SlideShare a Scribd company logo
1 of 20
Download to read offline
OpenSAMM in the Real World:
                      Pitfalls Discovered and Treasure
                          Collected Along the Way
                      Philip J. Beyer - Texas Education Agency
                                    philip.beyer@tea.state.tx.us   @pjbeyer
                                    Scott Stevens - Denim Group
                                          sstevens@denimgroup.com



Copyright 2011 by Texas Education
Agency. All rights reserved.                        LASCON 2011               http://lanyrd.com/shgmf   1
Overview
•     Background
•     The Manual
•     The Premise
•     Treasures and Pitfalls
•     Game Over




Copyright 2011 by Texas Education
Agency. All rights reserved.          LASCON 2011   http://lanyrd.com/shgmf   2
About
• Phil Beyer
         – Information Security Officer
         – Consulting background
• Scott Stevens
         – Project Manager
         – Application development background
• TEA
         – ~700 employees
         – ~1200 school districts
         – ~5 million students

Copyright 2011 by Texas Education
Agency. All rights reserved.        LASCON 2011   http://lanyrd.com/shgmf   3
Where Did TEA Start?
• Application Security Program already
  established
         – Some policies & procedures
         – Initial training & exposure to concepts
         – Historically siloed approach
• Outsourcing for subject matter expertise



Copyright 2011 by Texas Education
Agency. All rights reserved.            LASCON 2011   http://lanyrd.com/shgmf   4
Where Do You Start?
•     Establish your Application Security Program
•     Be the Champion (or find one)
•     Make sure your Team Gets It
•     Have a Roadmap to Maturity




Copyright 2011 by Texas Education
Agency. All rights reserved.               LASCON 2011   http://lanyrd.com/shgmf   5
The Manual
                                    Business Functions




Copyright 2011 by Texas Education
Agency. All rights reserved.               LASCON 2011   http://lanyrd.com/shgmf   6
The Manual
                                    Security Practices




Copyright 2011 by Texas Education
Agency. All rights reserved.              LASCON 2011    http://lanyrd.com/shgmf   7
The Manual
               Phases
1. The Early Levels
2. Racking Up Some
   Points
3. Hitting Your Stride
4. Bigger Treasures,
   Deeper Pits
    The End Game

Copyright 2011 by Texas Education
Agency. All rights reserved.
The Premise
• It has already started
• Shortcuts don’t exist
         – No cheat codes
         – No invincibility
         – No God mode
• There are Pitfalls
• There are Treasures

Copyright 2011 by Texas Education
Agency. All rights reserved.           LASCON 2011   http://lanyrd.com/shgmf   9
The Early Levels (Phase 1)
                                    Treasures
• A Map
         – Not necessarily THE Map, but
           something to get started
         – An organizational roadmap is a
           powerful thing
• Some Running Room
         – Awareness in the organization is
           increasing


Copyright 2011 by Texas Education                    http://lanyrd.com/shgmf
                                      LASCON 2011
Agency. All rights reserved.                                              10
The Early Levels (Phase 1)
                                     Pitfalls
• The Log
         – You can’t stand still
         – Move through Phase 1 so you
           don’t get rolled over
• Inertia
         – Getting started is just plain hard
         – Determining who should play is
           also hard

Copyright 2011 by Texas Education                    http://lanyrd.com/shgmf
                                      LASCON 2011
Agency. All rights reserved.                                              11
Racking Up Some Points (Phase 2)
                      Treasures
• Silver Bars
         – Development teams begin to
           appreciate the security problem


• The Ladder
         – More of the team is involved in
           practicing security
         – You’ve found a new way around
           the alligator-infested pond
Copyright 2011 by Texas Education                 http://lanyrd.com/shgmf
                                    LASCON 2011
Agency. All rights reserved.                                           12
Racking Up Some Points (Phase 2)
                       Pitfalls
• The Alligator
         – There’s a dangerous thing there
           on the screen
         – Threats are real, and now they
           see some of them too
• More Players
         – Other people are going to play
           your game
         – They may not play as { nice |
           carefully | safely } as you
Copyright 2011 by Texas Education                 http://lanyrd.com/shgmf
                                    LASCON 2011
Agency. All rights reserved.                                           13
Hitting Your Stride (Phase 3)
                                 Treasures
• Gold Bars
         – Better visibility instills confidence
           in Management
• The Compass
         – The Program has direction
         – From requirements to
           maintenance, a formal process
           starts to emerge


