|
| 1 | +## Description |
| 2 | + |
| 3 | +The OWASP DSOMM team is happy to announce its upcoming User Day on Wednesday, September 25th 2024. It is part of the OWASP AppSec San Francisco. |
| 4 | + |
| 5 | +## Location |
| 6 | +Hyatt Regency San Francisco |
| 7 | +Address: 5 Embarcadero Center San Francisco, CA 94111 United States |
| 8 | +Room: To be announced. |
| 9 | + |
| 10 | +## Agenda (DRAFT) |
| 11 | +Please expect changes in the timeline. |
| 12 | + |
| 13 | +| Time | Title | Speaker | |
| 14 | +|-------|--------------------------------------------------------------------------|---------------------| |
| 15 | +| 9:00 | Welcome | Timo Pagel | |
| 16 | +| 9:05 | Key Steps to Achieving an Application Security Program | Timo Pagel | |
| 17 | +| 10:00 | Reach your Dynamic Depth with OWASP secureCodeBox | Jannik Hollenbach | |
| 18 | +| 12:00 | Lunch Break | / | |
| 19 | +| 13:30 | Workshop: Utilizing DSOMM app to define your own program | Timo Pagel | |
| 20 | +| 14:00 | Workshop: Application and Vulnerability maturity Model (VMM) - DSOMM Map | Francesco Cipollone | |
| 21 | +| 16:00 | Wrap Up | Timo Pagel | |
| 22 | + |
| 23 | +### Talk Descriptions |
| 24 | +#### Key Steps to Achieving an Application Security Program |
| 25 | +This talk outlines a practical approach to building and optimizing application security (AppSec) programs for organizations of all sizes. |
| 26 | +While briefly touching on foundational elements, the presentation focuses on developing and implementing a custom organizational maturity model that resonates with development and operations teams. Moving beyond traditional frameworks, attendees will learn to design tailored models that account for diverse operating environments. The talk provides strategies for avoiding common pitfalls, implementing effective metrics, and creating a scalable AppSec approach adaptable to an organization’s evolving needs. Through actionable advice and real-world examples, participants will gain insights applicable to both new and existing AppSec programs. |
| 27 | + |
| 28 | +#### Workshop secureCodeBox? |
| 29 | + |
| 30 | +#### Workshop: Utilizing DSOMM app to define your own program |
| 31 | +Get to know the DSOMM application and how to customize it to distribute your AppSec Program as a maturity model. |
| 32 | + |
| 33 | +Requirements: |
| 34 | +- Docker |
| 35 | + |
| 36 | +Linux is recommended. |
| 37 | + |
| 38 | +#### Workshop: Application and Vulnerability maturity Model (VMM) - DSOMM Map |
| 39 | +Organizations face an ever-increasing risk of cyberattacks and data breaches. Vulnerabilities are getting discovered faster than ever, with a 34% YoY increase of vulnerability discovery. Vulnerabilities are often tackled as they come from security scanners, leading to burnout of security professionals, with 50% of security engineers considering changing their profession entirely. This workshop explores the vulnerability management process that applies to application, cloud, and infrastructure security. |
| 40 | + |
| 41 | +To mitigate these risks, vulnerability management and triage have become essential components of an effective cybersecurity program. Vulnerability triage, in particular, plays a critical role in identifying, prioritizing, and remediating vulnerabilities to minimize the organization's attack surface across applications, cloud and infrastructure. However, the process of vulnerability triage is not a one-size-fits-all approach and requires a maturity model that reflects the organization's current state of readiness. In this workshop, you will explore the evolution of vulnerability management and triage process maturity and how organizations can enhance their capabilities to manage and mitigate cybersecurity risks effectively. |
| 42 | + |
| 43 | +Why we created the vulnerability management process? |
| 44 | +We created the vulnerability maturity model to provide a quick and easy assessment method to define where you are in the vulnerability assessment process from triage. |
| 45 | +The VMM is mapped back to both SAMM, and DSOMM. |
0 commit comments