Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Sécurité des applications : Les fondements

Sécurité des applications : Les fondements

OWASP Montréal est fier d’accueillir au Midi Conférence du mois de mars, Mme Tanya Janca, Co-Leader du chapitre OWASP Ottawa et spécialiste de la sécurité applicative au sein du Gouvernement fédéral.

La conférence « Les fondements de la sécurité des applications » sera présentée en anglais.

Session Description : Everyone has heard about the problem; everyone is “getting hacked”. But what is the answer? From scanning your code with a vulnerability scanner to red teaming exercises, developer education programs and bug bounties, this talk will take the audience through all the possibilities of an extensive application security program, with a detailed explanation of each part.

Bio : Tanya Janca is an application security evangelist, a web application penetration tester and vulnerability assessor, a secure code reviewer, an ethical hacker, the Co-Leader of the OWASP Ottawa chapter, and has been developing software since the late 90’s. She has worn many hats and done many things, including; Custom Apps, Ethical Hacking, COTS, Incident Response, Enterprise Architect, Project and People Management, and even Tech Support. She is currently helping the Government of Canada secure their web applications.

Merci à notre commanditaire principal de cet événement: Ubitrak!

OWASP Montréal

March 20, 2017
Tweet

More Decks by OWASP Montréal

Other Decks in Programming

Transcript

  1. 8-12 May, 2017
    Pushing Left, Like a Boss
    Tanya Janca
    [email protected], OWASP Ottawa Chapter Co-Leader

    View Slide

  2. What is 'Pushing Left'?

    View Slide

  3. Current state: everyone is 'getting hacked'.

    View Slide

  4. Current state: we’re looking the wrong way.

    View Slide

  5. “Application Security is the art (or is that
    battle?) of making an application secure.”
    -- Tanya Janca
    AppSec: In Plain English

    View Slide

  6. Current state: Pen Testing.

    View Slide

  7. Current state: CIA

    View Slide

  8. Pushing Left, Like a Boss!

    View Slide

  9. Pushing Left: The Main Course

    View Slide

  10. Pushing Left: The Gravy

    View Slide

  11. Pushing Left: The Dessert

    View Slide

  12. Pushing Left: Testing Your Code

    View Slide

  13. Pushing Left: A Word of Caution

    View Slide

  14. Pushing Left: Threat Modeling

    View Slide

  15. Pushing Left: Reviewing Code

    View Slide

  16. Pushing Left: Writing Better Code

    View Slide

  17. OWASP: Your New BFF

    View Slide

  18. OWASP

    View Slide

  19. 8-12 May, 2017
    Pushing Left, Like a Boss
    Tanya Janca
    [email protected], OWASP Ottawa Chapter Co-Leader

    View Slide