Difference between revisions of "Summit 2011 Working Sessions/Session094"

From OWASP
Jump to: navigation, search
 
(16 intermediate revisions by 9 users not shown)
Line 2: Line 2:
 
|-
 
|-
  
| summit_session_name =  
+
| summit_session_attendee_name1 = Tony UcedaVelez
| summit_session_url =  
+
| summit_session_attendee_email1 = tonyuv@owasp.org
 +
| summit_session_attendee_username1 = Tony UcedaVelez
 +
| summit_session_attendee_company1= VerSprite
 +
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed1=
 +
 
 +
| summit_session_attendee_name2 = John Menerick
 +
| summit_session_attendee_email2 =  jmenerick@netsuite.com
 +
| summit_session_attendee_username2 = John Menerick
 +
| summit_session_attendee_company2= NetSuite
 +
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed2= (remote)
 +
 
 +
| summit_session_attendee_name3 = Daniel Brzozowski
 +
| summit_session_attendee_email3 = daniel@brzozowski.biz
 +
| summit_session_attendee_username3 = Daniel Brzozowski
 +
| summit_session_attendee_company3=
 +
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed3=
 +
 
 +
| summit_session_attendee_name4 = Alexandre Miguel Aniceto
 +
| summit_session_attendee_email4 = alexandre.aniceto@sekirite.org
 +
| summit_session_attendee_username4 = Alexandre Miguel Aniceto
 +
| summit_session_attendee_company4= Willway
 +
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed4=
 +
 
 +
| summit_session_attendee_name5 =
 +
| summit_session_attendee_email5 =
 +
| summit_session_attendee_username5 =
 +
| summit_session_attendee_company5=
 +
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed5=
 +
 
 +
| summit_session_attendee_name6 =
 +
| summit_session_attendee_email6 =
 +
| summit_session_attendee_username6 =
 +
| summit_session_attendee_company6=
 +
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed6=
 +
 
 +
| summit_session_attendee_name7 =
 +
| summit_session_attendee_email7 =
 +
| summit_session_attendee_username7 =
 +
| summit_session_attendee_company7=
 +
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed7=
 +
 
 +
| summit_session_attendee_name8 =
 +
| summit_session_attendee_email8 =
 +
| summit_session_attendee_username8 =
 +
| summit_session_attendee_company8=
 +
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed8=
 +
 
 +
| summit_session_attendee_name9 =
 +
| summit_session_attendee_email9 =
 +
| summit_session_attendee_username9 =
 +
| summit_session_attendee_company9=
 +
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed9=
 +
 
 +
| summit_session_attendee_name10 =
 +
| summit_session_attendee_email10 =
 +
| summit_session_attendee_username10 =
 +
| summit_session_attendee_company10=
 +
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed10=
 +
 
 +
| summit_session_attendee_name11 =
 +
| summit_session_attendee_email11 =
 +
| summit_session_attendee_username11 =
 +
| summit_session_attendee_company11=
 +
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed11=
 +
 
 +
| summit_session_attendee_name12 =
 +
| summit_session_attendee_email12 =
 +
| summit_session_attendee_username12 =
 +
| summit_session_attendee_company12=
 +
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed12=
 +
 
 +
| summit_session_attendee_name13 =
 +
| summit_session_attendee_email13 =
 +
| summit_session_attendee_username13 =
 +
| summit_session_attendee_company13=
 +
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed13=
 +
 
 +
| summit_session_attendee_name14 =
 +
| summit_session_attendee_email14 =
 +
| summit_session_attendee_username14 =
 +
| summit_session_attendee_company14=
 +
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed14=
 +
 
 +
| summit_session_attendee_name15 =
 +
| summit_session_attendee_email15 =
 +
| summit_session_attendee_username15 =
 +
| summit_session_attendee_company15=
 +
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed15=
 +
 
 +
| summit_session_attendee_name16 =
 +
| summit_session_attendee_email16 =
 +
| summit_session_attendee_username16 =
 +
| summit_session_attendee_company16=
 +
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed16=
 +
 
 +
| summit_session_attendee_name17 =
 +
| summit_session_attendee_email17 =
 +
| summit_session_attendee_username17 =
 +
| summit_session_attendee_company17=
 +
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed17=
 +
 
 +
| summit_session_attendee_name18 =
 +
| summit_session_attendee_email18 =
 +
| summit_session_attendee_username18 =
 +
| summit_session_attendee_company18=
 +
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed18=
 +
 
 +
| summit_session_attendee_name19 =
 +
| summit_session_attendee_email19 =
 +
| summit_session_attendee_username19 =
 +
| summit_session_attendee_company19=
 +
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed19=
 +
 