Copyright 2011 by Texas Education                  http://lanyrd.com/shgmf
                                    LASCON 2011
Agency. All rights reserved.                                            14
Hitting Your Stride (Phase 3)
                                  Pitfalls
• The Scorpion
         – Better informed Management
           may sting
• The Wall
         – A different kind of obstacle will
           block your path
         – Developers and Operators may
           not enjoy working together
           more closely
Copyright 2011 by Texas Education                 http://lanyrd.com/shgmf
                                    LASCON 2011
Agency. All rights reserved.                                           15
Bigger Treasures, Deeper Pits (Phase 4)
              Treasures
• The Bridge
         – Get rid of that Rope and jeer at
           the Alligators as you walk across
         – The whole Program is working
           together to build securely and
           verify aggressively




Copyright 2011 by Texas Education                 http://lanyrd.com/shgmf
                                    LASCON 2011
Agency. All rights reserved.                                           16
Bigger Treasures, Deeper Pits (Phase 4)
                Pitfalls
• The Hole
         – Compliance is not Security
         – Don’t let Management fall into the
           trap at this stage of the game… It
           can be a pretty deep pit




Copyright 2011 by Texas Education                 http://lanyrd.com/shgmf
                                    LASCON 2011
Agency. All rights reserved.                                           17
The End Game (Phases 5 & 6)
                             Treasures
• Shangri-La
         – You’ve reached the mystical,
           harmonious valley; a
           permanently happy land
           isolated from the outside world
         – I’d tell you how it feels, but we
           haven’t gotten there yet



Copyright 2011 by Texas Education                 http://lanyrd.com/shgmf
                                    LASCON 2011
Agency. All rights reserved.                                           18
It’s Time to Play
• Build a Mature Software Assurance Program
• Measure and Report Your Progress
• Have Fun!




Copyright 2011 by Texas Education                       http://lanyrd.com/shgmf
                                          LASCON 2011
Agency. All rights reserved.                                                 19
Resources
• OWASP – Open Web Application Security Project
         – http://www.owasp.org/
• OpenSAMM - Software Assurance Maturity Model
         – http://www.opensamm.org/

• Attribution
         – All OpenSAMM images are licensed under the Creative Commons
           Attribution-Share Alike 3.0 License.



Copyright 2011 by Texas Education                            http://lanyrd.com/shgmf
                                      LASCON 2011
Agency. All rights reserved.                                                      20

More Related Content

More from Philip Beyer

Choose to Lead: The Information Security Profession Needs You!
Choose to Lead: The Information Security Profession Needs You!Choose to Lead: The Information Security Profession Needs You!
Choose to Lead: The Information Security Profession Needs You!Philip Beyer
 
Risk Explained... in 5 Minutes or Less
Risk Explained... in 5 Minutes or LessRisk Explained... in 5 Minutes or Less
Risk Explained... in 5 Minutes or LessPhilip Beyer
 
The Myth of a Perfect Security Program ... The Reality of Eternal Life
The Myth of a Perfect Security Program ... The Reality of Eternal LifeThe Myth of a Perfect Security Program ... The Reality of Eternal Life
The Myth of a Perfect Security Program ... The Reality of Eternal LifePhilip Beyer
 
(Consulting) Couch to CISO: A Security Leader's First 100 Days and Beyond
(Consulting) Couch to CISO: A Security Leader's First 100 Days and Beyond(Consulting) Couch to CISO: A Security Leader's First 100 Days and Beyond
(Consulting) Couch to CISO: A Security Leader's First 100 Days and BeyondPhilip Beyer
 
Secure SDLC in the Real World: Pitfalls Discovered and Treasure Collected Alo...
Secure SDLC in the Real World: Pitfalls Discovered and Treasure Collected Alo...Secure SDLC in the Real World: Pitfalls Discovered and Treasure Collected Alo...
Secure SDLC in the Real World: Pitfalls Discovered and Treasure Collected Alo...Philip Beyer
 
Lean and (Prepared for) Mean: Application Security Program Essentials
Lean and (Prepared for) Mean: Application Security Program EssentialsLean and (Prepared for) Mean: Application Security Program Essentials
Lean and (Prepared for) Mean: Application Security Program EssentialsPhilip Beyer
 

More from Philip Beyer (6)

Choose to Lead: The Information Security Profession Needs You!
Choose to Lead: The Information Security Profession Needs You!Choose to Lead: The Information Security Profession Needs You!
Choose to Lead: The Information Security Profession Needs You!
 
