Difference between revisions of "Summit 2011 Working Sessions/Session085"

From OWASP
Jump to: navigation, search
 
(13 intermediate revisions by 5 users not shown)
Line 2: Line 2:
 
|-
 
|-
  
| summit_session_attendee_name1 =  
+
| summit_session_attendee_name1 = Lucas C. Ferreira
| summit_session_attendee_email1 =  
+
| summit_session_attendee_email1 = lucas.ferreira@owasp.org
 +
| summit_session_attendee_username1 = sapao
 
| summit_session_attendee_company1=
 
| summit_session_attendee_company1=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed1=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed1=
  
| summit_session_attendee_name2 =  
+
| summit_session_attendee_name2 = Vlatko Kosturjak
| summit_session_attendee_email2 =  
+
| summit_session_attendee_email2 = vlatko.kosturjak@owasp.org
 +
| summit_session_attendee_username2 = kost
 
| summit_session_attendee_company2=
 
| summit_session_attendee_company2=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed2=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed2=
Line 14: Line 16:
 
| summit_session_attendee_name3 =  
 
| summit_session_attendee_name3 =  
 
| summit_session_attendee_email3 =  
 
| summit_session_attendee_email3 =  
 +
| summit_session_attendee_username3 =
 
| summit_session_attendee_company3=
 
| summit_session_attendee_company3=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed3=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed3=
Line 19: Line 22:
 
| summit_session_attendee_name4 =  
 
| summit_session_attendee_name4 =  
 
| summit_session_attendee_email4 =  
 
| summit_session_attendee_email4 =  
 +
| summit_session_attendee_username4 =
 
| summit_session_attendee_company4=
 
| summit_session_attendee_company4=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed4=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed4=
Line 24: Line 28:
 
| summit_session_attendee_name5 =  
 
| summit_session_attendee_name5 =  
 
| summit_session_attendee_email5 =  
 
| summit_session_attendee_email5 =  
 +
| summit_session_attendee_username5 =
 
| summit_session_attendee_company5=
 
| summit_session_attendee_company5=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed5=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed5=
Line 29: Line 34:
 
| summit_session_attendee_name6 =  
 
| summit_session_attendee_name6 =  
 
| summit_session_attendee_email6 =  
 
| summit_session_attendee_email6 =  
 +
| summit_session_attendee_username6 =
 
| summit_session_attendee_company6=
 
| summit_session_attendee_company6=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed6=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed6=
Line 34: Line 40:
 
| summit_session_attendee_name7 =  
 
| summit_session_attendee_name7 =  
 
| summit_session_attendee_email7 =  
 
| summit_session_attendee_email7 =  
 +
| summit_session_attendee_username7 =
 
| summit_session_attendee_company7=
 
| summit_session_attendee_company7=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed7=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed7=
Line 39: Line 46:
 
| summit_session_attendee_name8 =  
 
| summit_session_attendee_name8 =  
 
| summit_session_attendee_email8 =  
 
| summit_session_attendee_email8 =  
 +
| summit_session_attendee_username8 =
 
| summit_session_attendee_company8=
 
| summit_session_attendee_company8=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed8=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed8=
Line 44: Line 52:
 
| summit_session_attendee_name9 =  
 
| summit_session_attendee_name9 =  
 
| summit_session_attendee_email9 =  
 
| summit_session_attendee_email9 =  
 +
| summit_session_attendee_username9 =
 
| summit_session_attendee_company9=
 
| summit_session_attendee_company9=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed9=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed9=
Line 49: Line 58:
 
| summit_session_attendee_name10 =  
 
| summit_session_attendee_name10 =  
 
| summit_session_attendee_email10 =  
 
| summit_session_attendee_email10 =  
 +
| summit_session_attendee_username10 =
 
| summit_session_attendee_company10=
 
| summit_session_attendee_company10=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed10=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed10=
Line 54: Line 64:
 
| summit_session_attendee_name11 =  
 
| summit_session_attendee_name11 =  
 
| summit_session_attendee_email11 =  
 
| summit_session_attendee_email11 =  
 +
| summit_session_attendee_username11 =
 
| summit_session_attendee_company11=
 
| summit_session_attendee_company11=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed11=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed11=
Line 59: Line 70:
 
| summit_session_attendee_name12 =  
 
| summit_session_attendee_name12 =  
 
| summit_session_attendee_email12 =  
 
| summit_session_attendee_email12 =  
 +
| summit_session_attendee_username12 =
 
| summit_session_attendee_company12=
 
| summit_session_attendee_company12=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed12=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed12=
Line 64: Line 76:
 
| summit_session_attendee_name13 =  
 
| summit_session_attendee_name13 =  
 
| summit_session_attendee_email13 =  
 
| summit_session_attendee_email13 =  
 +
| summit_session_attendee_username13 =
 
| summit_session_attendee_company13=
 
| summit_session_attendee_company13=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed13=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed13=
Line 69: Line 82:
 
