Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
What is OWASP 20160319InnovationEGG7th
Search
Sponsored
·
Your Podcast. Everywhere. Effortlessly.
Share. Educate. Inspire. Entertain. You do you. We'll handle the rest.
→
OWASP Japan
March 19, 2016
1.8k
3
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
What is OWASP 20160319InnovationEGG7th
OWASP Japan
March 19, 2016
More Decks by OWASP Japan
See All by OWASP Japan
OWASP Night 2019.03 Tokyo
owaspjapan
0
400
OWASP SAMMを活用したセキュア開発の推進
owaspjapan
0
1.1k
20190107_AbuseCaseCheatSheet
owaspjapan
0
220
セキュリティ要求定義で使える非機能要求グレードとASVS
owaspjapan
5
1.2k
AWSクラスタに捧ぐウェブを衛っていく方法論と死なない程度の修羅場の価値
owaspjapan
9
3.5k
Shifting Left Like a Boss
owaspjapan
2
340
OWASP Top 10 and Your Web Apps
owaspjapan
2
430
OWASP Japan Proposal: Encouraging Japanese Translation
owaspjapan
1
290
elegance_of_OWASP_Top10_2017
owaspjapan
2
580
Featured
See All Featured
[Rails World 2023 - Day 1 Closing Keynote] - The Magic of Rails
eileencodes
38
2.9k
Groundhog Day: Seeking Process in Gaming for Health
codingconduct
0
200
SERP Conf. Vienna - Web Accessibility: Optimizing for Inclusivity and SEO
sarafernandez
2
1.5k
Leo the Paperboy
mayatellez
7
1.8k
Redefining SEO in the New Era of Traffic Generation
szymonslowik
1
330
GraphQLとの向き合い方2022年版
quramy
50
15k
Let's Do A Bunch of Simple Stuff to Make Websites Faster
chriscoyier
508
140k
Connecting the Dots Between Site Speed, User Experience & Your Business [WebExpo 2025]
tammyeverts
11
940
The Art of Delivering Value - GDevCon NA Keynote
reverentgeek
16
2k
Writing Fast Ruby
sferik
630
63k
[RailsConf 2023 Opening Keynote] The Magic of Rails
eileencodes
31
10k
End of SEO as We Know It (SMX Advanced Version)
ipullrank
3
4.2k
Transcript
OWASPͷา͖ํ Innovation EGG ୈ7ճ LT Edition
ΣϒΛऔΓר͘Λղܾ͢ΔͨΊͷࠃࡍతͳΦʔϓϯίϛϡχςΟ
ຊͰOWASPνϟϓλʔͷઃཱ͕ྲྀߦΔ ࠷ۙɺ2ڌՃͱͳΓ·ͨ͠ɻ Fukushima Okinawa https://www.owasp.org/index.php/Japan
ͦΜͳதݱࡏຊྻౡɺɺɺ
ΠϯϑϧΤϯβͷରࡦ͞·͟· جຊతͳ ͏͕͍ɾखચ͍ පӃͰͷ ௨Ӄɾ༧ઁऔ ϚεΫͷ ண༻
ͦΕͰ͔͔Δͱ͖͔͔Δ
γεςϜಉ͡ʂͲΜͳରࡦΛ͍ͯͯ͠μϯ͢Δͱ͖μϯ͢Δ
ͱ͜ΖͰɺɺɺɺීஈ͔ΒΠϯϑϧΤϯβରࡦͨΓલʹ͍ͬͯΔɻ جຊతͳ ͏͕͍ɾखચ͍ පӃͰͷ ௨Ӄɾ༧ઁऔ ϚεΫͷ ண༻
͍ͬΆ͏ͦͷ͜ΖɺɺɺγεςϜͲ͏͔ɻɻɻ
૬ख͕࣌ؒ͋Γɺົͳ߈ܸΛ͔͚ͯ͘͠ΔͭΒ
γεςϜಉ͡ʂηΩϡϦςΟରࡦΛͨΓલʹ͍ͯ͜͠͏
Ͳ͏ͨΓલʹ͢ΕΑ͍͔ɻOWASPͷπʔϧͰ֬ೝͯ͠ΈΑ͏
ηΩϡϦςΟରࡦͷجຊతͳཧղʹOWASPͷυΩϡϝϯτΛݟΑ͏! جຊతͳ ͏͕͍ɾखચ͍ පӃͰͷ ௨Ӄɾ༧ઁऔ ϚεΫͷ ண༻
OWASP Top 10Ͱओཁͳ੬ऑੑͱͦͷରࡦΛཧղ! ࠷ۙɺMobile Top10 2016ӳޠ൛Ͱ·ͨ͠ɻ https://www.owasp.org/index.php/Mobile_Top_10_2016-Top_10
ηΩϡϦςΟରࡦΛޮతʹߦ͏ʹOWASPͷπʔϧΛ͓͏! جຊతͳ ͏͕͍ɾखચ͍ පӃͰͷ ௨Ӄɾ༧ઁऔ ϚεΫͷ ண༻
OWASP ZAPʹΑΓϫϯΫϦοΫͰ؆୯ʹ੬ऑੑΛνΣοΫ!
ͦͷଞπʔϧ ① 要件定義 OWASP ASVS(Application Security Verification Standard ) Web
システム/Web アプリケーションセキュリティ要件書 ② 設計・開発 OWASP Cheat Sheet Series OWASP Proactive Controls ③ テスト・導⼊ OWASP ZAP(Zed Attack Proxy) OWASP Testing Guide ④ 運⽤・保守 OWASP AppSensor OWASP Dependency Check ⑤ 知識 OWASP Top10 / Mobile Top10 / IoT Top 10 OWASP Snakes and Ladders
OWASP Cheer Sheet Series
ηΩϡϦςΟରࡦΛֶͿͳΒOWASPφΠτʹࢀՃ͠Α͏! جຊతͳ ͏͕͍ɾखચ͍ පӃͰͷ ௨Ӄɾ༧ઁऔ ϚεΫͷ ண༻
3ϲ݄ʹ1ͷOWASPφΠτͰΣϒηΩϡϦςΟͷ࠷৽ٕज़Λٵऩ!
OWASP Kansaiษڧձ͋Γ·͢ɻ
ʲࠂʳ4/2ʢʣʹԭೄͷࠃࡍిࢠϏδωεઐֶߍͰOWASP Night Okinawa #1։࠵! https://owasp-okinawa.doorkeeper.jp/events/41031
͝੩ௌ͋Γ͕ͱ͏͍͟͝·ͨ͠ʂ ΣϒΛ͔ͨ͠ͳͷʹ