SlideShare a Scribd company logo
1 of 5
Download to read offline
ENTERPRISE TRAINING PROJECT
OWASP Proposal Page
Application 1
Applicant's Identification/Project Release Leader Cassio Goldschmidt
Application Designation/Name
Enterprise Training
Project – Phase I
First (proposed) Reviewer
Application Security Issue Addressed Prelude
OWASP Top 10, the
foundation most well
known project, has
insuficient
supplemental material
that could be readily
used by companies
who would like to
educate employees on
it. Education on the
top 10 should not limit
itself to provide
awareness about
problem. It must
educate the
development
community on how to
resolve the issues
presented in the list.
Problem to be
addressed
• Provide
professional
quality training
material on
OWASPs best
well known
project.
• Help
disseminate
Web Security on
enterprises
• Introduce the
audience to tools
that help
mitigate the
issue
Proposal
Create a series of
training modules that
can be readily utilized
by enterprises that
would like to train
their employees on
web Security. The
first module that shall
be created is the
official one day
OWASP Top 10
training module. This
module shall be a
professional looking,
one day class (the
target is approximately
7.5 hours worth of
training) that unites
our education efforts
with the Top 10 web
vulnerabilities and
exercises based on
OWASP tools.
Prioritized area
(Please choose from here)
Enterprise usability of
OWASP projects
Project Release Roadmap
Milestones:
• Consolidate the
team – July 30th
• Find graphic
designer –
August 21st
• Divide the
work among
the members -
August 24th
• Create each of
the 10
modules,
including
graphics –
December 28th
• Review each of
the 10 modules
– February 28th
• Project
Completion -
March 12th
• Use the
training in at
least at one
enterprise –
March 26th
• Offer it as a
class at
OWASP
AppSec EU
2010
Other Questions |}
Project Goal
The ultimate goal of this project is to create a series of training modules that can be readily utilized by
enterprises that would like to train their employees on web Security. The first module that shall be
created is the official one day OWASP Top 10 training module. This module shall be a professional
looking, one day class (7.5 hours worth of training) that unites our education efforts with the Top 10
web vulnerabilities and exercises based on OWASP tools.
Each training module will consist of:
• A slide deck (ppt) where every single slide has a narration, word by word, of what an instructor
should teach in the slide. The narration will be later utilized to build online.
o Each deck must contain references in the end of each module
o References to surveys must be displayed in each slide where the information is
referenced
o All tools mentioned in the deck must contain a link to them
o All attacks shall contain an animation (when applicable) exemplifying the attack and
real life instances of the attack.
• Time it takes to present the slides (based on someone reading the narration while emulating a
presentation, plus or minus some minutes. The 1.5 minutes per slide rule must fall inside this
range)
• A set of questions related to the content of the module. The number of questions shall be no less
than a function (set by the committee later) that takes the deck size into consideration. Each
question shall meet best practices for exam question creation (e.g. OUCOM Multiple Choice
Exam Policy)
• Hands on fixation exercises (many will be based on already existing OWASP tools)
To maintain quality and uniformity among modules, all art shall be developed (or enhanced) by a
professional graphic designer who will be hired using the budget for this project. The graphic designer
shall be responsible for delivering the slide, charts, citation, bullets, agenda and timeline templates as
well as icon library that will be used as the base for the entire project and modules to come in the
future. The graphic designer will also be responsible for creating all PowerPoint animations. To
minimize the cost of this operation, the graphic designer will be hired overseas.
To foster contribution, all companies that donate time for the construction of a module will have their
logos displayed in the first and last slide of the deck they contributed.
Budget
• 20K for the top 10 (Phase I)
Schedule
• Consolidate the team – July 30th
• Find graphic designer – August 21st
• Divide the work among the members - August 24th
• Create each of the 10 modules, including graphics – December 28th
• Review each of the 10 modules – February 28th
• Present at least at one enterprise – March 27th
• Offer it as a class at OWASP AppSec EU 2010

More Related Content

Featured

2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by Hubspot2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by HubspotMarius Sescu
 
Everything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTEverything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTExpeed Software
 
Product Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsProduct Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsPixeldarts
 