| summit_session_attendee_name14 =  
 
| summit_session_attendee_name14 =  
 
| summit_session_attendee_email14 =  
 
| summit_session_attendee_email14 =  
 +
| summit_session_attendee_username14 =
 
| summit_session_attendee_company14=
 
| summit_session_attendee_company14=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed14=  
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed14=  
Line 74: Line 88:
 
| summit_session_attendee_name15 =  
 
| summit_session_attendee_name15 =  
 
| summit_session_attendee_email15 =  
 
| summit_session_attendee_email15 =  
 +
| summit_session_attendee_username15 =
 
| summit_session_attendee_company15=
 
| summit_session_attendee_company15=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed15=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed15=
Line 79: Line 94:
 
| summit_session_attendee_name16 =  
 
| summit_session_attendee_name16 =  
 
| summit_session_attendee_email16 =  
 
| summit_session_attendee_email16 =  
 +
| summit_session_attendee_username16 =
 
| summit_session_attendee_company16=
 
| summit_session_attendee_company16=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed16=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed16=
Line 84: Line 100:
 
| summit_session_attendee_name17 =  
 
| summit_session_attendee_name17 =  
 
| summit_session_attendee_email17 =  
 
| summit_session_attendee_email17 =  
 +
| summit_session_attendee_username17 =
 
| summit_session_attendee_company17=
 
| summit_session_attendee_company17=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed17=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed17=
Line 89: Line 106:
 
| summit_session_attendee_name18 =  
 
| summit_session_attendee_name18 =  
 
| summit_session_attendee_email18 =  
 
| summit_session_attendee_email18 =  
 +
| summit_session_attendee_username18 =
 
| summit_session_attendee_company18=
 
| summit_session_attendee_company18=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed18=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed18=
Line 94: Line 112:
 
| summit_session_attendee_name19 =  
 
| summit_session_attendee_name19 =  
 
| summit_session_attendee_email19 =  
 
| summit_session_attendee_email19 =  
 +
| summit_session_attendee_username19 =
 
| summit_session_attendee_company19=
 
| summit_session_attendee_company19=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed19=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed19=
Line 99: Line 118:
 
| summit_session_attendee_name20 =  
 
| summit_session_attendee_name20 =  
 
| summit_session_attendee_email20 =  
 
| summit_session_attendee_email20 =  
 +
| summit_session_attendee_username20 =
 
| summit_session_attendee_company20=
 
| summit_session_attendee_company20=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed20=
 
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed20=
  
 
|-
 
|-
| summit_track_logo =  
+
| summit_track_logo = [[Image:T._metrics.jpg]]
| summit_ws_logo =  
+
| summit_ws_logo = [[Image:WS._metrics.jpg]]
| summit_session_name =  
+
| summit_session_name = Common structure and numbering for all guides
| summit_session_url =  
+
| summit_session_url = http://www.owasp.org/index.php/Summit_2011_Working_Sessions/Session085
 +
| mailing_list =
 
|-
 
|-
  
 
| short_working_session_description=
 
| short_working_session_description=
 +
The purpose of this session is to bring together the various document project leaders and other interested parties to discuss the establishment of a common document numbering system. This will also require that applicable document projects have a similar structure, at least in the areas associated with the numbering. That means this session will drive revisions to current projects. Additionally, this is an opportunity to discuss the overall alignment of the release document projects and how they fit into a secure development life cycle.
 +
 +
Some of the document projects that would benefit from this activity include the following, but there are several others not listed :
 +
*[[OWASP Secure Coding Practices - Quick Reference Guide|OWASP Secure Coding Practices - Quick Reference Guide]].........(What to do - Requirements),
 +
*[[OWASP Guide Project|OWASP Development Guide]].......................................(How to do it – Coding guidance),
 +
*[[:Category:OWASP Ruby on Rails Security Guide V2|OWASP Ruby on Rails Security Guide V2]].........................(How to do it – Ruby specific),
 +
*[[OWASP Testing Project|OWASP Testing Guide]]...........................................(How to test it – Pen Testing),
 +
*[[:Category:OWASP Code Review Project|OWASP Code Review Guide]].......................................( How to test it – Code Review),
 +
*[[:Category:OWASP Application Security Verification Standard Project|OWASP Application Security Verification Standard Project]]......(Verify and rate what was done),
  
 
|-
 
|-
Line 130: Line 160:
 
|-
 
|-
  
| summit_session_objective_name1=  
+
| summit_session_objective_name1 = Discuss and review current document project structures and key elements.
  
| summit_session_objective_name2 =  
+
| summit_session_objective_name2 = Review proposal to align to ASVS and discuss whether the current version of ASVS provides an adequate baseline.
  
| summit_session_objective_name3 =  
+
| summit_session_objective_name3 = Review other options for structure and numbering.
  
| summit_session_objective_name4 =  
+
| summit_session_objective_name4 = Develop a draft structure and numbering plan.
  
| summit_session_objective_name5 =
+
| summit_session_objective_name5 = Discuss any dependencies which may exist, such as common nomenclature and definitions.
  
