Friday, November 10, 2017

October 2017 Connector

OWASP Connector

FOLLOW US


           
  COMMUNICATIONS |  PROJECTS |  EVENTS |  CHAPTERS |  MEMBERSHIP  
Wed November 8, 2017
OWASP CONNECTOR
Communications

Operations Update

The September Operations Update includes vital information about OWASP's infrastructure initiatives, project activity, and Chapters. Read it for an overview of what is happening in OWASP.


OWASP Board of Directors Election is Reopened

Dear OWASP Community,

The OWASP Global Board has become aware of an issue that affects the integrity of our ongoing Board of Directors election.

It is with respect for the integrity of our election process, due sensitivity to the impact it will cause and fairness to all our candidates and voting members, that we have decided to halt the current election and restart it with a clean slate once the issue has been corrected. We do not take this action lightly, but as a unified Board feel we have a duty to do so. We are committed to free, fair, transparent and open elections.

There are two irregularities that need to be addressed to ensure that we have fair results:

  • A candidate was left off of the ballot.
  • Some community members whose membership expired between June - October had one of two issues:
    • Their memberships did not auto-renew.
    • They did not receive proper reminders that their membership was expiring and that they need to renew.

To address this we have opened a NEW 2017 OWASP Board of Directors election. In order to ensure fair results, the previous vote tallies have been zeroed out for this totally NEW ELECTION. Whether or not you already voted, please take a few moments to cast your vote and help decide the future direction of OWASP! If you are a member in good standing with voting privileges, you should receive an invitation to vote in the election by the end of the day today, 10/19/2017. If you do not receive an email, but believe you should have, or have any other issues related to the election, please email election2017@owasp.org.

The process behind the scenes for the past two days has been scrambling to ensure that the election is set up properly and doing a second review of the setup before re-opening.

Even as the election opens, OWASP Staff are working tirelessly to make sure that anyone who should be able to vote can. Unfortunately, this continues to be a highly manual process. The anticipated process and timeline is outlined below.

  • 10/19 - open election
  • 10/26-10/31 send renewal emails
  • 11/7 - close renewals related to voting
  • 11/8 - add those who renewed to Simply Voting
  • 11/16 - close voting
  • 11/17 - notify candidates
  • 11/20 - share the results with the community

It is critically important that the community participate in this important election in which we will be choosing four new board members.

I apologize again for the inconvenience caused through this process. Thank you for your support and patience as we worked through these issues. As always, feel free to contact me or other leaders directly in addition to the address above if you have further questions or concerns.

Thank you,

Matt Konda

OWASP Board Chair

 


Let OWASP Know How You Think We Should Construct our Budget

Every year the community gets the opportunity to tell the Board of Directors where they believe we should invest by giving input into the OWASP Annual Budget. This is the time that you can ask for funds beyond the grant amount 2k per year for resources to accomplish a particular goal for your chapter or project. You can also ask the board to implement funded initiatives, additional events, or anything that you believe will make OWASP more successful in 2018.

This year requests will go through the OWASP Service Desk hosted on Jira. You can read more about the process including Deadlines and how to submit on the OWASP Wiki

OWASP Leader Workshop

The semi annual Leader Workshop covered a lot of ground this year. The first half was devoted to our ongoing plans upgrade the infrastructure at OWASP. Since the meeting we have learned of a significant problem with our Association Management System (AMS) Migration. Correcting this issue is our largest concern at the moment. The second focus we have is our transition from mailing lists to Discourse. Once on Discourse you will be able to interact with the platform solely through your email if you wish.

Your input is invaluable and we thank you for your time.

The second half of the meeting was devoted to hearing what our Leaders need from the organization. We asked you to fill out charts listing what support is needed, what concerns need to be halted, and what has been working well for you. Overall we learned that our community is worried about vendor influence in our organization, but that the community was pleased with the OWASP Project Summit, Project outputs, and the continued efforts of the staff. Importantly we heard that Leaders see a deep need for funding projects, for increased infrastructure, and for better resources such as updated templates in more formats, swifter project start times, and shared resources such as access to staff recommended technical writers and graphics.

