SlideShare a Scribd company logo
1 of 20
Download to read offline
OpenSAMM in the Real World:
                      Pitfalls Discovered and Treasure
                          Collected Along the Way
                      Philip J. Beyer - Texas Education Agency
                                    philip.beyer@tea.state.tx.us   @pjbeyer
                                    Scott Stevens - Denim Group
                                          sstevens@denimgroup.com



Copyright 2011 by Texas Education
Agency. All rights reserved.                        LASCON 2011               http://lanyrd.com/shgmf   1
Overview
•     Background
•     The Manual
•     The Premise
•     Treasures and Pitfalls
•     Game Over




Copyright 2011 by Texas Education
Agency. All rights reserved.          LASCON 2011   http://lanyrd.com/shgmf   2
About
• Phil Beyer
         – Information Security Officer
         – Consulting background
• Scott Stevens
         – Project Manager
         – Application development background
• TEA
         – ~700 employees
         – ~1200 school districts
         – ~5 million students

Copyright 2011 by Texas Education
Agency. All rights reserved.        LASCON 2011   http://lanyrd.com/shgmf   3
Where Did TEA Start?
• Application Security Program already
  established
         – Some policies & procedures
         – Initial training & exposure to concepts
         – Historically siloed approach
• Outsourcing for subject matter expertise



Copyright 2011 by Texas Education
Agency. All rights reserved.            LASCON 2011   http://lanyrd.com/shgmf   4
Where Do You Start?
•     Establish your Application Security Program
•     Be the Champion (or find one)
•     Make sure your Team Gets It
•     Have a Roadmap to Maturity




Copyright 2011 by Texas Education
Agency. All rights reserved.               LASCON 2011   http://lanyrd.com/shgmf   5
The Manual
                                    Business Functions




Copyright 2011 by Texas Education
Agency. All rights reserved.               LASCON 2011   http://lanyrd.com/shgmf   6
The Manual
                                    Security Practices




Copyright 2011 by Texas Education
Agency. All rights reserved.              LASCON 2011    http://lanyrd.com/shgmf   7
The Manual
               Phases
1. The Early Levels
2. Racking Up Some
   Points
3. Hitting Your Stride
4. Bigger Treasures,
   Deeper Pits
    The End Game

Copyright 2011 by Texas Education
Agency. All rights reserved.
The Premise
• It has already started
• Shortcuts don’t exist
         – No cheat codes
         – No invincibility
         – No God mode
• There are Pitfalls
• There are Treasures

Copyright 2011 by Texas Education
Agency. All rights reserved.           LASCON 2011   http://lanyrd.com/shgmf   9
The Early Levels (Phase 1)
                                    Treasures
• A Map
         – Not necessarily THE Map, but
           something to get started
         – An organizational roadmap is a
           powerful thing
• Some Running Room
         – Awareness in the organization is
           increasing


Copyright 2011 by Texas Education                    http://lanyrd.com/shgmf
                                      LASCON 2011
Agency. All rights reserved.                                              10
The Early Levels (Phase 1)
                                     Pitfalls
• The Log
         – You can’t stand still
         – Move through Phase 1 so you
           don’t get rolled over
• Inertia
         – Getting started is just plain hard
         – Determining who should play is
           also hard

Copyright 2011 by Texas Education                    http://lanyrd.com/shgmf
                                      LASCON 2011
Agency. All rights reserved.                                              11
Racking Up Some Points (Phase 2)
                      Treasures
• Silver Bars
         – Development teams begin to
           appreciate the security problem


• The Ladder
         – More of the team is involved in
           practicing security
         – You’ve found a new way around
           the alligator-infested pond
Copyright 2011 by Texas Education                 http://lanyrd.com/shgmf
                                    LASCON 2011
Agency. All rights reserved.                                           12
Racking Up Some Points (Phase 2)
                       Pitfalls
• The Alligator
         – There’s a dangerous thing there
           on the screen
         – Threats are real, and now they
           see some of them too
• More Players
         – Other people are going to play
           your game
         – They may not play as { nice |
           carefully | safely } as you
Copyright 2011 by Texas Education                 http://lanyrd.com/shgmf
                                    LASCON 2011
Agency. All rights reserved.                                           13
Hitting Your Stride (Phase 3)
                                 Treasures
• Gold Bars
         – Better visibility instills confidence
           in Management
• The Compass
         – The Program has direction
         – From requirements to
           maintenance, a formal process
           starts to emerge


