conference and training days!

=Call for Sponsorships=

Call For Sponsorships
OWASP New Zealand Day 2020 will be held in Auckland on the 21st of February, 2020, and is a security conference entirely dedicated to application security. The conference is once again being hosted by the University of Auckland with their support and assistance. OWASP New Zealand Day is a very low-cost event, and requires sponsor support to help be an instructive and quality event for the New Zealand community. OWASP is strictly not for profit. The sponsorship money will be used to help make OWASP New Zealand Day 2020 a compelling, and valuable experience for all attendees.

Sponsorship funds collected are to be used for things such as:


 * Venue - Room use and on-site management fees
 * Name tags - We feel that getting to know people within the New Zealand community is important, and name tags make that possible
 * Promotion - We would like to reach a wider audience, by utilising paid advertising for the event
 * Printed Materials - Printed materials will include program information, room signs, and lanyards
 * Recognition items for speakers and trainers
 * Afternoon tea, to promote a congenial environment for networking among application security professionals

Facts
Last year, the event was supported by six premier sponsors and attracted more than 650 attendees. Plenty of constructive (and positive!) feedback from the audience was received, and we are using this to make the conference more appealing to more people. For more information on the last New Zealand Day event, please visit: https://www.owasp.org/index.php/OWASP_New_Zealand_Day_2019

The OWASP New Zealand community is strong, with more than 500 people currently subscribed to the mailing list (sign up). OWASP New Zealand Day is expected to attract between 700 and 850 attendees this year.

OWASP regular attendees are IT project managers, IT security managers, IT security consultants, Web application architects and developers, QA managers, QA testers and system administrators.

How to Become a Sponsor
All financial matters related to the conference, including Sponsorship Agreements and payments, are handled through the OWASP Foundation. To express interest in supporting the conference as a sponsor, please [mailto:new-zealand-day@owasp.org contact us by email].

Premium Sponsorship Packages
NOTE: All amounts listed are in New Zealand dollars (NZD)

1. Afternoon Tea Break - Conference Day
Sponsorships Available: Two (2)

General Rate: $5,500

Benefits:


 * Opportunity to display your company's banner in the conference lobby (see notes below) throughout the day of the conference
 * Recognition as sponsoring provider, on signs displayed on service tables during tea breaks
 * Six (6) complimentary tickets to the Pre-Conference Reception
 * Ten (10) reserved passes for main Conference
 * Sponsor logo printed on attendee badges
 * Sponsor logo printed on Room Signs
 * Single-colour sponsor logo imprinted on t-shirts
 * Single-colour sponsor logo imprinted on conference tote bags
 * Sponsor logo displayed on conference Web page, alongside Platinum Sponsors
 * Opportunity to include 200-word company description in About Our Sponsors section of conference Web page
 * Written recognition as a leading sponsor, in pre-event publicity communications
 * Visual and verbal recognition of sponsor at opening and closing sessions of conference

2. Pre-Conference Reception
On Thursday evening, the OWASP New Zealand Day Committee will host a reception for speakers, trainers, conference volunteers, and Premier Sponsors. The event will be held at an establishment near the conference venue.

Sponsorships Available: One (1)

General Rate: $4,000

Benefits:


 * Opportunity to display your company's banner at the reception venue (see notes below) during the reception
 * Six (6) complimentary tickets to the Pre-Conference Reception
 * Ten (10) reserved passes for main Conference
 * Recognition as sponsoring provider, on signs displayed on service tables/bars during reception
 * Sponsor logo printed on Room Signs
 * Single-colour sponsor logo imprinted on t-shirts
 * Single-colour sponsor logo imprinted on conference tote bags
 * Sponsor logo displayed on conference Web page, alongside Gold Sponsors
 * Opportunity to include 150-word company description in About Our Sponsors section of conference Web page
 * Written recognition as a leading sponsor, in pre-event publicity communications
 * Visual and verbal recognition of sponsor at opening and closing sessions of conference

3. T-Shirts for Participants
We will be distributing branded t-shirts to all event participants, including attendees, speakers, sponsor staff, trainers, and volunteers.