You can watch the meeting here, and discuss your thoughts either on the OWASP blog page or on the YouTube comments section.



 
Events

AppSec USA Developer Summit

An invitation to the local community and attendees of Global AppSecs to join us for FREE security training in the days before the AppSec Global Conference, the AppSec USA 2017 Developer Summit was a huge success, drawing unprecedented crowds! 180 participants learned about threat modeling, API vulnerabilities, and hacking iOS from 4 trainers in 3 sessions held over the course of 2 days.

While our training is performed by volunteers and primarily aimed at developers and new AppSec professionals, everyone is welcome and even seasoned pros might learn something new.

Look to attend or teach at our next Developer Summit in Tel Aviv, details coming soon!

2018 AppSec Europe CfP and CfT are now OPEN



We are glad to announce that the 2018 AppSec Europe Call for Papers and Call for Training are now open.

The OWASP AppSec conference is Europe's premier venue for web applications leaders, software engineers, researchers and visionaries from all over the world. AppSec Europe gathers the application security community for a 5-day event to share and discuss novel ideas, initiatives and advancements in AppSec.  The 2018 conference will take place in Tel-Aviv from June 17th to 21st 2018, with papers/talks presented on 20th and 21st June and training from the 17th and 18th.

The special theme of OWASP AppSec EU this year is: Usable Security. How is security affected by the human aspects of users, developers and administrators? How do we design, deploy and manage a security system so that it will be used consistently and properly? What lessons can we learn from past success (or not-exactly-success...) stories in which the human factor played a major role?

Topics of interest include, but are not limited to the following:
  • Novel web vulnerabilities and countermeasures
  • New technologies, paradigms, tools
  • OWASP tools or projects in practice
  • Secure development: frameworks, best practices, secure coding, methods, processes, SDLC
  • Browser security
  • Mobile security and security for the mobile web
  • Cloud security
  • REST/SOAP security
  • Security of frameworks
  • Large-scale security assessments of web applications and services
  • Privacy risks in the web and the cloud
  • Management topics in Application Security: Business Risks, Awareness Programs, Project Management, Managing SDLC
To ensure the best talks available are presented at AppSec Europe blind reading is being incorporated as part of their process. This means that names and job titles will be removed when the paper abstract is being reviewed. All speakers will be given access to speaker mentorship. 

The submission deadline is January 5, 2018. Please submit your proposal through EasyChair and encourage your favorite trainers and speakers to apply as well.

Upcoming Events

  • AppSec Europe 2018 — June 17–21, 2018; Tel Aviv, Israel
  • AppSec USA  — Fall 2018; San Jose, CA, USA

Regional and Local Events

Training Events

  • Seminario Universitario de Ciberseguridad  — November 10, 2017; Cali, Colombia

Partner and Promotional Events

 

 
Chapters

Chapter Health Checks                                                                 

It is time again for us to conduct our annual Chapter health check.  It will go forward from 11/9 and take several weeks.  Normally the health check entails Tiffany, the community manager, checking the wiki page of every Chapter to make sure that they have made the minimum number of meetings (each chapter must host a minimum of 4 meetings to be considered active and all meetings must be posted on the wiki to be considered open) and following up with chapters who did not manage to make the minimum number of meetings or seem at risk.  During this time she offeres support about building chapter attendance, running a chapter, and raising activity as needed.  

However, this time will take a little longer as we will be reaching out to each Chapter in alphabetical order to ensure that the Chapter's information has made the AMS transition intact.  To streamline the process, please make sure that your wiki page is up to date with all of the meetings you hosted this year. This is a great opportunity to reach out with questions about activities, budgets, or other matters.


Welcome New Chapters!                                                               

We would like to welcome these new chapters:

Madurai                Sioux Falls                Ahmedabad


 


 

The OWASP Foundation, 1200C Agora Drive #232, Bel Air, Maryland, 21014, USA

Labels: , ,

Tuesday, August 29, 2017

Connector August 2017

OWASP Connector

FOLLOW US


           
  COMMUNICATIONS |  PROJECTS |  EVENTS |  CHAPTERS |  MEMBERSHIP  
Mon, August 28, 2017
OWASP CONNECTOR
Communications

Operations Update

The August Operations Update includes vital information about OWASP's infrastructure initiatives, project activity, and Chapters. Read it for an overview of what is happening in OWASP.


