|
|
Utilizing DevSecOps to Its Fullest Potential at AppSec USA
DevSecOps will be one of the most discussed topics at this year’s AppSec conference for obvious reasons. It’s one of the fundamental building blocks of security, development, and organizational growth. We’ll have plenty of DevSecOps talks and workshops to keep you
busy, but here are a few of this year’s highlights:
Overcoming Mobile App Security Challenges with DevOps (Thursday, 9/21 @ 11:30am):
Solution Engineer for NowSecure, Brian Lawrence examines some of the most common reasons companies struggle without consistent DevOps programs. He’ll look at challenges such as technology fragmentation, how mobile apps expose enterprise architecture, the unending updates cycle, and more before framing some successful DevSecOps processes to mitigate these issues.
Making Vulnerability Management Less Painful with OWASP DefectDojo (Thursday, 9/21
@ 1:30pm): Let Greg Anderson, Senior Security Engineer for Pearson, take some of the pain and tedium out of vulnerability management by introducing you to DefectDojo. He’ll demo this enterprise-level tool’s ability to automate, report, scan, and service vulnerabilities to make your -and your engineers’ - lives easier.
WAFs FTW! A Modern DevOps Approach to Security Testing Your WAF (Thursday, 9/21 @ 3:30pm): In this lecture Zack Allen, Threat Operations Manager at ZeroFox, examines a framework to test arbitrary Web Application Firewall implementations and explores rapid prototyping of attack payloads without relying on developer support to verify WAF defenses and make this tool more valuable than ever.
Core Rule Set for the Masses (Friday, 9/22 @ 11:30pm): Although ModSecurity - OWASP’s very own web application firewall - is widely considered an exceptional security tool, maintaining and managing the system can be tedious, time consuming and difficult. OWASP volunteer Tin Zaw and Robert Whitely, Security Solutions Architect for Verizon Digital Media Services, work together to share some benefits of enhancing and fine tuning to spend less time managing and more time enjoying ModSecurity.
How to Stop Worrying About Application Container Security (Friday, 9/22 @ 2:30pm): Information Security Engineer for the US Citizenship and Immigration Services (USCIS), Brian Andrzejewski challenges existing security models by harnessing containers to deploy applications securely and swiftly. He’ll use his experience at USCIS as a case study to frame this innovative concept and discuss the merits of building a container ecosystem.
|
Volunteer spots for AppSec USA now open!
OWASP has volunteer positions available for AppSec USA. If you are interested, please take a moment to choose your shifts through this signup.com form.
If you are volunteering in exchange for your ticket you will receive an email explaining how to register for the conference. If you are planning on doing this, please remember that you will need to sign up for 8 hours worth of shifts and OWASP does not cover travel or accommodations.
Remember to consult the Conference Schedule to make sure that you do not choose a shift that conflicts with your preferred talks.
Volunteer Orientation is on-site Monday evening. You will receive an email with the exact time and location closer to the event. If you can't make it, please let us know!
|
OWASP World Tour
This year the strategic goal of OWASP is to raise awareness and spread application security knowledge world-wide by hosting a training world tour. The 2017 world tour will have three, free mass application security training events. Each one-day AppSec training course will teach 500 developers, software testers and entry level application security professionals core security topics. Our goal is that each training will combine general security principles such as the principle of least privilege, using secure defaults, reducing attack surface with AppSec specific topics such as parameterized queries to prevent SQLi and input validation and encoding. We are also interested in teaching how OWASP Projects can assist in developing secure software.
As part of the OWASP World Tour we are inviting all professional trainers to apply to the Call for Training for your opportunity to train in Tokyo, Boston, or Tel Aviv. Training will close in this month, so apply today! If you are interested or know someone who is interested in attending the OWASP World Tour near you, please keep an eye on the OWASP Blog or OWASP World Tour Wiki Page for registration.
|
5th Annual AppSec Bucharest
OWASP Bucharest team is happy to announce the OWASP Bucharest AppSec Conference 2017 at Hotel Caro; a three day security and hacking conference dedicated to the application security. The event will be in English, with cutting-edge topics presented by renowned security professionals. The CfP is open through September 9th as is the Call for Training. Oct 11th and 12th are dedicated to trainings and on the 13th talks and workshops will run in parallel. We will also have CtF with a grand prize of 1024 Euros. Conference talks are free however, you need to register. More information, including the current training schedule available on the wiki.
|
Upcoming Events
Regional and Local Events
- AppSec AU — September 7–9, 2017; Melbourne, Australia
- OWASP Indonesia Day — September 9, 2017; Yogyakarta, Central Java, Indonesia
- Cheat Sheet Workshop with Jim Manico — September 10-12, 2017;Frankfurt, Germany
- ARMSec — September 28, 2017;Yerevan, Armenia
- New York Metro Joint Cyber Security Conference — October 5, 2017;New York, NY
- OWASP Bucharest AppSec Conference 2017 — October 6, 2017; Bucharest, Romania
- OWASP BASC 2017 — October 14, 2017; Boston, MA, USA
- AppSec Israel 2017 — October 17–18, 2017; Tel Aviv, Israel
- LASCON 2017 — October 26–27, 2017; Austin, TX, USA
- OWASP Benelux Day 2017 — November 23–24, 2017; Tilburg, the Netherlands
- OWASP AppSec Africa 2018 — May 10–12, 2018; Morocco
Training Events
- OWASP Cyber Security Explorer — August 10–11, 2017; Amity University, Rajasthan, India
- OWASP Training Day 2017 — October 4, 2017; Portland, OR, USA
- OWASP World Tour — September 30, 2017; Tokyo, Japan,
- OWASP World Tour — October 9, 2017; Boston University, Boston, MA, USA
- OWASP World Tour — October 17th, 2017; Tel Aviv, Israel
Developer Summits
Partner and Promotional Events
|
|
0 Comments:
Post a Comment
Subscribe to Post Comments [Atom]
<< Home