Copyright 2011 by Texas Education                  http://lanyrd.com/shgmf
                                    LASCON 2011
Agency. All rights reserved.                                            14
Hitting Your Stride (Phase 3)
                                  Pitfalls
• The Scorpion
         – Better informed Management
           may sting
• The Wall
         – A different kind of obstacle will
           block your path
         – Developers and Operators may
           not enjoy working together
           more closely
Copyright 2011 by Texas Education                 http://lanyrd.com/shgmf
                                    LASCON 2011
Agency. All rights reserved.                                           15
Bigger Treasures, Deeper Pits (Phase 4)
              Treasures
• The Bridge
         – Get rid of that Rope and jeer at
           the Alligators as you walk across
         – The whole Program is working
           together to build securely and
           verify aggressively




Copyright 2011 by Texas Education                 http://lanyrd.com/shgmf
                                    LASCON 2011
Agency. All rights reserved.                                           16
Bigger Treasures, Deeper Pits (Phase 4)
                Pitfalls
• The Hole
         – Compliance is not Security
         – Don’t let Management fall into the
           trap at this stage of the game… It
           can be a pretty deep pit




Copyright 2011 by Texas Education                 http://lanyrd.com/shgmf
                                    LASCON 2011
Agency. All rights reserved.                                           17
The End Game (Phases 5 & 6)
                             Treasures
• Shangri-La
         – You’ve reached the mystical,
           harmonious valley; a
           permanently happy land
           isolated from the outside world
         – I’d tell you how it feels, but we
           haven’t gotten there yet



Copyright 2011 by Texas Education                 http://lanyrd.com/shgmf
                                    LASCON 2011
Agency. All rights reserved.                                           18
It’s Time to Play
• Build a Mature Software Assurance Program
• Measure and Report Your Progress
• Have Fun!




Copyright 2011 by Texas Education                       http://lanyrd.com/shgmf
                                          LASCON 2011
Agency. All rights reserved.                                                 19
Resources
• OWASP – Open Web Application Security Project
         – http://www.owasp.org/
• OpenSAMM - Software Assurance Maturity Model
         – http://www.opensamm.org/

• Attribution
         – All OpenSAMM images are licensed under the Creative Commons
           Attribution-Share Alike 3.0 License.



Copyright 2011 by Texas Education                            http://lanyrd.com/shgmf
                                      LASCON 2011
Agency. All rights reserved.                                                      20

More Related Content

More from Philip Beyer

Choose to Lead: The Information Security Profession Needs You!
Choose to Lead: The Information Security Profession Needs You!Choose to Lead: The Information Security Profession Needs You!
Choose to Lead: The Information Security Profession Needs You!Philip Beyer
 
Risk Explained... in 5 Minutes or Less
Risk Explained... in 5 Minutes or LessRisk Explained... in 5 Minutes or Less
Risk Explained... in 5 Minutes or LessPhilip Beyer
 
The Myth of a Perfect Security Program ... The Reality of Eternal Life
The Myth of a Perfect Security Program ... The Reality of Eternal LifeThe Myth of a Perfect Security Program ... The Reality of Eternal Life
The Myth of a Perfect Security Program ... The Reality of Eternal LifePhilip Beyer
 
(Consulting) Couch to CISO: A Security Leader's First 100 Days and Beyond
(Consulting) Couch to CISO: A Security Leader's First 100 Days and Beyond(Consulting) Couch to CISO: A Security Leader's First 100 Days and Beyond
(Consulting) Couch to CISO: A Security Leader's First 100 Days and BeyondPhilip Beyer
 
Secure SDLC in the Real World: Pitfalls Discovered and Treasure Collected Alo...
Secure SDLC in the Real World: Pitfalls Discovered and Treasure Collected Alo...Secure SDLC in the Real World: Pitfalls Discovered and Treasure Collected Alo...
Secure SDLC in the Real World: Pitfalls Discovered and Treasure Collected Alo...Philip Beyer
 
Lean and (Prepared for) Mean: Application Security Program Essentials
Lean and (Prepared for) Mean: Application Security Program EssentialsLean and (Prepared for) Mean: Application Security Program Essentials
Lean and (Prepared for) Mean: Application Security Program EssentialsPhilip Beyer
 

More from Philip Beyer (6)

Choose to Lead: The Information Security Profession Needs You!
Choose to Lead: The Information Security Profession Needs You!Choose to Lead: The Information Security Profession Needs You!
Choose to Lead: The Information Security Profession Needs You!
 