Improved Reimbursements System on Horizon for OWASP

OWASP’s growth over the past decade has been phenomenal! We we have grown from an idea to over 40,000 participating members, 2,000 paid or honorary members, and a staff of 6. As an organization we have prioritized support for volunteer-led priorities and experimentation in our dynamic community. This means that staff has created a lattice of support procedures for small, experimental activities that rapidly became a mainstay of OWASP. As our needs or size changed, these procedures either remained the same or underwent repeated limited revision.

Some of these processes were perfect for OWASP 5 or even 2 years ago, but now need to be made more robust to support their exponentially larger loads. During 2017 and 2018 the staff will be focusing on improving these basic processes to increase speed, transparency and ease for our volunteers

One example of this is the OWASP reimbursement system. Currently all reimbursements go through tata forms into a black hole until paid. The only way for a submitter to check on the progress of their reimbursement is by repeatedly emailing staff member. Furthermore, in many cases that staff member must repeatedly email accounting to get an update as well. Worse, previous, workflows were not identical across all OWASP activities. All of this led to confusion and inefficiency.

The OWASP Staff has created a new reimbursement system that will utilize Jira to make sure that all reimbursements go through the appropriate workflow and that the submitter can see where their reimbursement is in the process at any time. All reimbursement communications will be in the same place to facilitate swift repayment. This reimbursement system will be launched in the coming month and there are no changes to the current funding rules. You can read more about how it will work complete with examples on the OWASP Wiki.


2017 Global Board of Directors Election

The OWASP Board of Directors are seven hardworking volunteers elected to direct the financial and outreach goals of the organization. As a group the board members self organize into positions and guide the organization by defining our strategic goals. You can follow the election on the Board of Directors Election wiki page.

This year we have seven candidates running for the four open board positions. You can click on their names to read their bios and statements of purpose :

Greg Anderson Bil Corry Arthur Hicken Steve Kosten

Sherif Mansour Owen Pendlebury Milton Smith Chenxi Wang

Additionally, during this time we request that our members submit questions to be asked of our candidates for the board during an interview that will be recorded and shared prior to the election. The following are the winning questions from our community.

1. How do you make sure that the board's decisions won't be influenced by any personal favors or corruption?

2. OWASP does not have a great reputation internationally due what most people call "Politics", how do you intend to solve the "Politics" problem?

3. How do you intend to address bullying within OWASP? If someone is a repeat offender, will you enforce rules to expel or suspend offending parties?

4. How do you intend to empower the Compliance Committee? Currently all it has the power to do is mediate or make suggestions, it needs more than that.

5. What accomplishments related to OWASP Foundation's mission have you demonstrated in the last (5) years?

6. What kind of action plan do you have in mind to help motivate the participation of Developers into OWASP community?

7. What is your strategy to keep chapters active and motivated with OWASP and keep having meetings and organize local events?

Don’t forget that you must be a member by September 30th to vote for the OWASP Board of Directors. Get your Membership Today!


OWASP Volunteer Platform

We are ready to begin the design stage for building the OWASP Volunteer Platform and we need your help! The first step of the design phase is a set of surveys. OWASP Leaders will receive a survey to explore your needs as volunteer managers via email. The survey will be active until September 22, 2017. The wider OWASP community will be encouraged to follow a link to the Volunteer Portal Survey for Community Members which explores the needs of prospective volunteers in a volunteer management platform. You do not need to be a paid member of OWASP to take the survey. If you are both a Leader who manages volunteers and a volunteer elsewhere in OWASP you are encouraged to take both surveys.

Your input is invaluable and we thank you for your time.

https://www.surveymonkey.com/r/OWASP-VolunteerSurvey-Communitymemeber

(estimated time to take: 4 min.)


OWASP in the News

 


Projects

OWASP Top 10 2017 Project Update

The OWASP Top 10 is the most heavily referenced, most heavily used, and most heavily downloaded document at OWASP. Therefore, it rightfully has a greater level of scrutiny and a greater level of review as befitting a Flagship project.

