Re: [SC-L] win win for owasp and television spots

2010-01-23 Thread Neil Matatall
Don¹t forget to mention how individuals can get involved with OWASP ;)  Like
mailing lists, local chapter meetings and larger events such as AppSec 2010
(from 9/7-9/10) 

Neil

On 1/22/10 6:50 AM, "Justin Clarke"  wrote:

> Hi Matt,
> 
> What would be very good is if you can talk to the (newly created) OWASP
> Connections Committee. I believe your best contact would be Lorna Alamri,
> who is heading up our PR initiative.
> 
> Best regards
> 
> Justin
> 
> 
> On 22/01/2010 10:39, "Matt Parsons"  wrote:
> 
>> > Ladies and Gentlemen,
>> > I am starting to get approached by a few television stations to talk about
>> > application security.  I would like to promote Owasp in these talks.  What
>> > would be the best way to do it professionally and competently?
>> >
>> > See below news story.
>> >
>> > Thanks,
>> > Matt
>> >
>> >
>> > http://www.the33tv.com/news/kdaf-password-security-jim,0,3650695.story
>> >
>> >
>> >
>> > Matt Parsons, MSM, CISSP
>> > 315-559-3588 Blackberry
>> > 817-294-3789 Home office
>> > mailto:mparsons1...@gmail.com
>> > http://www.parsonsisconsulting.com
>> > http://www.o2-ounceopen.com/o2-power-users/
>> > http://www.linkedin.com/in/parsonsconsulting
>> > http://parsonsisconsulting.blogspot.com/
>> >
>> >
>> >
>> >
>> > ___
>> > Secure Coding mailing list (SC-L) SC-L@securecoding.org
>> > List information, subscriptions, etc -
>> http://krvw.com/mailman/listinfo/sc-l
>> > List charter available at - http://www.securecoding.org/list/charter.php
>> > SC-L is hosted and moderated by KRvW Associates, LLC (http://www.KRvW.com)
>> > as a free, non-commercial service to the software security community.
>> > ___
> 
> 
> ___
> Secure Coding mailing list (SC-L) SC-L@securecoding.org
> List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l
> List charter available at - http://www.securecoding.org/list/charter.php
> SC-L is hosted and moderated by KRvW Associates, LLC (http://www.KRvW.com)
> as a free, non-commercial service to the software security community.
> ___
> 



smime.p7s
Description: S/MIME cryptographic signature
___
Secure Coding mailing list (SC-L) SC-L@securecoding.org
List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l
List charter available at - http://www.securecoding.org/list/charter.php
SC-L is hosted and moderated by KRvW Associates, LLC (http://www.KRvW.com)
as a free, non-commercial service to the software security community.
___


Re: [SC-L] Where Does Secure Coding Belong In the Curriculum?

2009-08-21 Thread Neil Matatall

Everyone,

Thank you for all of the input.  Really.  This information has been 
extremely helpful! 


Neil

Goertzel, Karen [USA] wrote:

Here's an extract from the Information Assurance Technology Analysis Center (part of 
DTIC) "Software Security Assurance: A State of the Art Report" 
(http://iac.dtic.mil/iatac/download/security.pdf):

Courses on secure software development, secure programming, etc., typically
begin by introducing common attacks against software-intensive information
systems and the vulnerabilities targeted by those attacks, then progress to
modeling, design, coding, and testing practices that software developers can 
adopt
to reduce the likelihood that exploitable vulnerabilities will appear in the 
software
they produce. The following is a representative sampling of such courses:

- Arizona State University: Software Security
- Ben-Gurion University (Beer-Sheva, Israel): Security of Software Systems
- Carnegie Mellon University (CMU) and University of Ontario (Canada):
Secure Software Systems
- George Mason University: Secure Software Design and Programming
- George Washington University: Security and Programming Languages
- Catholic University of Leuven (Belgium): Development of Secure Software
- New Mexico Tech: Secure Software Construction
- North Dakota State University: Engineering Secure Software
- Northeastern University: Engineering Secure Software Systems
- Northern Kentucky University, Rochester Institute of Technology, and
University of Denver: Secure Software Engineering
- Polytechnic University: Application Security
- Purdue University: Secure Programming
- Queen’s University (Kingston, ON, Canada): Software Reliability
and Security
- Santa Clara University: Secure Coding in C and C++
- University of California at Berkeley, Walden University (online): Secure
Software Development
- University of California at Santa Cruz: Software Security Testing
- University of Canterbury (New Zealand): Secure Software
- University of Nice Sophia-Antipolis (Nice, France): Formal Methods
and Secure Software
- University of Oxford (UK): Design for Security
- University of South Carolina: Building Secure Software.

As noted earlier, other schools offer lectures on secure coding and other
software security relevant topics within their larger software engineering or
computer security course offerings. At least two universities - the University
of Texas at San Antonio and University of Dublin (Ireland) - have established
reading groups focusing on software security.

As part of its Trustworthy Computing initiative, Microsoft Research
has established its Trustworthy Computing Curriculum program [309] for
promoting university development of software security curricula. Interested
institutions submit proposals to Microsoft, and those that are selected are
provided seed funding for course development.

Another recent trend is post-graduate degree programs with specialties
or concentrations in secure software engineering (or security engineering for
software-intensive systems). Some of these are standard degree programs,
while others are specifically designed for the continuing education of working
professionals. The following are typical examples:

- James Madison University: Master of Science in Computer Science with
a Concentration in Secure Software Engineering
- Northern Kentucky University: Graduate Certificate in Secure
Software Engineering
- Stanford University: Online Computer Security Certificate in Designing
Secure Software From the Ground Up
- University of Colorado at Colorado Springs: Graduate Certificate in
Secure Software Systems
- Walden University (online): Master of Science in Software Engineering
with a Specialization in Secure Computing
- University of Central England at Birmingham: Master of Science in
Software Development and Security
- Chalmers University (Gothenburg, Sweden): Master of Science in
Secure and Dependable Computer Systems.

In another interesting trend (to date, exclusively in non-US schools),
entire academic departments - and in one case a whole graduate school—are
being devoted to teaching and research in software dependability, including
security, e.g.:

- University of Oldenburg (Germany) TrustSoft Graduate School of
Trustworthy Software Systems
- Fraunhofer Institute for Experimental Software Engineering (IESE)
(Kaiserslautern, Germany): Department of Security and Safety
- Bond University (Queensland, Australia): Centre for Software Assurance.


Karen Mercedes Goertzel, CISSP
Associate
703.698.7454
goertzel_ka...@bah.com

From: sc-l-boun...@securecoding.org [sc-l-boun...@securecoding.org] On Behalf 
Of Gary McGraw [...@cigital.com]
Sent: Thursday, August 20, 2009 2:55 PM
To: Neil Matatall; Secure Code Mailing List
Subject: Re: [SC-L] Where Does Secure Coding Belong In the Curriculum?

hi neil,

For what it's worth, there is a list of universities with some kind of software security 
curriculum on 

[SC-L] Where Does Secure Coding Belong In the Curriculum?

2009-08-20 Thread Neil Matatall
Inspired by the "What is the size of this list?" discussion, I decided I 
won't be a lurker :)


A question prompted by 
http://michael-coates.blogspot.com/2009/04/universities-web-app-security.html 
 
and the OWASP podcast mentions


So where does secure coding belong in the curriculum?

Higher Ed?  High School?

Undergrad? Grad? Extension?

I started a discussion in the Educause group on linked in.  I guess it 
requires authentication and possibly group membership: 
http://www.linkedin.com/groupAnswers?viewQuestionAndAnswers=&gid=138011&discussionID=5737656


It looks like some Universities are offering courses now...

Neil
___
Secure Coding mailing list (SC-L) SC-L@securecoding.org
List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l
List charter available at - http://www.securecoding.org/list/charter.php
SC-L is hosted and moderated by KRvW Associates, LLC (http://www.KRvW.com)
as a free, non-commercial service to the software security community.
___