Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

vbu_branch - remote participant related updates #777

Closed
wants to merge 7 commits into from
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 11 additions & 0 deletions content/faq/remote-participant.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
---
title : Remote Participant
layout : FAQ
---

### How do I participate remotely?

This year We created, for each room, a `Google Meet` link.\
We do plan to provide list with links to all available rooms though which the interested remote participants can follow the sessions.

Stay tuned!
1 change: 1 addition & 0 deletions content/tracks/CISO/working-sessions/ciso-roundtable.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,7 @@ participants :
- Ante Gulam
- Kevin Fielder
- Tony Richards
meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
---

<!--(add intro)
Expand Down
3 changes: 2 additions & 1 deletion content/tracks/CISO/working-sessions/cyber-insurance.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,7 @@ status : review-content # draft, review-content, done
categories : ["CISO"]
organizers : ["Yvette Connor"]
description : Session on Cyber Insurance
meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
---

According to industry veteran and Chief of Security Strategy at SentinelOne, Jeremiah Grossman, the security industry must change. Today, the security industry is one of very few businesses that does not offer any guarantees or warranties.
Expand Down Expand Up @@ -80,7 +81,7 @@ The Law of Large Numbers Underwriting
- Simple application
- Broad coverage rating based on domicile, industry, revenue and number of employees
- Streamlined claims process & payment (focused on cyber time vs. natural time)

### Cyber Insurance Trends Worth Watching
Insurance companies realized that the handling of a cyber event can have a significant impact on the total amount of the claim. Therefore, many companies are working to develop Cyber Incident Response services that come bundled with the policies. This way, once an incident takes place, insurance companies can help to minimize the payouts by making sure events are handled appropriately and with all the necessary due process.

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,7 @@ organizers : ["Yvette Connor"]
participants :
- Tony Richards
description : Session on Risk Modeling
meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
---

<!--(add intro)
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,7 @@ status : review-content # draft, review-content, done
organizers :
description :
participants :
meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
---

This Working Session aims to continue the work done at the last Summit on this CDC model.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,7 @@ organizers :
description :
participants :
locked : true
meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
---

AppSec and InfoSec talent are difficult to find these days,
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,7 @@ organizers :
- Sherif Mansour
- Steve Springett
description : Working session with OWASP leaders, MITRE, NIST, and other agencies
meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
---

## WHY
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,7 @@ session_slack: https://os-summit.slack.com/messages/CAV6XTSQL
status : draft # draft, review-content, done
organizers :
description : Working Session for CISOs
meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
---

If you are interested in becoming a Chief Information Security Officer, keep reading and sign up for the Open Security Summit.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -14,9 +14,10 @@ session_slack: https://os-summit.slack.com/messages/CAUNTQ124
status : review-content # draft, review-content, done
description :
organizers :
participants:
participants :
- Russ Miles
- Chris Allen
meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
---

In this session, attendees will learn how to build chaos experiments from scratch using the free and open source Chaos Toolkit.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,7 @@ description : Exploring the Chaos Toolkit's stead-state hypothesis and how one
organizers :
- Russ Miles
participants:
meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session

---

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ description : Practical Guide to Extending the Chaos Toolkit for DevSecOps conc
organizers :
- Russ Miles
participants:

meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
---

The Chaos Toolkit provides a Universal API for Chaos Engineering experiments that is then used to drive various implementations of chaos-causing and system-state-probing functions.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ description : An exploration and working session to characterise, explore and i
organizers :
- Russ Miles
participants:

meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
---

In this session a collection of real-world security cases will be explored through the lens of the chaos engineering discipline.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,7 @@ status : draft
organizers : Franziska Buehler
participants : Tanya Janca
description : Adding OWASP ModSecurity Core Rule Set 3 and Pixi to CircleCI pipeline
meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
---

## Topic
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -13,9 +13,8 @@ status : review-content
organizers :
- PhotoBox-GS
participants :
meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session