 
|-
 
|-
Line 154: Line 184:
 
|-
 
|-
  
| working_session_additional_details =  
+
| working_session_additional_details = The presence on this session of the participants of the Working Sessions below is advisable
 +
* [[Summit 2011 Working Sessions/Session052|'''OWASP Testing Guide''']]
 +
* [[Summit 2011 Working Sessions/Session066|'''Development Guide''']]
 +
* [[Summit 2011 Working Sessions/Session053|'''OWASP Java Project''']]
 +
* [[Summit 2011 Working Sessions/Session200|'''OWASP Secure Coding Practices Project''']]
  
 
|-
 
|-
  
|summit_session_deliverable_name1 =  
+
|summit_session_deliverable_name1 = A written recommendation for a unified category and numbering system for applicable document projects.
|summit_session_deliverable_url_1 =
+
  
|summit_session_deliverable_name2 =  
+
|summit_session_deliverable_name2 = Agreement from applicable document project leaders to adopt the finalized version of the system.
|summit_session_deliverable_url_2 =
+
  
|summit_session_deliverable_name3 =  
+
|summit_session_deliverable_name3 = An implementation plan discussing when projects will implement the new system.
|summit_session_deliverable_url_3 =
+
  
 
|summit_session_deliverable_name4 =  
 
|summit_session_deliverable_name4 =  
|summit_session_deliverable_url_4 =
 
  
 
|summit_session_deliverable_name5 =  
 
|summit_session_deliverable_name5 =  
|summit_session_deliverable_url_5 =  
+
 
 +
|summit_session_deliverable_name6 =
 +
 
 +
|summit_session_deliverable_name7 =
 +
 
 +
|summit_session_deliverable_name8 =  
  
 
|-
 
|-
  
| summit_session_leader_name1 =  
+
| summit_session_leader_name1 = Keith Turpin
| summit_session_leader_email1 =  
+
| summit_session_leader_email1 = keith.n.turpin@boeing.com
 +
| summit_session_leader_username1 = Keith Turpin
  
| summit_session_leader_name2 =  
+
| summit_session_leader_name2 = Matteo Meucci
| summit_session_leader_email2 =  
+
| summit_session_leader_email2 = matteo.meucci@owasp.org
 +
| summit_session_leader_username2 = Mmeucci
  
| summit_session_leader_name3 =  
+
| summit_session_leader_name3 = Vishal Garg
| summit_session_leader_email3 =  
+
| summit_session_leader_email3 = vishalgrg@gmail.com
 +
| summit_session_leader_username3 = Vishal_Garg
  
 
|-
 
|-
  
| operational_leader_name1 =
+
| operational_leader_name1 = Jim Manico
| operational_leader_email1 =
+
| operational_leader_email1 = jim.manico@owasp.org
 +
| operational_leader_username1 = jmanico
  
 
|-
 
|-

Latest revision as of 05:29, 8 February 2011

Global Summit 2011 Home Page
Global Summit 2011 Tracks

WS. metrics.jpg Common structure and numbering for all guides
Please see/use the 'discussion' page for more details about this Working Session
Working Sessions Operational Rules - Please see here the general frame of rules.
WORKING SESSION IDENTIFICATION
Short Work Session Description The purpose of this session is to bring together the various document project leaders and other interested parties to discuss the establishment of a common document numbering system. This will also require that applicable document projects have a similar structure, at least in the areas associated with the numbering. That means this session will drive revisions to current projects. Additionally, this is an opportunity to discuss the overall alignment of the release document projects and how they fit into a secure development life cycle.

Some of the document projects that would benefit from this activity include the following, but there are several others not listed :

Related Projects (if any)


Email Contacts & Roles Chair
Keith Turpin @
Matteo Meucci @
Vishal Garg @
Operational Manager
Jim Manico @
Mailing list
Subscription Page
WORKING SESSION SPECIFICS
Objectives
  1. Discuss and review current document project structures and key elements.
  2. Review proposal to align to ASVS and discuss whether the current version of ASVS provides an adequate baseline.
  3. Review other options for structure and numbering.
  4. Develop a draft structure and numbering plan.
  5. Discuss any dependencies which may exist, such as common nomenclature and definitions.

Venue/Date&Time/Model Venue/Room
OWASP Global Summit Portugal 2011
Date & Time


Discussion Model
participants and attendees

WORKING SESSION OPERATIONAL RESOURCES
Projector, whiteboards, markers, Internet connectivity, power

WORKING SESSION ADDITIONAL DETAILS
The presence on this session of the participants of the Working Sessions below is advisable
WORKING SESSION OUTCOMES / DELIVERABLES
Proposed by Working Group Approved by OWASP Board

A written recommendation for a unified category and numbering system for applicable document projects.

After the Board Meeting - fill in here.

Agreement from applicable document project leaders to adopt the finalized version of the system.

After the Board Meeting - fill in here.

An implementation plan discussing when projects will implement the new system.

After the Board Meeting - fill in here.

After the Board Meeting - fill in here.

After the Board Meeting - fill in here.

After the Board Meeting - fill in here.

After the Board Meeting - fill in here.

After the Board Meeting - fill in here.

Working Session Participants

(Add you name by clicking "edit" on the tab on the upper left side of this page)

WORKING SESSION PARTICIPANTS
Name Company Notes & reason for participating, issues to be discussed/addressed
Lucas C. Ferreira @


Vlatko Kosturjak @