 +
| summit_session_attendee_name20 =
 +
| summit_session_attendee_email20 =
 +
| summit_session_attendee_username20 =
 +
| summit_session_attendee_company20=
 +
| summit_session_attendee_notes,_reason_for_participating_and_issues_to_be discussed20=
 +
|-
 +
| summit_track_logo = [[Image:T._mitigation.jpg]]
 +
| summit_ws_logo = [[Image:WS._mitigation.jpg]]
 +
| summit_session_name = Microsoft's SDL in 16 steps (and lessons learned)
 +
| summit_session_url = http://www.owasp.org/index.php/Summit_2011_Working_Sessions/Session094
 +
| mailing_list =
  
 
|-
 
|-
  
| short_working_session_description=
+
| short_working_session_description=This OWASP Working Session will explore the Simplified SDL and its 16 security practices implementation guidance (see reference materials below). The Simplified SDL is a platform-agnostic process for implementing proven application security practices in any size organization.
 +
This working group will discuss the feasibility of creating one or more practical, platform-specific resource libraries for each of the security practices in the 16 steps of the Simplified SDL. Further, we will discuss prioritization of the 16 Practices for organizations implementing security in an incremental fashion.
  
 
|-
 
|-
Line 28: Line 152:
 
|-
 
|-
  
| summit_session_objective_name1=  
+
| summit_session_objective_name1= Discuss additional reference materials and identifying publicly-available tools targeting a variety of platforms (web, OSX, Unix, mobile platforms, etc) in an effort to provide practical, platform-specific implementation guidance for each of the security practices in the 16 Steps of the Simplified SDL.
  
| summit_session_objective_name2 =  
+
| summit_session_objective_name2 = Define the practical “crawl/walk/run” steps for adopting the 16 Practices of the Simplified SDL for development organizations of any size.
  
 
| summit_session_objective_name3 =  
 
| summit_session_objective_name3 =  
Line 53: Line 177:
  
 
| working_session_additional_details =  
 
| working_session_additional_details =  
 +
Reference materials: [http://go.microsoft.com/?linkid=9708425 Simplified SDL paper] & [http://blogs.msdn.com/b/sdl/archive/2011/01/26/only-16-security-practices-implementation-guidance-included.aspx 16 Steps blog post].
  
 
|-
 
|-
  
|summit_session_deliverable_name1 =  
+
|summit_session_deliverable_name1 = Identify 1-2 target platforms and potential locations for a library of platform-specific guidance and tools associated with each of the 16 practices of the Simplified SDL.
|summit_session_deliverable_url_1 =
+
  
|summit_session_deliverable_name2 =  
+
|summit_session_deliverable_name2 = Identify OWASP contributors who are willing to help build the content for #1.
|summit_session_deliverable_url_2 =
+
  
|summit_session_deliverable_name3 =  
+
|summit_session_deliverable_name3 = Define the practical “crawl/walk/run” steps for adopting the 16 Practices of the Simplified SDL for development organizations of any size.
|summit_session_deliverable_url_3 =
+
  
 
|summit_session_deliverable_name4 =  
 
|summit_session_deliverable_name4 =  
|summit_session_deliverable_url_4 =
 
  
 
|summit_session_deliverable_name5 =  
 
|summit_session_deliverable_name5 =  
|summit_session_deliverable_url_5 =  
+
 
 +
|summit_session_deliverable_name6 =
 +
 
 +
|summit_session_deliverable_name7 =
 +
 
 +
|summit_session_deliverable_name8 =  
  
 
|-
 
|-
  
| summit_session_leader_name1 =  
+
| summit_session_leader_name1 = Jeremy Dallman
| summit_session_leader_email1 =  
+
| summit_session_leader_email1 = jdallman@exchange.microsoft.com
| summit_session_leader_wiki_username1 =  
+
| summit_session_leader_username1 =  
  
 
| summit_session_leader_name2 =  
 
| summit_session_leader_name2 =  
 
| summit_session_leader_email2 =  
 
| summit_session_leader_email2 =  
| summit_session_leader_wiki_username2 =
+
| summit_session_leader_username2 =  
  
 
| summit_session_leader_name3 =  
 
| summit_session_leader_name3 =  
 
| summit_session_leader_email3 =  
 
| summit_session_leader_email3 =  
| summit_session_leader_wiki_username3 =
+
| summit_session_leader_username3 =  
  
 
|-
 
|-
Line 89: Line 215:
 
| operational_leader_name1 =
 
| operational_leader_name1 =
 
| operational_leader_email1 =
 
| operational_leader_email1 =
| operational_leader_wiki_username1 =  
+
| operational_leader_username1 =  
  
