welcome to the owasp toronto meetup hello and happy 2018
play

Welcome to the OWASP Toronto Meetup Hello, and happy 2018! - PowerPoint PPT Presentation

Welcome to the OWASP Toronto Meetup Hello, and happy 2018! Announcement: OWASP Top 10 2017 Changes between 2013 and 2017 Hi, I am X. How do I get into AppSec/Security? OWASP Toronto Chapter January 17, 2018 Topics Overviews, Career Paths,


  1. Welcome to the OWASP Toronto Meetup Hello, and happy 2018!

  2. Announcement: OWASP Top 10 2017

  3. Changes between 2013 and 2017

  4. Hi, I am X. How do I get into AppSec/Security? OWASP Toronto Chapter January 17, 2018

  5. Topics Overviews, Career Paths, Advice ● Secure SDLC frameworks ● Tools & Training ● Agile & DevSecOps ● Real Life Stories ● Training, Certifications and Career Fairs ●

  6. Getting the Lay of NICE Cybersecurity Workforce Framework the land SANS CISO Mind Map (or, Refeeq Rehman’s) Find out what jobs/roles are Henry Jiang’s Map of Cyber commonly out there, figure out Security Domains where your skills overlap, find out what skills you need, etc. Cyberseek Career Pathway

  7. Advice Krebs on Security - How to break into Security Series (Older, but still relevant advice) Wisdom, editorials, and on-point snark

  8. Secure SDLC: Some frameworks DOE-C2M2 NIST CSF OWASP SAMM BSIMM

  9. OWASP Software Assurance Maturity Model

  10. BSIMM8 https://www.bsimm.com

  11. US Dept of Energy Capability Maturity Model

  12. NIST Cyber Security Framework

  13. Blogs like SANS AppSec Blog and Google Project Zero General Sources of Info Twitter #appsec and major players, including Michael Geist and Office of the Privacy Commissioner of Canada Teach yourself, then keep up with the field. Infosec industry site has some Security Podcasts like Defensive recommendations you can pick Security through.

  14. General Online Coursera ● Cybrary ● Learning edX ● Lynda (free via Library!) ● MIT Open Coursewear ● Udacity ● Udemy ● Alternatives to Youtube, which actually has some pretty neat stuff on it too.

  15. Audience ... http://money.cnn.com/2017/10/31/media/facebook-twitter-google-congress/index.html What is your job title, and what sources of information do you use regularly?

  16. Point of View: Developers and Testers

  17. OWASP resources OWASP has a lot of projects that can be helpful for developers to start learning about security. Two good starting points: A Quick Developer’s Guide ● OWASP Security Knowledge Framework ● https://create.piktochart.com/output/6400107-untitled-infographic

  18. OWASP Resources OWASP Code Review Guide ● OWASP Developer/Builder ● Cheat Sheets Free Secure Coding Resources* Secure Coding Exercises Hacksplaining ● Code Bashing ● RIPSTECH PHP Security ● Advent Calendar * The latter resources also can be mined for other security-related Other Publications info. CERT Secure Coding ● Safecode training ●

  19. Deliberately Vulnerable Applications Security Testing OWASP Juice Shop ● OWASP WebGoat ● Resources OWASP Security Shepherd ● HTTP Proxies (+ other awesomeness) Learn about the basic classes of application security vulnerabilities OWASP Zed Attack Proxy ● with hands-on, practical, guided (ZAP) lessons. Burp Suite Community Edition ● Kali Linux (+ forensics mode) ●

  20. An Intro to CTFs Capture the Flag! CTF Time Calendar Vulnerable VMs to practice on in a lab, often abstracted from CTFs. https://www.vulnhub.com/ ● Training Wheels are off.... Go hack (they also suggest some resources) stuff.

  21. Real Life Whitehat CERN hacking challenge (students only) Challenges Bug Bounty Programs Legally try your skills against real targets. Be sure to read the instructions, code of ethics, and bounty rules.

  22. Agile? Secure SDLC vs CI (Continuous Integration) and CD (Continuous ● Development / Delivery / Deployment) SDL-Agile Requirements? ● Thoughts from the audience? ●

  23. Point of View: Dev Ops

  24. Secure DevOps Toolchain from SANS https://www.sans.org/security-resources/posters/secure-devops-toolchain-swat-checklist/60/download

  25. Additional OWASP Appsec Pipeline ● DevSecOps Studio ● DevSecOps Awesome DevSecOps ● AWS codepipeline devsecops ● Resources Whether you stay earthbound or go to the cloud.

  26. Point of View: Non-Devs

  27. Learn to Program Check out Laurence Bradford’s list of resources.. Free Code Camp ● Code Wars ● Scripting experience and compiled language programming are both good to have.

  28. Security Origin Stories

  29. Certifications & Career Fairs

  30. (ISC) 2 Not free! ● CISSP (Certified Information Systems Security Professional) ● Concentrations: ○ ISSAP (Architecture) ■ ISSEP (Engineering) ■ ISSMP (Manager) ■ Relevant to application security: ● CSSLP (Certified Secure Software Lifecycle Professional) ○ Others: ● CCSP (Cloud) ○

  31. SANS Courses / GIAC Certifications Not free! ● SANS training courses with associated GIAC certifications ● Relevant to application security: ● GWAPT ○ GWEB ○ GSSP-JAVA, GSSP-NET ○

  32. Pen Testing Certifications Offensive Security Certified Professional (heavy focus on network-based ● content, but still somewhat relevant)

  33. Product Specific Certifications CCNA / CCNE ● Security+ ●

  34. Career Fairs Sheridan College Biztech: February 14, 2018 ● SecTor Expo: October 1-3, 2018 ● TASK: TBD ●

  35. Audience ... AppSec / Security professionals: Hiring managers: ● ● What training or certifications or skills What do you like to see in candidates? have you found to be most useful to your career?

  36. Questions? Closing Comments?

Download Presentation
Download Policy: The content available on the website is offered to you 'AS IS' for your personal information and use only. It cannot be commercialized, licensed, or distributed on other websites without prior consent from the author. To download a presentation, simply click this link. If you encounter any difficulties during the download process, it's possible that the publisher has removed the file from their server.

Recommend


More recommend