Application Portfolio Risk Ranking: Banishing Fud With Structure And Numbers presented at OWASP Appsec 2010

by Dan Dan cornell (Denim Group),

Tags: Security Application Security


Summary : Far too often application security decisions are made in an ad hoc manner and based on little or no data. This leads to an inefficient allocation of scarce resources. To move beyond fear, uncertainty and doubt, organizations must adopt an approach to application risk management based on a structured process and quantitative data. This talk outlines such an approach for organizations to enumerate all the applications in their portfolio. It then goes through background information to collect for each application to support further decision-making. In addition, the talk presents an application risk-ranking framework allowing security analysts to quantitatively categorize their application assets and then plan for assessment activities based on available budgets. Attendees will leave with the knowledge and tools required for them to use the approach on the applications they are responsible for in their organization. Template spreadsheets and a How-To guide will also be provided.

Dan Dan cornell: Dan Cornell has over twelve years of experience architecting, developing and securing web-based software systems. As a Principal of Denim Group, he leads the organization's technology team overseeing methodology development and project execution for Denim Group's customers. He also heads the Denim Group application security research team, investigating the application of secure coding and development techniques to the improvement of web based software development methodologies.