OWASP Pune Meeting December 2015

From OWASP
Jump to: navigation, search

December 2015 meet on 17th December, 2015 () 5.00 pm to 6.00 pm - IST


Session Details/Agenda:


5.00 pm to 6.00PM: CICD - Continuous integration, continuous development by Mahesh Saptarshi/ Rohit Pitke

In the present scenario of rapid product development, CICD (continuous integration, continuous deployment), and always-available e-retail, banking and social media services it is imperative that security assurance practices also scale up to the shorter timelines.

While we know that tools and automation is the way to go, running different tools, collating the reports, filing the evidences for audits and assuring management and auditors of the security preparedness of the deployment is still not scalable to weekly deployments, let alone daily and hourly roll outs.

Mahesh will demonstrate a security automation framework where this problem is addressed through separating the tool running intelligence from the report parsing and orchestration. It serves two purposes: 1. Periodic and predictable (baseline) tool runs for trend analysis 2. Rapid integration framework to add more and more tools without the entire team learning the new tools, and protecting "institutional learning".

This also allows for collecting the security assurance related data in a single place so the data analysis (eventually this will be Big Data) to be performed independent of the tools and targets


When: 17th December, 2015 (Thursday) - 5.00 PM to 6.00 PM IST

Where: PTC Software Pvt. Ltd. Marisoft complex, Kalyani Nagar, Wadgoan Shery Pune 122001