 
|-
 
|-
  
| summit_session_attendee_name1 =
 
| summit_session_attendee_email1 =
 
| summit_session_attendee_wiki_username1 =
 
 
| summit_session_attendee_name2 =
 
| summit_session_attendee_email2 =
 
| summit_session_attendee_wiki_username2 =
 
 
| summit_session_attendee_name3 =
 
| summit_session_attendee_email3 =
 
| summit_session_attendee_wiki_username3 =
 
 
| summit_session_attendee_name4 =
 
| summit_session_attendee_email4 =
 
| summit_session_attendee_wiki_username4 =
 
 
| summit_session_attendee_name5 =
 
| summit_session_attendee_email5 =
 
| summit_session_attendee_wiki_username5 =
 
 
| summit_session_attendee_name6 =
 
| summit_session_attendee_email6 =
 
| summit_session_attendee_wiki_username6 =
 
 
| summit_session_attendee_name7 =
 
| summit_session_attendee_email7 =
 
| summit_session_attendee_wiki_username7 =
 
 
| summit_session_attendee_name8 =
 
| summit_session_attendee_email8 =
 
| summit_session_attendee_wiki_username8 =
 
 
| summit_session_attendee_name9 =
 
| summit_session_attendee_email9 =
 
| summit_session_attendee_wiki_username9 =
 
 
| summit_session_attendee_name10 =
 
| summit_session_attendee_email10 =
 
| summit_session_attendee_wiki_username10 =
 
 
| summit_session_attendee_name11 =
 
| summit_session_attendee_email11 =
 
| summit_session_attendee_wiki_username11 =
 
 
| summit_session_attendee_name12 =
 
| summit_session_attendee_email12 =
 
| summit_session_attendee_wiki_username12 =
 
 
| summit_session_attendee_name13 =
 
| summit_session_attendee_email13 =
 
| summit_session_attendee_wiki_username13 =
 
 
| summit_session_attendee_name14 =
 
| summit_session_attendee_email14 =
 
| summit_session_attendee_wiki_username14 =
 
 
| summit_session_attendee_name15 =
 
| summit_session_attendee_email15 =
 
| summit_session_attendee_wiki_username15 =
 
 
| summit_session_attendee_name16 =
 
| summit_session_attendee_email16 =
 
| summit_session_attendee_wiki_username16 =
 
 
| summit_session_attendee_name17 =
 
| summit_session_attendee_email17 =
 
| summit_session_attendee_wiki_username17=
 
 
| summit_session_attendee_name18 =
 
| summit_session_attendee_email18 =
 
| summit_session_attendee_wiki_username18 =
 
 
| summit_session_attendee_name19 =
 
| summit_session_attendee_email19 =
 
| summit_session_attendee_wiki_username19 =
 
 
| summit_session_attendee_name20 =
 
| summit_session_attendee_email20 =
 
| summit_session_attendee_wiki_username20 =
 
 
|-
 
  
 
| meeting_notes =  
 
| meeting_notes =  

Latest revision as of 23:31, 8 February 2011

Global Summit 2011 Home Page
Global Summit 2011 Tracks

WS. mitigation.jpg Microsoft's SDL in 16 steps (and lessons learned)
Please see/use the 'discussion' page for more details about this Working Session
Working Sessions Operational Rules - Please see here the general frame of rules.
WORKING SESSION IDENTIFICATION
Short Work Session Description This OWASP Working Session will explore the Simplified SDL and its 16 security practices implementation guidance (see reference materials below). The Simplified SDL is a platform-agnostic process for implementing proven application security practices in any size organization.

This working group will discuss the feasibility of creating one or more practical, platform-specific resource libraries for each of the security practices in the 16 steps of the Simplified SDL. Further, we will discuss prioritization of the 16 Practices for organizations implementing security in an incremental fashion.

Related Projects (if any)


Email Contacts & Roles Chair
Jeremy Dallman @

Operational Manager
Mailing list
Subscription Page
WORKING SESSION SPECIFICS
Objectives
  1. Discuss additional reference materials and identifying publicly-available tools targeting a variety of platforms (web, OSX, Unix, mobile platforms, etc) in an effort to provide practical, platform-specific implementation guidance for each of the security practices in the 16 Steps of the Simplified SDL.
  2. Define the practical “crawl/walk/run” steps for adopting the 16 Practices of the Simplified SDL for development organizations of any size.

Venue/Date&Time/Model Venue/Room
OWASP Global Summit Portugal 2011
Date & Time


Discussion Model
participants and attendees

WORKING SESSION OPERATIONAL RESOURCES
Projector, whiteboards, markers, Internet connectivity, power

WORKING SESSION ADDITIONAL DETAILS
Reference materials: Simplified SDL paper & 16 Steps blog post.
WORKING SESSION OUTCOMES / DELIVERABLES
Proposed by Working Group Approved by OWASP Board

Identify 1-2 target platforms and potential locations for a library of platform-specific guidance and tools associated with each of the 16 practices of the Simplified SDL.

After the Board Meeting - fill in here.

Identify OWASP contributors who are willing to help build the content for #1.

After the Board Meeting - fill in here.

Define the practical “crawl/walk/run” steps for adopting the 16 Practices of the Simplified SDL for development organizations of any size.

After the Board Meeting - fill in here.

After the Board Meeting - fill in here.

After the Board Meeting - fill in here.

After the Board Meeting - fill in here.

After the Board Meeting - fill in here.

After the Board Meeting - fill in here.

Working Session Participants

(Add you name by clicking "edit" on the tab on the upper left side of this page)

WORKING SESSION PARTICIPANTS
Name Company Notes & reason for participating, issues to be discussed/addressed
Tony UcedaVelez @
VerSprite

John Menerick @
NetSuite
(remote)
Daniel Brzozowski @


Alexandre Miguel Aniceto @
Willway