Risk Explained... in 5 Minutes or Less
Risk Explained... in 5 Minutes or LessRisk Explained... in 5 Minutes or Less
Risk Explained... in 5 Minutes or Less
 
The Myth of a Perfect Security Program ... The Reality of Eternal Life
The Myth of a Perfect Security Program ... The Reality of Eternal LifeThe Myth of a Perfect Security Program ... The Reality of Eternal Life
The Myth of a Perfect Security Program ... The Reality of Eternal Life
 
(Consulting) Couch to CISO: A Security Leader's First 100 Days and Beyond
(Consulting) Couch to CISO: A Security Leader's First 100 Days and Beyond(Consulting) Couch to CISO: A Security Leader's First 100 Days and Beyond
(Consulting) Couch to CISO: A Security Leader's First 100 Days and Beyond
 
Secure SDLC in the Real World: Pitfalls Discovered and Treasure Collected Alo...
Secure SDLC in the Real World: Pitfalls Discovered and Treasure Collected Alo...Secure SDLC in the Real World: Pitfalls Discovered and Treasure Collected Alo...
Secure SDLC in the Real World: Pitfalls Discovered and Treasure Collected Alo...
 
Lean and (Prepared for) Mean: Application Security Program Essentials
Lean and (Prepared for) Mean: Application Security Program EssentialsLean and (Prepared for) Mean: Application Security Program Essentials
Lean and (Prepared for) Mean: Application Security Program Essentials
 

Recently uploaded

The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024Rafal Los
 
Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Allon Mureinik
 
A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024Results
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...Neo4j
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationRadu Cotescu
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountPuma Security, LLC
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEarley Information Science
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationSafe Software
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024The Digital Insurer
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking MenDelhi Call girls
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Enterprise Knowledge
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Drew Madelung
 
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure serviceWhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure servicePooja Nehwal
 
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsTop 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsRoshan Dwivedi
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slidespraypatel2
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking MenDelhi Call girls
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Igalia
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking MenDelhi Call girls
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonAnna Loughnan Colquhoun
 

Recently uploaded (20)

The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)
 
A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path Mount
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure serviceWhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
WhatsApp 9892124323 ✓Call Girls In Kalyan ( Mumbai ) secure service
 
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsTop 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slides
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 

OpenSAMM in the Real World: Pitfalls Discovered and Treasures Collected Along the Way

