Looks like this event has already ended.

Check out upcoming events by this organizer, or organize your very own event.

View upcoming events Create an event

Darren Meyer - Selling Static Analysis: How to Start Fast and Finish Strong

OWASP MSP

Monday, June 27, 2011 from 6:00 PM to 8:00 PM (CDT)

Hopkins, MN

Darren Meyer - Selling Static Analysis: How to Start Fast...

Ticket Information

Type Remaining End     Quantity
Darren Meyer   more info 22 tickets Ended Free  
SHARE THIS EVENT

Event Details

 

OWASP MSP PRESENTS

 

Darren Meyer

Selling Static Analysis: How to Start Fast and Finish Strong

 

Date: Monday, June 27, 2011

Agenda:

6:00 PM Room opens for networking, CPE signup

6:25 PM Welcome: OWASP chapter updates

6:30 PM Darren Meyer

7:30 PM Upcoming events reminder and meeting wrap-up

Thank You: Concord for sponsoring our meeting location. Please contact Lorna at lorna.alamri@owasp.org or 651-338-0243 if you would like to sponsor a meeting or meeting location for an upcoming OWASP MSP meeting.


 

The Presentation:

 

Selling Static Analysis: How to Start Fast and Finish Strong

 

Static Code Analysis tools are a wonderful addition to a strong application security program for any large-scale development effort - but their expense often causes management heartburn.  This talk addresses how to:

1. Convince management of the value a Static Code Analysis tool can provide
2. Sell process over product
3. Get development teams on your side
4. Get a "quick and dirty" Static Code Analysis program up and running
5. Expand that nascent program into a mature part of a Secure SDLC
5a. Use Static Code Analysis to drive building a Secure SDLC if you don't have one

The material covered is based on the speaker's personal experience trying, failing, trying, and finally succeeding in accomplishing these things.

Part 1 - Convincing management

This segment covers approaches to articulating value of a Static Code Analysis tool - with or without an existing Secure SDLC program - to organization decision makers. In other words, this segment covers how to do a good sales job by showing managers things they care about.

FUD is discouraged.

Part 2 - Selling process over product

This segment emphasizes the importance of building good process - and advertising it - over selecting any particular product.

Part 3 - Getting development teams on your side

This segment covers various techniques to successfully market Static Code Analysis tools and processes to development teams. Successful marketing means that developers are pressuring their management to support adopting an Static Code Analysis process.

Included are common responses developers have to proposals to integrate Static Code Analysis toolkits and processes to their workflow, and responses that do and don't work.

Part 4 - Quick start

This segment covers rapidly and inexpensively building a proof of concept Static Code Analysis that highlights the need for sound process, but still returns a great deal of provable value. It also covers useful metrics and reporting to capture that can bolster the argument for an organization-wide adoption.

Risks and trade-offs of taking this approach are discussed.

Part 5 - Integrating into the SDLC

This segment covers "where to go from here" after a successful proof of concept. Considerations for integrating with Secure SDLCs at various points of maturity are provided, as well as discussions of making processes adaptable to various development lifecycle frameworks (e.g. waterfall, agile, etc.).

Also covered is how to use support for Static Code Analysis to drive building a Secure SDLC in an organization that's resistant to SDLC changes.

Throughout each section, security as an aspect of overall quality is emphasized, as well as the social aspects of successfully building this component of a Secure SDLC.
 

The Speaker:

Darren Meyer

Darren is a senior technical architect working in application security at a large company in the Twin Cities area. He has over a decade of software development experience that informs his desire to support and educate developers in application security practice.

Thank you to our meeting sponsor, Concord.

Location: Concord, 509 2nd Avenue S, Hopkins MN 55343. [Main Entrance Lobby]

 

 


 

Registration closes at 3:00 PM Central Time on the day of the meeting.

Registration is required.

When & Where



Concord
509 2nd Avenue S
Hopkins, MN 55343

Monday, June 27, 2011 from 6:00 PM to 8:00 PM (CDT)


  Add to my calendar

Organizer

OWASP MSP

The Open Web Application Security Project (OWASP) is an open community dedicated to enabling organizations to conceive, develop, acquire, operate, and maintain applications that can be trusted. All of the OWASP tools, documents, forums, and chapters are free and open to anyone interested in improving application security. We advocate approaching application security as a people, process, and technology problem because the most effective approaches to application security include improvements in all of these areas. The OWASP Minneapolis-St. Paul chapter was host to OWASP AppSec USA 2011 at the Minneapolis Convention Center September 20-23, 2011. Get the presentation material at http://www.appsecusa.org/.

  Contact the Organizer

Please log in or sign up

In order to purchase these tickets in installments, you'll need an Eventbrite account. Log in or sign up for a free account to continue.