Sponsorships Available: One (1)

General Rate: $4,500

Benefits:


 * Opportunity to display your company's banner at the reception venue (see notes below) during the reception
 * Six (6) complimentary tickets to the Pre-Conference Reception
 * Ten (10) reserved passes for main Conference
 * Recognition as sponsoring provider, on signs displayed on service tables/bars during reception
 * Sponsor logo printed on Room Signs
 * Single-colour sponsor logo imprinted on t-shirts
 * Single-colour sponsor logo imprinted on conference tote bags
 * Sponsor logo displayed on conference Web page, alongside Gold Sponsors
 * Opportunity to include 150-word company description in About Our Sponsors section of conference Web page
 * Written recognition as a leading sponsor, in pre-event publicity communications
 * Visual and verbal recognition of sponsor at opening and closing sessions of conference

4. Conference Tote Bags for Attendees
Sponsorships Available: One (1)

General Rate: $4,000

Benefits:


 * Single-colour sponsor logo printed on tote bags
 * Single-colour sponsor logo imprinted on t-shirts
 * Six (6) complimentary tickets to the Pre-Conference Reception
 * Ten (10) reserved passes for main Conference
 * Sponsor logo printed on Room Signs
 * Sponsor logo displayed on conference Web page, alongside Gold Sponsors
 * Opportunity to include 150-word company description in About Our Sponsors section of conference Web page
 * Visual and verbal recognition of sponsor at opening and closing sessions of conference

5. Speaker Gifts
Sponsorships Available: One (1)

General Rate: $1,000

Benefits:


 * Sponsor logo printed on Room Signs
 * Single-colour sponsor logo imprinted on conference tote bags
 * Two (2) complimentary tickets to the Pre-Conference Reception
 * Five (5) reserved passes for main Conference
 * Sponsor logo displayed on conference Web page, alongside Silver Sponsors
 * Opportunity to include 100-word company description in About Our Sponsors section of conference Web page
 * Written recognition as a leading sponsor, in pre-event publicity communications
 * Visual and verbal recognition of sponsor at opening and closing sessions of conference

6. Morning and Afternoon Tea Breaks - Training Day
Sponsorships Available: One (1)

General Rate: $2,500

Benefits:


 * Opportunity to display your company's banner in the training facility lobby (see notes below) throughout the training day
 * Recognition as sponsoring provider, on signs displayed on service tables during training day tea breaks
 * Four (4) complimentary tickets to the Pre-Conference Reception
 * Five (5) reserved passes for main Conference
 * Sponsor logo displayed on conference Web page, alongside Silver Sponsors
 * Opportunity to include 100-word company description in About Our Sponsors section of conference Web page
 * Visual and verbal recognition of sponsor at opening and closing sessions of conference

7. Diversity Fund
The OWASP New Zealand Day Diversity and Financial Aid Fund has been established to provide financial assistance to students at New Zealand universities. Each Diversity Fund sponsorship is intended to cover travel expenses for one New Zealand student, from outside the Auckland area, who will be attending or presenting at the conference. Each Diversity Fund support recipient will receive funding for return airfare from their nearest domestic airport to Auckland International Airport, two night's accommodation in a lodging near the conference venue, and return shuttle transportation between the airport and the accommodation.

Sponsorships Available: No Limit

General Rate: $800, or more

Benefits:


 * Sponsor logo displayed on conference Web page, as a Diversity Fund Sponsor
 * Visual and verbal recognition of sponsor at opening and closing sessions of conference

8. Door Prizes
At the closing session of the conference, the OWASP New Zealand Day Committee will conduct a series of random drawings, awarding donated items to attendees, who must be present to win. There is no minimum or maximum value required for donated items, nor is the number of items provided subject to any limit. It is recommended that items provided be of interest to the conference's target audience, rather than of a generic nature.

Sponsorships Available: No Limit

General Rate: In-Kind Donation

Benefits:


 * Verbal recognition, at the time of the prize drawing, as the donor of the prize

9. Other Supporting Sponsorships
If your company would like to provide special items to attendees, funding for paid promotional advertising for the event, or other items that we haven't yet thought of, you are welcome to contact us to discuss your ideas.

Sponsorships Available: No Limit

General Rate: In-Kind Donation

Benefits:


 * Sponsor logo displayed on conference Web page, as a Supporting Sponsor
 * Visual and verbal recognition of sponsor at opening and closing sessions of conference

Diversity and Financial Aid fund
Thanks to the generous support of our lovely sponsors, we will have some funding available to help people from around New Zealand attend the OWASP NZ Day, who would otherwise find it hard to attend. In particular, we welcome applications from women, people of colour, LGBTIQ, and all others. You all deserve to be able to learn more about security, and we’ll do our best to help make that happen!