Risk Explained... in 5 Minutes or Less
Risk Explained... in 5 Minutes or LessRisk Explained... in 5 Minutes or Less
Risk Explained... in 5 Minutes or Less
 
The Myth of a Perfect Security Program ... The Reality of Eternal Life
The Myth of a Perfect Security Program ... The Reality of Eternal LifeThe Myth of a Perfect Security Program ... The Reality of Eternal Life
The Myth of a Perfect Security Program ... The Reality of Eternal Life
 
(Consulting) Couch to CISO: A Security Leader's First 100 Days and Beyond
(Consulting) Couch to CISO: A Security Leader's First 100 Days and Beyond(Consulting) Couch to CISO: A Security Leader's First 100 Days and Beyond
(Consulting) Couch to CISO: A Security Leader's First 100 Days and Beyond
 
Secure SDLC in the Real World: Pitfalls Discovered and Treasure Collected Alo...
Secure SDLC in the Real World: Pitfalls Discovered and Treasure Collected Alo...Secure SDLC in the Real World: Pitfalls Discovered and Treasure Collected Alo...
Secure SDLC in the Real World: Pitfalls Discovered and Treasure Collected Alo...
 
Lean and (Prepared for) Mean: Application Security Program Essentials
Lean and (Prepared for) Mean: Application Security Program EssentialsLean and (Prepared for) Mean: Application Security Program Essentials
Lean and (Prepared for) Mean: Application Security Program Essentials
 

Recently uploaded

Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubKalema Edgar
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebUiPathCommunity
 
The State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxThe State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxLoriGlavin3
 
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfHyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfPrecisely
 
Moving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfMoving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfLoriGlavin3
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsRizwan Syed
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 3652toLead Limited
 
What is DBT - The Ultimate Data Build Tool.pdf
What is DBT - The Ultimate Data Build Tool.pdfWhat is DBT - The Ultimate Data Build Tool.pdf
What is DBT - The Ultimate Data Build Tool.pdfMounikaPolabathina
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Mark Simos
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsSergiu Bodiu
 
Commit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyCommit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyAlfredo García Lavilla
 
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024BookNet Canada
 
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxDigital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxLoriGlavin3
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii SoldatenkoFwdays
 
SALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICESSALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICESmohitsingh558521
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc
 
unit 4 immunoblotting technique complete.pptx
unit 4 immunoblotting technique complete.pptxunit 4 immunoblotting technique complete.pptx
unit 4 immunoblotting technique complete.pptxBkGupta21
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfAlex Barbosa Coqueiro
 
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxLoriGlavin3
 

Recently uploaded (20)

Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding Club
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio Web
 
The State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxThe State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptx
 
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfHyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
 
Moving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfMoving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdf
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL Certs
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365
 
What is DBT - The Ultimate Data Build Tool.pdf
What is DBT - The Ultimate Data Build Tool.pdfWhat is DBT - The Ultimate Data Build Tool.pdf
What is DBT - The Ultimate Data Build Tool.pdf
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platforms
 
Commit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyCommit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easy
 
DMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special EditionDMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special Edition
 
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
 
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxDigital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko
 
SALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICESSALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICES
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
 
unit 4 immunoblotting technique complete.pptx
unit 4 immunoblotting technique complete.pptxunit 4 immunoblotting technique complete.pptx
unit 4 immunoblotting technique complete.pptx
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdf
 
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
 

OpenSAMM in the Real World: Pitfalls Discovered and Treasures Collected Along the Way