---

Hands on session to show participants how to create a Slack bot in Python


Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ status : draft
organizers :
- James Wharton
participants:

meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
---

Based on the ideas and tech provided by ThoughtWorks at https://www.thoughtworks.com/radar
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,7 @@ session_slack: https://os-summit.slack.com/messages/CAVDU1W4S
status : done
organizers : Imran Mohammed A
description : AppSec Metrics and Visualisation
meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
participants :
- Francois Raynaud
- Timo Pagel
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@ participants :
- Timo Pagel
- Jim Newman
description : Using DevSecOps studio to learn and teach Integrating security tools in the SDL
meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
---

Most of today´s application security problems can be traced to flaws in the code. It does not matter whether security issues affect operating system components, client applications, web applications, or other systems, most well-known vulnerabilities are caused by coding errors and implementation issues.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,7 @@ description : Beginner level session on DevSecOps and publishing to the Cloud
organizers :
- Tanya Janca
participants :
meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
---

For many people 'the cloud' and DevSecOps can be a bit mysterious. Let's clear this up with a nice, long, slow demo of how to load up an app in your editor, make a change, run it through your pipeline (and pass the security checkes!), then publish it into the cloud. One step at a time.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@ participants:
- Kevin Fielder
- Wayne Moore
- Mark Regensberg
meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
---

Session to consolidate and publish anonymised real-word playbooks (provided by Summit partipants)
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,7 @@ status : draft
organizers :
- Ann-Marie Grace
participants :
meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
---

Hands on session on how to use JIRA for incident response
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ technology :
session_slack: https://os-summit.slack.com/messages/CAVHKD1TP
description : Hands on session writing security tests
status : draft
meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
organizers :
- Sotiraki Sima
participants :
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,7 @@ status : draft # draft, review-content, done

organizers :
description : Using activity-oriented metrics for Security
meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
---

## WHY
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,7 @@ status : draft # draft, review-content, done
organizers :
- Tanya Janca
description : "DevSecOps: adding security testing, review and configurations to a VSTS pipeline"
meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
---

The OWASP DevSlop VSTS pipeline, affectionately known as "Patty", needs to produce the absolute most secure code possible, as not it is used to release DevSlop.com (our website), it is a proof of concept pipeline for anyone to use, anywhere, for free. Come help us improve the security of this proof of concept but hacking it and helping us add more checks!
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,7 @@ organizers : Ante Gulam
track : DevSecOps
participants :
description : Agile Practices for Security Teams
meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
---

Until recently, cyber security was often considered as “nice to have” in the software development lifecycle. However, due to several data breaches that hit the headlines, more and more dev teams are now starting to incorporate security practices in their processes.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,7 @@ status : review-content # draft, review-content, done
organizers :
participants : Francois Raynaud
description : AppSec SOC Monitoring Visualisation
meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
---

## Why
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,7 @@ participants:
- Timo Pagel

description : DevSecOps Maturity Model (DSOMM)
meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
---

<!-- (add more details about DevSecOps Maturity Model here)
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,7 @@ description : Best practice cheat sheet for integrating Agile Security into the
organizers :
- Tony Richards
participants :
meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
---

## Why
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,7 @@ status : review-content # draft, review-content, done
organizers : Imran Mohammed A
participants : Francois Raynaud
description : Integrate security tools as part of CI/CD pipeline to find/fix issues early in SDL
meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
---

Most of today´s application security problems can be traced to flaws in the code. It does not matter whether security issues affect operating system components, client applications, web applications, or other systems, most well-known vulnerabilities are caused by coding errors and implementation issues.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,7 @@ session_slack: https://os-summit.slack.com/messages/CAVD5BNRY
status : done
organizers : ["Fraser Scott"]
description : A beta session of the OWASP Cloud Security Workshop (not to be scheduled on the Tuesday)
meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
---

The OWASP Cloud Security project aims to help people secure their products and services running in the cloud by providing a set of easy to use threat and control BDD stories that pool together the expertise and experience of the development, operations, and security communities.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,7 @@ organizers :
participants :
- Francois Raynaud
description : Working Sessions for Owasp Defect Dojo
meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
---
An open source vulnerability management tool that streamlines the testing process by offering templating, report generation, metrics, and baseline self-service tools.