Our funds are limited, and we’ll be reviewing applications every week, starting at the end of January. Submit your application soon, so we can approve them promptly, and you’ll be in several review cycles!

Process:


 * Fill out our Application Form
 * We will review and approve applications each week. The first reviews will be completed by 20 December.
 * We will contact all applicants and let them know the result of the review.
 * Successful applicants will be contacted to help sort things out.

We use the following criteria to help us decide who gets approved:


 * We are biased towards (but not exclusively for) diverse applicants.
 * We do attempt to maximise cost efficiency and will aim to get as many people to OWASP as possible, with our limited funds.

Each successful recipient can choose whether to be kept anonymous (in which case only the OWASP NZ committee will know the details of your funding), or to be put in touch with the supporting company whose sponsorship is going towards your attendance (if applicable). We think some of our sponsors may enjoy the opportunity to chat with you on the day and talk about your experiences and plans for the future, but that’s totally optional and up to you.

If you have any questions, feel free to [mailto:new-zealand-day@owasp.org drop us an email].

= International Attendees =

Information for International Travellers
Effective on 1 October 2019, new travel requirements take effect for visitors to New Zealand from Visa Waiver countries.

Here are the requirements, as we (the conference committee) understand them - the usual "does not constitute legal advice" disclaimers apply:


 * 1) If you are in one of the groups listed on Immigration New Zealand's Travelers who do not need an NZeTA page: no worries, you can just turn up;
 * 2) If you are travelling on a passport meeting the conditions listed on the New Zealand Visa Waiver Countries page: You will need to obtain a New Zealand Electronic Travel Authority (NZeTA);
 * 3) If you are travelling on any other passport, you will need to apply for a visa to visit New Zealand:
 * 4) If you are visiting New Zealand, and will attend the conference and/or a training class as part of your visit, you should be able to travel on a Visitor Visa;
 * 5) For those visiting New Zealand to present a training class, we have been made aware of conflicting information provided by Immigration New Zealand staff and embassy officials. Some trainers have been advised they can come to New Zealand on a Business Visitor Visa, while others have been informed they must apply for a Specific Purpose Work Visa. The latter visa requires more documentation, and takes longer to process, so please plan accordingly.

If you're unsure what travel documentation you need, we highly recommend you contact Immigration New Zealand early.

= Code of Conduct =

Code of Conduct
We want to make the OWASP NZ Day a welcoming environment for all attendees. To that end, we would like to remind you that all activities associated with this event are subject to OWASP's Conference Policies. At their core, these policies are intended to promote and maintain an inclusive, welcoming environment for all participants - actions detrimental to that environment are unwelcome.

Speakers, trainers and sponsors have all been reminded of these policies, and are expected to abide by them like all attendees.

If you have any concerns during the day, please seek out John, Austin, or Brendan. We will make ourselves visible at the start of the day, so you know what we look like.

= Call For Training - CLOSED =

Call for Training
'''The Call for Training is now closed. Trainers selected to present have been contacted, and details have been finalised. See the "Training - 19-20 February" tab for information on the training classes offered this year.'''

We are happy to announce that training will run on Wednesday and Thursday, 19-20 February 2020, the two days before the OWASP NZ Day conference. The training venue will be in classrooms and Case Study rooms of varying sizes, kindly provided by the University of Auckland School of Business, in the same building as the OWASP NZ Day conference itself. The largest rooms can accommodate up to 69 attendees, with power for laptop usage and Wi-Fi. A wide range of half-day, one-day, or two-day training proposals will be considered, see the Call for Presentations for a list of example topics.

The fixed per-attendee fees for training are as follows:
 * $325.00 for a half-day session;
 * $625.00 for a one-day session; and
 * $1,250.00 for a two-day session.

As this training is part of an OWASP event, the OWASP Foundation's revenue sharing policy applies, which allocates 40% of the registration fee to the training presenter ($130 per attendee for a half-day session, $250 for one-day, and $500 for two-day). The per-attendee fee paid will include both paid registrations, and "free" training seats allocated to the conference's premier sponsors.

During each training day, morning and afternoon tea will be provided; lunch will be on your own.

Training presenters will be automatically registered for the main conference on Friday, 21 February, and will receive complimentary tickets to the Pre-Conference Reception on Thursday evening, 20 February.

Please submit your training proposal on PaperCall.

Submission Deadline: Saturday, 30th November 2019

Applicants will be notified in the following week after the deadline, whether they were successful or not. Our goal is to have the training programme finalised before registration opens on 15th December.