AppSec Europe 2014 Project Talk...OWASP Software Assurance Maturity Model (SAMM) ASSES questionnaire...

31
AppSec Europe 2014 Project Talk

Transcript of AppSec Europe 2014 Project Talk...OWASP Software Assurance Maturity Model (SAMM) ASSES questionnaire...

Page 1: AppSec Europe 2014 Project Talk...OWASP Software Assurance Maturity Model (SAMM) ASSES questionnaire GOAL gap analysis PLAN roadmap IMPLEMENT OWASP resources … “ ” PROTECT Tools:

AppSec Europe 2014 Project Talk

Page 2: AppSec Europe 2014 Project Talk...OWASP Software Assurance Maturity Model (SAMM) ASSES questionnaire GOAL gap analysis PLAN roadmap IMPLEMENT OWASP resources … “ ” PROTECT Tools:
Page 3: AppSec Europe 2014 Project Talk...OWASP Software Assurance Maturity Model (SAMM) ASSES questionnaire GOAL gap analysis PLAN roadmap IMPLEMENT OWASP resources … “ ” PROTECT Tools:
Page 4: AppSec Europe 2014 Project Talk...OWASP Software Assurance Maturity Model (SAMM) ASSES questionnaire GOAL gap analysis PLAN roadmap IMPLEMENT OWASP resources … “ ” PROTECT Tools:

� �

Design Build Test Production

vulnerabilityscanning -

WAF

security testingdynamic test

tools

coding guidelines code reviews

static test tools

security requirements /

threat modeling

reactiveproactive

Secure Development Lifecycle(SAMM)

Page 5: AppSec Europe 2014 Project Talk...OWASP Software Assurance Maturity Model (SAMM) ASSES questionnaire GOAL gap analysis PLAN roadmap IMPLEMENT OWASP resources … “ ” PROTECT Tools:

An organization’s behavior changes slowly over time

Changes must be iterative while

working toward long-term goals

There is no single recipe that works

for all organizations

A solution must enable risk-based choices tailored to the organization

Guidance related to security

activities must be prescriptive

A solution must provide enough details for non-security-people

Overall, must be simple, well-defined, and measurable

OWASP Software Assurance

Maturity Model (SAMM)

Page 6: AppSec Europe 2014 Project Talk...OWASP Software Assurance Maturity Model (SAMM) ASSES questionnaire GOAL gap analysis PLAN roadmap IMPLEMENT OWASP resources … “ ” PROTECT Tools:
Page 7: AppSec Europe 2014 Project Talk...OWASP Software Assurance Maturity Model (SAMM) ASSES questionnaire GOAL gap analysis PLAN roadmap IMPLEMENT OWASP resources … “ ” PROTECT Tools:
Page 8: AppSec Europe 2014 Project Talk...OWASP Software Assurance Maturity Model (SAMM) ASSES questionnaire GOAL gap analysis PLAN roadmap IMPLEMENT OWASP resources … “ ” PROTECT Tools:
Page 9: AppSec Europe 2014 Project Talk...OWASP Software Assurance Maturity Model (SAMM) ASSES questionnaire GOAL gap analysis PLAN roadmap IMPLEMENT OWASP resources … “ ” PROTECT Tools:
Page 10: AppSec Europe 2014 Project Talk...OWASP Software Assurance Maturity Model (SAMM) ASSES questionnaire GOAL gap analysis PLAN roadmap IMPLEMENT OWASP resources … “ ” PROTECT Tools:

ASSESquestionnaire

GOALgap analysis

PLAN roadmap

IMPLEMENTOWASP

resources

Page 11: AppSec Europe 2014 Project Talk...OWASP Software Assurance Maturity Model (SAMM) ASSES questionnaire GOAL gap analysis PLAN roadmap IMPLEMENT OWASP resources … “ ” PROTECT Tools:
Page 12: AppSec Europe 2014 Project Talk...OWASP Software Assurance Maturity Model (SAMM) ASSES questionnaire GOAL gap analysis PLAN roadmap IMPLEMENT OWASP resources … “ ” PROTECT Tools:
Page 13: AppSec Europe 2014 Project Talk...OWASP Software Assurance Maturity Model (SAMM) ASSES questionnaire GOAL gap analysis PLAN roadmap IMPLEMENT OWASP resources … “ ” PROTECT Tools:

Page 14: AppSec Europe 2014 Project Talk...OWASP Software Assurance Maturity Model (SAMM) ASSES questionnaire GOAL gap analysis PLAN roadmap IMPLEMENT OWASP resources … “ ” PROTECT Tools:
Page 15: AppSec Europe 2014 Project Talk...OWASP Software Assurance Maturity Model (SAMM) ASSES questionnaire GOAL gap analysis PLAN roadmap IMPLEMENT OWASP resources … “ ” PROTECT Tools:
Page 16: AppSec Europe 2014 Project Talk...OWASP Software Assurance Maturity Model (SAMM) ASSES questionnaire GOAL gap analysis PLAN roadmap IMPLEMENT OWASP resources … “ ” PROTECT Tools:
Page 17: AppSec Europe 2014 Project Talk...OWASP Software Assurance Maturity Model (SAMM) ASSES questionnaire GOAL gap analysis PLAN roadmap IMPLEMENT OWASP resources … “ ” PROTECT Tools:

“ ”

Page 18: AppSec Europe 2014 Project Talk...OWASP Software Assurance Maturity Model (SAMM) ASSES questionnaire GOAL gap analysis PLAN roadmap IMPLEMENT OWASP resources … “ ” PROTECT Tools:
Page 19: AppSec Europe 2014 Project Talk...OWASP Software Assurance Maturity Model (SAMM) ASSES questionnaire GOAL gap analysis PLAN roadmap IMPLEMENT OWASP resources … “ ” PROTECT Tools:
Page 20: AppSec Europe 2014 Project Talk...OWASP Software Assurance Maturity Model (SAMM) ASSES questionnaire GOAL gap analysis PLAN roadmap IMPLEMENT OWASP resources … “ ” PROTECT Tools:

PROTECT

Tools: Enterprise Security API (ESAPI), CSRFGuard, AppSensor, ModSecurity Core Rule Set Project

Docs: Development Guide, Cheat Sheets, Secure Coding Practices - Quick Reference Guide

DETECT

Tools: OWTF, Broken Web Applications Project, Zed Attack Proxy

Docs: Code Review Guide, Testing Guide, Top Ten Project

LIFE CYCLE

SAMM, Application Security Verification Standard, Legal Project, WebGoat, Education Project, Cornucopia

Page 21: AppSec Europe 2014 Project Talk...OWASP Software Assurance Maturity Model (SAMM) ASSES questionnaire GOAL gap analysis PLAN roadmap IMPLEMENT OWASP resources … “ ” PROTECT Tools:

Page 22: AppSec Europe 2014 Project Talk...OWASP Software Assurance Maturity Model (SAMM) ASSES questionnaire GOAL gap analysis PLAN roadmap IMPLEMENT OWASP resources … “ ” PROTECT Tools:
Page 23: AppSec Europe 2014 Project Talk...OWASP Software Assurance Maturity Model (SAMM) ASSES questionnaire GOAL gap analysis PLAN roadmap IMPLEMENT OWASP resources … “ ” PROTECT Tools:

Page 24: AppSec Europe 2014 Project Talk...OWASP Software Assurance Maturity Model (SAMM) ASSES questionnaire GOAL gap analysis PLAN roadmap IMPLEMENT OWASP resources … “ ” PROTECT Tools:
Page 25: AppSec Europe 2014 Project Talk...OWASP Software Assurance Maturity Model (SAMM) ASSES questionnaire GOAL gap analysis PLAN roadmap IMPLEMENT OWASP resources … “ ” PROTECT Tools:

Page 26: AppSec Europe 2014 Project Talk...OWASP Software Assurance Maturity Model (SAMM) ASSES questionnaire GOAL gap analysis PLAN roadmap IMPLEMENT OWASP resources … “ ” PROTECT Tools:
Page 27: AppSec Europe 2014 Project Talk...OWASP Software Assurance Maturity Model (SAMM) ASSES questionnaire GOAL gap analysis PLAN roadmap IMPLEMENT OWASP resources … “ ” PROTECT Tools:
Page 28: AppSec Europe 2014 Project Talk...OWASP Software Assurance Maturity Model (SAMM) ASSES questionnaire GOAL gap analysis PLAN roadmap IMPLEMENT OWASP resources … “ ” PROTECT Tools:
Page 29: AppSec Europe 2014 Project Talk...OWASP Software Assurance Maturity Model (SAMM) ASSES questionnaire GOAL gap analysis PLAN roadmap IMPLEMENT OWASP resources … “ ” PROTECT Tools:
Page 30: AppSec Europe 2014 Project Talk...OWASP Software Assurance Maturity Model (SAMM) ASSES questionnaire GOAL gap analysis PLAN roadmap IMPLEMENT OWASP resources … “ ” PROTECT Tools:
Page 31: AppSec Europe 2014 Project Talk...OWASP Software Assurance Maturity Model (SAMM) ASSES questionnaire GOAL gap analysis PLAN roadmap IMPLEMENT OWASP resources … “ ” PROTECT Tools:

Feb 2014 SecAppDev 2013

• Roles & ResponsibilitiesPeople

• Activities• Deliverables• Control Gates

Process

• Standards & Guidelines• Compliance• Transfer methods

Knowledge

• Development support• Assessment tools• Management tools

Tools & Components

Risk Training