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,7 @@ participants :
- Onkar Dhane
- Stephen Hookings
description : Working Sessions for Owasp DevSecOps Studio
meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
---

DevSecOps Studio is one of its kind, self contained DevSecOps environment/distribution to help individuals in learning DevSecOps concepts. It takes lots of efforts to setup the environment for training/demos and more often, its error prone when done manually. DevSecOps Studio is easy to get started, mostly automatic and battle tested during our Free Practical DevSecOps Course at https://www.teachera.io/devsecops-course/
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,7 @@ outcomes_2017: https://owaspsummit.org/Outcomes/GitHub-Security-Feature-Request.
organizers :
description : How to secure Github Integrations
participants :
meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
---

## Why
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,7 @@ organizers :
- Francois Raynaud
description : Secure the CI/CD pipeline
participants :
meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
---

## Why
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,7 @@ status : review-content # draft, review-content, done
organizers :
description :
participants :
meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
---

Security Champions are a key element of any AppSec team, since they create a cross-functional team focused on Application Security.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,7 @@ description : Working Sessions for Security Crowdsourcing
organizers :
- Stu Hirst
participants :
meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
---

Security crowdsourcing is necessary - it is allowing highly talented individuals and resourceful organisations to use the power of their intelligence, skills and resources to fight cyber threats.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,7 @@ description :
participants :
organizers :
- Adrian Winckles
meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
---

We're rebooting the OWASP Distributed Web Application Honeypot Project which Ryan Barnett used to lead and fell dormant due to a change of employer. We now have the capacity to host a new community reporting server in ARU's new research lab (as well as plenty of physical server capacity).
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ description :
organizers :
- Yuriy Ackermann
participants :

meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
---

See how this [Web Authentication: What It Is and What It Means for Passwords](https://duo.com/blog/web-authentication-what-it-is-and-what-it-means-for-passwords)
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -15,8 +15,8 @@ description : Ask all the burning questions you have on GDPR
organizers :
- Tony Richards
participants :
meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session

---

'Ask Me Anything' session where tech and non-tech people can ask anything someone who is from the industry relating to GDPR

Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ participants :
invited:
- Dinis Cruz
- Fernanda Almeida

meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
---

## Topic
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,7 @@ organizers :
participants :
- Mario Platt
- Goher Mohammad
meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
---

Create graphs as shows in the https://github.com/pbx-gs/gdpr-patterns project
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,7 @@ description : Hands on user session on how to use Threat Models in GDPR mapping
organizers :
- Sotiraki Sima
participants :
meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
---

Hands on user session on how to use Threat Models in GDPR mappings
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,7 @@ status : review-content # draft, review-content, done
description : What is the best way to become an DPO (Data Protection Officer)
organizers :
participants :
meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
---

So You want to be a Data protection Officer?
Expand Down
1 change: 1 addition & 0 deletions content/tracks/GDPR/working-sessions/DPO-what-to-expect.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,7 @@ status : review-content # draft, review-content, done
description : What should be expected of DPOs (Data Protection Officers)
organizers :
participants :
meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
---

A Data Protection Officer is acting in an independent manner.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,7 @@ status : done # draft, review-content, done
description : Working Session on reviewing and agreeing on a set of GDPR patterns
organizers :
- Mario Platt
meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
---

GDPR Patterns are reusable mappings of data journeys across specific threat modelling
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -13,9 +13,10 @@ room_id : table-2
session_slack: https://os-summit.slack.com/messages/CAUSB0YG1
status : # draft, review-content, done
description : Mapping out the multiple differences across the EU
meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
organizers :
participants :

- Tony Richards
---

Within GRPR members there are already legal variations with national laws.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ session_slack: https://os-summit.slack.com/messages/CAV6AK0J0
status : review-content # draft, review-content, done
description : How to create positive feedback loops between the multiple teams aiming for GDPR Compliance
organizers :
participants :
meet_url : #URL to the relevant Google Meet Room thus the remote participants can join a session
---

There are a lots of good things behind the GDRR
Expand Down
Loading