Under new leadership, the project has issued a second call data and survey which will end on September 18th. You can read more about it on the Top 10 Blog post at the OWASP Blog.


OWASP Project Reviews @ APPSEC USA 2017

Once more OWASP is reviewing projects who wish to graduate from Incubator to Lab to Flagship at this workshop. We are also performing some more detail health checks. The purpose of these assessments is to determine whether a project meets the minimum criteria to graduate as outlined in the Project Health Assessment Criteria Document. The review process begins with an initial self-assessment done by the project leader and reviewed by Matt Tesauro. Next, the assessment enters the peer review phase where we ask volunteers in our OWASP Community to participate and finalize the results. Here's a Sample of a Project Assessment to give you an idea what these look like.

We are still looking for more volunteers to help in this mission. Sign Up!

OWASP Project Reviews @ APPSEC USA 2017 - Funding Incentive is Available!

Please contact Claudia Aviles Casanovas and Matt Tesauro with any questions.




Events

Utilizing DevSecOps to Its Fullest Potential at AppSec USA

DevSecOps will be one of the most discussed topics at this year’s AppSec conference for obvious reasons. It’s one of the fundamental building blocks of security, development, and organizational growth. We’ll have plenty of DevSecOps talks and workshops to keep you busy, but here are a few of this year’s highlights:

Overcoming Mobile App Security Challenges with DevOps (Thursday, 9/21 @ 11:30am): Solution Engineer for NowSecure, Brian Lawrence examines some of the most common reasons companies struggle without consistent DevOps programs. He’ll look at challenges such as technology fragmentation, how mobile apps expose enterprise architecture, the unending updates cycle, and more before framing some successful DevSecOps processes to mitigate these issues.

Making Vulnerability Management Less Painful with OWASP DefectDojo (Thursday, 9/21 @ 1:30pm): Let Greg Anderson, Senior Security Engineer for Pearson, take some of the pain and tedium out of vulnerability management by introducing you to DefectDojo. He’ll demo this enterprise-level tool’s ability to automate, report, scan, and service vulnerabilities to make your -and your engineers’ - lives easier.

WAFs FTW! A Modern DevOps Approach to Security Testing Your WAF (Thursday, 9/21 @ 3:30pm): In this lecture Zack Allen, Threat Operations Manager at ZeroFox, examines a framework to test arbitrary Web Application Firewall implementations and explores rapid prototyping of attack payloads without relying on developer support to verify WAF defenses and make this tool more valuable than ever.

Core Rule Set for the Masses (Friday, 9/22 @ 11:30pm): Although ModSecurity - OWASP’s very own web application firewall - is widely considered an exceptional security tool, maintaining and managing the system can be tedious, time consuming and difficult. OWASP volunteer Tin Zaw and Robert Whitely, Security Solutions Architect for Verizon Digital Media Services, work together to share some benefits of enhancing and fine tuning to spend less time managing and more time enjoying ModSecurity.

How to Stop Worrying About Application Container Security (Friday, 9/22 @ 2:30pm): Information Security Engineer for the US Citizenship and Immigration Services (USCIS), Brian Andrzejewski challenges existing security models by harnessing containers to deploy applications securely and swiftly. He’ll use his experience at USCIS as a case study to frame this innovative concept and discuss the merits of building a container ecosystem.

Volunteer spots for AppSec USA now open!

OWASP has volunteer positions available for AppSec USA. If you are interested, please take a moment to choose your shifts through this signup.com form.

If you are volunteering in exchange for your ticket you will receive an email explaining how to register for the conference. If you are planning on doing this, please remember that you will need to sign up for 8 hours worth of shifts and OWASP does not cover travel or accommodations.

Remember to consult the Conference Schedule to make sure that you do not choose a shift that conflicts with your preferred talks.

Volunteer Orientation is on-site Monday evening. You will receive an email with the exact time and location closer to the event. If you can't make it, please let us know!


OWASP World Tour

This year the strategic goal of OWASP is to raise awareness and spread application security knowledge world-wide by hosting a training world tour. The 2017 world tour will have three, free mass application security training events. Each one-day AppSec training course will teach 500 developers, software testers and entry level application security professionals core security topics.

