Difference between revisions of "OWASP ESAPI AppSecDC"

From OWASP
Jump to: navigation, search
(The speaker)
(The speaker)
Line 5: Line 5:
  
 
== The speaker ==
 
== The speaker ==
Jeff Williams is the founder and CEO of Aspect Security, specializing exclusively in application security risk management services. Jeff also serves as the volunteer Chair of the Open Web Application Security Project (OWASP). Jeff has made extensive contributions to the application security community through OWASP, including the Top Ten, WebGoat, Secure Software Contract Annex, Enterprise Security API, Risk Rating Methodology, several smaller security tools, and the worldwide local chapters program. Jeff has degrees in psychology, computer science, and human factors, and law.
+
Jeff Williams is the founder and CEO of Aspect Security, specializing exclusively in application security professional services. Jeff also serves as the volunteer Chair of the Open Web Application Security Project (OWASP). He has made extensive contributions to the application security community through OWASP, including writing the Top Ten, WebGoat, Secure Software Contract Annex, Enterprise Security API, OWASP Risk Rating Methodology, and starting the worldwide local chapters program. If nothing else, Jeff is probably the tallest application security expert in the world and likes nothing better than discussing new ideas for changing the way we build software.
 
+
Jeff has been training developers, architects, managers, and security specialists since 1994. He’s a trained facilitator and ran the SSE-CMM Author Group for several years. He’s spoken at many security conferences and participated in many panels, occasionally serving as moderator.  
+
  
 
[[Category:OWASP_AppSec_DC_09]][[Category:OWASP_Conference_Presentations]]
 
[[Category:OWASP_AppSec_DC_09]][[Category:OWASP_Conference_Presentations]]

Revision as of 19:43, 20 August 2009

The presentation

Owasp logo normal.jpg

In an enterprise with hundreds or thousands of applications, securing one at a time is too expensive and takes too long. The goal of this session is to identify the strategies that most cost-effectively reduce risk over time. How do we craft an effective application security program using a combination of tools, standard controls, consultants, in-house teams, testers and auditors, and training. How can we manage the cost and risk over time – what metrics have proven to be effective in practice?

The speaker

Jeff Williams is the founder and CEO of Aspect Security, specializing exclusively in application security professional services. Jeff also serves as the volunteer Chair of the Open Web Application Security Project (OWASP). He has made extensive contributions to the application security community through OWASP, including writing the Top Ten, WebGoat, Secure Software Contract Annex, Enterprise Security API, OWASP Risk Rating Methodology, and starting the worldwide local chapters program. If nothing else, Jeff is probably the tallest application security expert in the world and likes nothing better than discussing new ideas for changing the way we build software.