  • 1. OpenSAMM in the Real World: Pitfalls Discovered and Treasure Collected Along the Way Philip J. Beyer - Texas Education Agency philip.beyer@tea.state.tx.us @pjbeyer Scott Stevens - Denim Group sstevens@denimgroup.com Copyright 2011 by Texas Education Agency. All rights reserved. LASCON 2011 http://lanyrd.com/shgmf 1
  • 2. Overview • Background • The Manual • The Premise • Treasures and Pitfalls • Game Over Copyright 2011 by Texas Education Agency. All rights reserved. LASCON 2011 http://lanyrd.com/shgmf 2
  • 3. About • Phil Beyer – Information Security Officer – Consulting background • Scott Stevens – Project Manager – Application development background • TEA – ~700 employees – ~1200 school districts – ~5 million students Copyright 2011 by Texas Education Agency. All rights reserved. LASCON 2011 http://lanyrd.com/shgmf 3
  • 4. Where Did TEA Start? • Application Security Program already established – Some policies & procedures – Initial training & exposure to concepts – Historically siloed approach • Outsourcing for subject matter expertise Copyright 2011 by Texas Education Agency. All rights reserved. LASCON 2011 http://lanyrd.com/shgmf 4
  • 5. Where Do You Start? • Establish your Application Security Program • Be the Champion (or find one) • Make sure your Team Gets It • Have a Roadmap to Maturity Copyright 2011 by Texas Education Agency. All rights reserved. LASCON 2011 http://lanyrd.com/shgmf 5
  • 6. The Manual Business Functions Copyright 2011 by Texas Education Agency. All rights reserved. LASCON 2011 http://lanyrd.com/shgmf 6
  • 7. The Manual Security Practices Copyright 2011 by Texas Education Agency. All rights reserved. LASCON 2011 http://lanyrd.com/shgmf 7
  • 8. The Manual Phases 1. The Early Levels 2. Racking Up Some Points 3. Hitting Your Stride 4. Bigger Treasures, Deeper Pits The End Game Copyright 2011 by Texas Education Agency. All rights reserved.
  • 9. The Premise • It has already started • Shortcuts don’t exist – No cheat codes – No invincibility – No God mode • There are Pitfalls • There are Treasures Copyright 2011 by Texas Education Agency. All rights reserved. LASCON 2011 http://lanyrd.com/shgmf 9
  • 10. The Early Levels (Phase 1) Treasures • A Map – Not necessarily THE Map, but something to get started – An organizational roadmap is a powerful thing • Some Running Room – Awareness in the organization is increasing Copyright 2011 by Texas Education http://lanyrd.com/shgmf LASCON 2011 Agency. All rights reserved. 10
  • 11. The Early Levels (Phase 1) Pitfalls • The Log – You can’t stand still – Move through Phase 1 so you don’t get rolled over • Inertia – Getting started is just plain hard – Determining who should play is also hard Copyright 2011 by Texas Education http://lanyrd.com/shgmf LASCON 2011 Agency. All rights reserved. 11
  • 12. Racking Up Some Points (Phase 2) Treasures • Silver Bars – Development teams begin to appreciate the security problem • The Ladder – More of the team is involved in practicing security – You’ve found a new way around the alligator-infested pond Copyright 2011 by Texas Education http://lanyrd.com/shgmf LASCON 2011 Agency. All rights reserved. 12
  • 13. Racking Up Some Points (Phase 2) Pitfalls • The Alligator – There’s a dangerous thing there on the screen – Threats are real, and now they see some of them too • More Players – Other people are going to play your game – They may not play as { nice | carefully | safely } as you Copyright 2011 by Texas Education http://lanyrd.com/shgmf LASCON 2011 Agency. All rights reserved. 13
  • 14. Hitting Your Stride (Phase 3) Treasures • Gold Bars – Better visibility instills confidence in Management • The Compass – The Program has direction – From requirements to maintenance, a formal process starts to emerge Copyright 2011 by Texas Education http://lanyrd.com/shgmf LASCON 2011 Agency. All rights reserved. 14
  • 15. Hitting Your Stride (Phase 3) Pitfalls • The Scorpion – Better informed Management may sting • The Wall – A different kind of obstacle will block your path – Developers and Operators may not enjoy working together more closely Copyright 2011 by Texas Education http://lanyrd.com/shgmf LASCON 2011 Agency. All rights reserved. 15
  • 16. Bigger Treasures, Deeper Pits (Phase 4) Treasures • The Bridge – Get rid of that Rope and jeer at the Alligators as you walk across – The whole Program is working together to build securely and verify aggressively Copyright 2011 by Texas Education http://lanyrd.com/shgmf LASCON 2011 Agency. All rights reserved. 16
  • 17. Bigger Treasures, Deeper Pits (Phase 4) Pitfalls • The Hole – Compliance is not Security – Don’t let Management fall into the trap at this stage of the game… It can be a pretty deep pit Copyright 2011 by Texas Education http://lanyrd.com/shgmf LASCON 2011 Agency. All rights reserved. 17
  • 18. The End Game (Phases 5 & 6) Treasures • Shangri-La – You’ve reached the mystical, harmonious valley; a permanently happy land isolated from the outside world – I’d tell you how it feels, but we haven’t gotten there yet Copyright 2011 by Texas Education http://lanyrd.com/shgmf LASCON 2011 Agency. All rights reserved. 18
  • 19. It’s Time to Play • Build a Mature Software Assurance Program • Measure and Report Your Progress • Have Fun! Copyright 2011 by Texas Education http://lanyrd.com/shgmf LASCON 2011 Agency. All rights reserved. 19
  • 20. Resources • OWASP – Open Web Application Security Project – http://www.owasp.org/ • OpenSAMM - Software Assurance Maturity Model – http://www.opensamm.org/ • Attribution – All OpenSAMM images are licensed under the Creative Commons Attribution-Share Alike 3.0 License. Copyright 2011 by Texas Education http://lanyrd.com/shgmf LASCON 2011 Agency. All rights reserved. 20