Our goal is that each training will combine general security principles such as the principle of least privilege, using secure defaults, reducing attack surface with AppSec specific topics such as parameterized queries to prevent SQLi and input validation and encoding. We are also interested in teaching how OWASP Projects can assist in developing secure software.

As part of the OWASP World Tour we are inviting all professional trainers to apply to the Call for Training for your opportunity to train in Tokyo, Boston, or Tel Aviv. Training will close in this month, so apply today!

If you are interested or know someone who is interested in attending the OWASP World Tour near you, please keep an eye on the OWASP Blog or OWASP World Tour Wiki Page for registration.


5th Annual AppSec Bucharest

OWASP Bucharest team is happy to announce the OWASP Bucharest AppSec Conference 2017 at Hotel Caro; a three day security and hacking conference dedicated to the application security. The event will be in English, with cutting-edge topics presented by renowned security professionals.

The CfP is open through September 9th as is the Call for Training.

Oct 11th and 12th are dedicated to trainings and on the 13th talks and workshops will run in parallel. We will also have CtF with a grand prize of 1024 Euros. Conference talks are free however, you need to register.

More information, including the current training schedule available on the wiki.

Upcoming Events

Regional and Local Events

Training Events

  • OWASP Cyber Security Explorer — August 10–11, 2017; Amity University, Rajasthan, India
  • OWASP Training Day 2017  — October 4, 2017; Portland, OR, USA
  • OWASP World Tour  — September 30, 2017; Tokyo, Japan,
  • OWASP World Tour  — October 9, 2017; Boston University, Boston, MA, USA
  • OWASP World Tour  —  October 17th, 2017; Tel Aviv, Israel

Developer Summits

Partner and Promotional Events


Chapters

OWASP Go Live?

We are looking Chapters interested in participating in the alpha test of the OWASP Discourse system. You can read more about the requirements on the OWASP Discourse roll out plan. If interested please fill out this form of interest.



Membership

June 2017 Corporate Members


August 2017 Corporate Members

We would like to thank the following companies for supporting the OWASP Foundation.  
The companies listed below have contributed this month by either renewing their existing 
Corporate Membership or joining OWASP as a new Corporate Member.  

Details about Corporate Membership can be found here.



Contributor Corporate Members


Code Dx is committed to reducing barriers to effective application security. Our automated application vulnerability correlation and management tools help find and fix insecure code faster, with less effort and a smaller team. Focus your precious resources on developing valuable new features, and ship secure code faster and more often.
For more information, please visit https://codedx.com/



Founded in 1975, Information Builders continues to deliver state-of-the-art technology that is transforming business in all commercial industries, government, and education. We remain one the largest independent, privately held companies in the software industry. Headquartered above Madison Square Garden in New York, Information Builders operates in more than 60 global locations and has built an active customer base of tens of thousands of major installations at the world's leading organizations. Information Builders is not only a major software supplier to our customers, but also a major provider to the leading software vendors in the industry including HP, IBM, Oracle, SAP, Teradata, and many others. In addition to our commitment to superior software engineering, we are equally proud of our people. Some of the most talented and creative professionals in the industry work at Information Builders and are passionate about what they do. In fact, the professionalism and tenure of our employees is often cited as a major differentiator by our customers. Our reputation for customer service has garnered us the highest honors from “CRM” magazine, the SSPA, and the American Business Awards. Our products and services have received top recognition from independent analyst research firms including Gartner, Forrester, Ventana Research, BARC, Butler, Bloor, and The Data Warehouse Institute (TDWI). Most importantly, our customers have received the most information technology and business awards for their accomplishments. More than 50 of our customers have had their information systems inducted into the Smithsonian Institute for superior information technology achievement through the Computerworld Honors Program. http://www.informationbuilders.com/about_us






Want your company name here? 
Find out how by visiting our Corporate Member information page, or contact Kelly Santalucia, our Membership & Business Liaison today!  



Thank you to all of our Premier and Contributor Corporate Members for your support!
 

The OWASP Foundation, 1200C Agora Drive #232, Bel Air, Maryland, 21014, USA

Labels: ,