  • 1. OpenSAMM in the Real World: Pitfalls Discovered and Treasure Collected Along the Way Philip J. Beyer - Texas Education Agency philip.beyer@tea.state.tx.us @pjbeyer Scott Stevens - Denim Group sstevens@denimgroup.com Copyright 2011 by Texas Education Agency. All rights reserved. LASCON 2011 http://lanyrd.com/shgmf 1
  • 2. Overview • Background • The Manual • The Premise • Treasures and Pitfalls • Game Over Copyright 2011 by Texas Education Agency. All rights reserved. LASCON 2011 http://lanyrd.com/shgmf 2
  • 3. About • Phil Beyer – Information Security Officer – Consulting background • Scott Stevens – Project Manager – Application development background • TEA – ~700 employees – ~1200 school districts – ~5 million students Copyright 2011 by Texas Education Agency. All rights reserved. LASCON 2011 http://lanyrd.com/shgmf 3
  • 4. Where Did TEA Start? • Application Security Program already established – Some policies & procedures – Initial training & exposure to concepts – Historically siloed approach • Outsourcing for subject matter expertise Copyright 2011 by Texas Education Agency. All rights reserved. LASCON 2011 http://lanyrd.com/shgmf 4
  • 5. Where Do You Start? • Establish your Application Security Program • Be the Champion (or find one) • Make sure your Team Gets It • Have a Roadmap to Maturity Copyright 2011 by Texas Education Agency. All rights reserved. LASCON 2011 http://lanyrd.com/shgmf 5
  • 6. The Manual Business Functions Copyright 2011 by Texas Education Agency. All rights reserved. LASCON 2011 http://lanyrd.com/shgmf 6
  • 7. The Manual Security Practices Copyright 2011 by Texas Education Agency. All rights reserved. LASCON 2011 http://lanyrd.com/shgmf 7
  • 8. The Manual Phases 1. The Early Levels 2. Racking Up Some Points 3. Hitting Your Stride 4. Bigger Treasures, Deeper Pits The End Game Copyright 2011 by Texas Education Agency. All rights reserved.
  • 9. The Premise • It has already started • Shortcuts don’t exist – No cheat codes – No invincibility – No God mode • There are Pitfalls • There are Treasures Copyright 2011 by Texas Education Agency. All rights reserved. LASCON 2011 http://lanyrd.com/shgmf 9
  • 10. The Early Levels (Phase 1) Treasures • A Map – Not necessarily THE Map, but something to get started – An organizational roadmap is a powerful thing • Some Running Room – Awareness in the organization is increasing Copyright 2011 by Texas Education http://lanyrd.com/shgmf LASCON 2011 Agency. All rights reserved. 10
  • 11. The Early Levels (Phase 1) Pitfalls • The Log – You can’t stand still – Move through Phase 1 so you don’t get rolled over • Inertia – Getting started is just plain hard – Determining who should play is also hard Copyright 2011 by Texas Education http://lanyrd.com/shgmf LASCON 2011 Agency. All rights reserved. 11
  • 12. Racking Up Some Points (Phase 2) Treasures • Silver Bars – Development teams begin to appreciate the security problem • The Ladder – More of the team is involved in practicing security – You’ve found a new way around the alligator-infested pond Copyright 2011 by Texas Education http://lanyrd.com/shgmf LASCON 2011 Agency. All rights reserved. 12
  • 13. Racking Up Some Points (Phase 2) Pitfalls • The Alligator – There’s a dangerous thing there on the screen – Threats are real, and now they see some of them too • More Players – Other people are going to play your game – They may not play as { nice | carefully | safely } as you Copyright 2011 by Texas Education http://lanyrd.com/shgmf LASCON 2011 Agency. All rights reserved. 13
  • 14. Hitting Your Stride (Phase 3) Treasures • Gold Bars – Better visibility instills confidence in Management • The Compass – The Program has direction – From requirements to maintenance, a formal process starts to emerge Copyright 2011 by Texas Education http://lanyrd.com/shgmf LASCON 2011 Agency. All rights reserved. 14
  • 15. Hitting Your Stride (Phase 3) Pitfalls • The Scorpion – Better informed Management may sting • The Wall – A different kind of obstacle will block your path – Developers and Operators may not enjoy working together more closely Copyright 2011 by Texas Education http://lanyrd.com/shgmf LASCON 2011 Agency. All rights reserved. 15
  • 16. Bigger Treasures, Deeper Pits (Phase 4) Treasures • The Bridge – Get rid of that Rope and jeer at the Alligators as you walk across – The whole Program is working together to build securely and verify aggressively Copyright 2011 by Texas Education http://lanyrd.com/shgmf LASCON 2011 Agency. All rights reserved. 16
  • 17. Bigger Treasures, Deeper Pits (Phase 4) Pitfalls • The Hole – Compliance is not Security – Don’t let Management fall into the trap at this stage of the game… It can be a pretty deep pit Copyright 2011 by Texas Education http://lanyrd.com/shgmf LASCON 2011 Agency. All rights reserved. 17
  • 18. The End Game (Phases 5 & 6) Treasures • Shangri-La – You’ve reached the mystical, harmonious valley; a permanently happy land isolated from the outside world – I’d tell you how it feels, but we haven’t gotten there yet Copyright 2011 by Texas Education http://lanyrd.com/shgmf LASCON 2011 Agency. All rights reserved. 18
  • 19. It’s Time to Play • Build a Mature Software Assurance Program • Measure and Report Your Progress • Have Fun! Copyright 2011 by Texas Education http://lanyrd.com/shgmf LASCON 2011 Agency. All rights reserved. 19
  • 20. Resources • OWASP – Open Web Application Security Project – http://www.owasp.org/ • OpenSAMM - Software Assurance Maturity Model – http://www.opensamm.org/ • Attribution – All OpenSAMM images are licensed under the Creative Commons Attribution-Share Alike 3.0 License. Copyright 2011 by Texas Education http://lanyrd.com/shgmf LASCON 2011 Agency. All rights reserved. 20