January 2021 Chapter Meeting


Details
This month's meetup is VIRTUAL. Join Wasatch AppSec Slack (https://join.slack.com/t/wasatchappsec/shared_invite/zt-h8yyr334-Jz0aQD6CiXMzc5P3e_3JxA) to suggest any additional topics.
Agenda:
12 - 12:50pm
- OWASP SAMM (Software Assurance Maturity Model) with Brian Glas.
12:50 - 1pm
Open Forum, Admin Items, Choose next Guest Speaker
Abstract: OWASP SAMM (https://owaspsamm.org) is the prime maturity model for software assurance that provides an effective and measurable way for all types of organizations to analyze and improve their software security posture. Building security into the software development and management practices of a company can be a daunting task. There are many elements to the equation: company structure, different stakeholders, technology stacks, tools and processes, and so forth. Implementing software assurance will have a significant impact on the organization. Yet, trying to achieve this without a good framework is most likely leading to just marginal and unsustainable improvements. OWASP Software Assurance Maturity Model (SAMM) gives you a structural and measurable framework to do just that. It enables you to formulate and implement a strategy for software security that is tailored to the risk profile of your organization. In this talk, we give an overview of the new release of the SAMM model. After 10 years since its first conception, it was important to align it with today’s development practices.
We will cover a number of topics in the talk: (i) the core structure of the model, which was redesigned and extended to align with modern development practices, (ii) the measurement model which was set up to cover both coverage and quality and (iii) the new security practice streams where the SAMM activities are grouped in maturity levels. We will demonstrate the new SAMM2 toolbox to measure the maturity of an example DevOps team and how you can create a roadmap of activities.
Bio: Brian Glas has worked in IT for almost 20 years and information/application security for the last decade. He started as an enterprise Java developer, then transitioned to helping build an application security program as both tech lead and manager. He later played the role of enterprise architect and did a little incident response and reverse engineering malware for fun. Glas then spent a number of years as a consultant helping clients build AppSec programs, create/update SDLCs, and other related initiatives. He has worked on the Trustworthy Computing team at Microsoft and is now an assistant professor of Computer Science at Union University authoring a Cybersecurity program. He also has been a co-lead for SAMM v2 and the OWASP Top 10.
Leaders Zoom Account Two is inviting you to a scheduled Zoom meeting.
Topic: OWASP SLC/Wasatch AppSec January 2021 Chapter Meeting
Time: Jan 27, 2021 12:00 PM Mountain Time (US and Canada)
Join Zoom Meeting
https://zoom.us/j/99613814556?pwd=eHZjOHhPakZBanlHUXZXbkVocERyUT09
Meeting ID: 996 1381 4556
Passcode: 276752
One tap mobile
+12532158782,,99613814556# US (Tacoma)
+13462487799,,99613814556# US (Houston)
Dial by your location
+1 253 215 8782 US (Tacoma)
+1 346 248 7799 US (Houston)
+1 669 900 6833 US (San Jose)
+1 301 715 8592 US (Washington D.C)
+1 312 626 6799 US (Chicago)
+1 929 436 2866 US (New York)
Meeting ID: 996 1381 4556
Find your local number: https://zoom.us/u/adRd8fuD01

January 2021 Chapter Meeting