How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthThinkNow
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfmarketingartwork
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024Neil Kimberley
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)contently
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024Albert Qian
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsKurio // The Social Media Age(ncy)
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Search Engine Journal
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summarySpeakerHub
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next Tessa Mero
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentLily Ray
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best PracticesVit Horky
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project managementMindGenius
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...RachelPearson36
 

Featured (20)

2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by Hubspot2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by Hubspot
 
Everything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTEverything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPT
 
Product Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsProduct Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage Engineerings
 
How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental Health
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
 
Skeleton Culture Code
Skeleton Culture CodeSkeleton Culture Code
Skeleton Culture Code
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 

OWASP Season of Code Proposal - Enterprise Training

  • 1. ENTERPRISE TRAINING PROJECT OWASP Proposal Page Application 1 Applicant's Identification/Project Release Leader Cassio Goldschmidt Application Designation/Name Enterprise Training Project – Phase I First (proposed) Reviewer Application Security Issue Addressed Prelude OWASP Top 10, the foundation most well known project, has insuficient supplemental material that could be readily used by companies who would like to
  • 2. educate employees on it. Education on the top 10 should not limit itself to provide awareness about problem. It must educate the development community on how to resolve the issues presented in the list. Problem to be addressed • Provide professional quality training material on OWASPs best well known project. • Help disseminate Web Security on enterprises • Introduce the audience to tools that help mitigate the issue Proposal Create a series of training modules that can be readily utilized by enterprises that would like to train their employees on web Security. The first module that shall be created is the official one day OWASP Top 10 training module. This module shall be a
  • 3. professional looking, one day class (the target is approximately 7.5 hours worth of training) that unites our education efforts with the Top 10 web vulnerabilities and exercises based on OWASP tools. Prioritized area (Please choose from here) Enterprise usability of OWASP projects Project Release Roadmap Milestones: • Consolidate the team – July 30th • Find graphic designer – August 21st • Divide the work among the members - August 24th • Create each of the 10 modules, including graphics – December 28th • Review each of the 10 modules – February 28th • Project Completion - March 12th • Use the training in at least at one enterprise – March 26th • Offer it as a class at OWASP AppSec EU 2010 Other Questions |}
  • 4. Project Goal The ultimate goal of this project is to create a series of training modules that can be readily utilized by enterprises that would like to train their employees on web Security. The first module that shall be created is the official one day OWASP Top 10 training module. This module shall be a professional looking, one day class (7.5 hours worth of training) that unites our education efforts with the Top 10 web vulnerabilities and exercises based on OWASP tools. Each training module will consist of: • A slide deck (ppt) where every single slide has a narration, word by word, of what an instructor should teach in the slide. The narration will be later utilized to build online. o Each deck must contain references in the end of each module o References to surveys must be displayed in each slide where the information is referenced o All tools mentioned in the deck must contain a link to them o All attacks shall contain an animation (when applicable) exemplifying the attack and real life instances of the attack. • Time it takes to present the slides (based on someone reading the narration while emulating a presentation, plus or minus some minutes. The 1.5 minutes per slide rule must fall inside this range) • A set of questions related to the content of the module. The number of questions shall be no less than a function (set by the committee later) that takes the deck size into consideration. Each question shall meet best practices for exam question creation (e.g. OUCOM Multiple Choice Exam Policy) • Hands on fixation exercises (many will be based on already existing OWASP tools) To maintain quality and uniformity among modules, all art shall be developed (or enhanced) by a professional graphic designer who will be hired using the budget for this project. The graphic designer shall be responsible for delivering the slide, charts, citation, bullets, agenda and timeline templates as well as icon library that will be used as the base for the entire project and modules to come in the future. The graphic designer will also be responsible for creating all PowerPoint animations. To minimize the cost of this operation, the graphic designer will be hired overseas. To foster contribution, all companies that donate time for the construction of a module will have their logos displayed in the first and last slide of the deck they contributed. Budget • 20K for the top 10 (Phase I)
  • 5. Schedule • Consolidate the team – July 30th • Find graphic designer – August 21st • Divide the work among the members - August 24th • Create each of the 10 modules, including graphics – December 28th • Review each of the 10 modules – February 28th • Present at least at one enterprise – March 27th • Offer it as a class at OWASP AppSec EU 2010