diff --git a/img/team/Nariman.jpg b/img/team/Nariman.jpg new file mode 100644 index 00000000..558dee51 Binary files /dev/null and b/img/team/Nariman.jpg differ diff --git a/index.xml b/index.xml index d222860b..508e49aa 100644 --- a/index.xml +++ b/index.xml @@ -71,7 +71,7 @@ The first stream focuses on removing any subjectivity from the build process by The first stream focuses on establishing a common security baseline to automatically detect so-called “low hanging fruit”. Progressively customize the automated tests for each application and increase their frequency of execution to detect more bugs and regressions earlier, as close as possible to their inception.Software Dependencieshttps://owaspsamm.org/model/implementation/secure-build/stream-b/Mon, 01 Jan 0001 00:00:00 +0000https://owaspsamm.org/model/implementation/secure-build/stream-b/Software Requirementshttps://owaspsamm.org/model/design/security-requirements/stream-a/Mon, 01 Jan 0001 00:00:00 +0000https://owaspsamm.org/model/design/security-requirements/stream-a/Strategy and Metricshttps://owaspsamm.org/model/governance/strategy-and-metrics/Mon, 01 Jan 0001 00:00:00 +0000https://owaspsamm.org/model/governance/strategy-and-metrics/Software assurance entails many different activities and concerns. Without an overall plan, you might be spending a lot of effort to build in security, while in fact your efforts may be unaligned, disproportional or even counterproductive. The goal of the Strategy and Metrics (SM) practice is to build an efficient and effective plan for realizing your software security objectives within your organization. A software security program, that selects and prioritizes activities of the rest of the model, serves as the foundation for your efforts.Stream Guidancehttps://owaspsamm.org/stream-guidance/Mon, 01 Jan 0001 00:00:00 +0000https://owaspsamm.org/stream-guidance/Guidance per Stream in the model What’s SAMM guidance? SAMM is a prescriptive security maturity model that is technology, process, and organization agnostic. The model fits any software development process, industry or environment. However, thanks to that, the prescriptive advice is high level by design. That’s where we bring the guidance documents into play. Their purpose is to provide concrete examples and recommendations to help organizations kickstart their security assurance programme based on SAMM.Supplier Securityhttps://owaspsamm.org/model/design/security-requirements/stream-b/Mon, 01 Jan 0001 00:00:00 +0000https://owaspsamm.org/model/design/security-requirements/stream-b/Supportershttps://owaspsamm.org/supporters/Mon, 01 Jan 0001 00:00:00 +0000https://owaspsamm.org/supporters/Organizations supporting SAMM These are companies and organizations who support and have supported SAMM in a variety of ways. For details on how to sponsor SAMM and the benefits of the different levels, see the Sponsor page. -SilverSystem Decommissioning / Legacy Managementhttps://owaspsamm.org/model/operations/operational-management/stream-b/Mon, 01 Jan 0001 00:00:00 +0000https://owaspsamm.org/model/operations/operational-management/stream-b/Technology Managementhttps://owaspsamm.org/model/design/secure-architecture/stream-b/Mon, 01 Jan 0001 00:00:00 +0000https://owaspsamm.org/model/design/secure-architecture/stream-b/The Modelhttps://owaspsamm.org/model/Mon, 01 Jan 0001 00:00:00 +0000https://owaspsamm.org/model/Select a language English Français SAMM model overview Governance Design Implementation Verification Operations Strategy and Metrics Threat Assessment Secure Build Architecture Assessment Incident Management Policy and Compliance Security Requirements Secure Deployment Requirements-driven Testing Environment Management Education and Guidance Secure Architecture Defect Management Security Testing Operational Management Introduction The mission of OWASP Software Assurance Maturity Model (SAMM) is to be the prime maturity model for software assurance that provides an effective and measurable way for all types of organizations to analyze and improve their software security posture.The teamhttps://owaspsamm.org/team/Mon, 01 Jan 0001 00:00:00 +0000https://owaspsamm.org/team/Who is behind SAMM? SAMM is a community-based project and there have been many contributors throughout its history. +SilverSystem Decommissioning / Legacy Managementhttps://owaspsamm.org/model/operations/operational-management/stream-b/Mon, 01 Jan 0001 00:00:00 +0000https://owaspsamm.org/model/operations/operational-management/stream-b/Technology Managementhttps://owaspsamm.org/model/design/secure-architecture/stream-b/Mon, 01 Jan 0001 00:00:00 +0000https://owaspsamm.org/model/design/secure-architecture/stream-b/The Modelhttps://owaspsamm.org/model/Mon, 01 Jan 0001 00:00:00 +0000https://owaspsamm.org/model/Select a language English Français SAMM model overview Gouvernance Conception Implémentation Vérification Opérations Stratégie & Métriques Évaluation de la menace Génération Sécurisée Évaluation de l'architecture Gestion des incidents Politique & Conformité Exigences de Sécurité Déploiement Sécurisé Tests axés sur les exigences Gestion de l'environnement Éducation & Orientation Architecture de Sécurité Gestion des Défauts Tests de sécurité Gestion opérationnelle Introduction The mission of OWASP Software Assurance Maturity Model (SAMM) is to be the prime maturity model for software assurance that provides an effective and measurable way for all types of organizations to analyze and improve their software security posture.The teamhttps://owaspsamm.org/team/Mon, 01 Jan 0001 00:00:00 +0000https://owaspsamm.org/team/Who is behind SAMM? SAMM is a community-based project and there have been many contributors throughout its history. The OWASP SAMM community is powered by security knowledgeable volunteers from businesses and educational organizations. This global collective collaborates to create freely-available articles, methodologies, documentation, tools, and technologies. The OWASP SAMM Core Team These are the people who are currently part of the Core Team, participating actively in regular meetings and summits, and contributing to the project with their work.Threat Assessmenthttps://owaspsamm.org/model/design/threat-assessment/Mon, 01 Jan 0001 00:00:00 +0000https://owaspsamm.org/model/design/threat-assessment/The Threat Assessment (TA) practice focuses on identifying and understanding of project-level risks based on the functionality of the software being developed and characteristics of the runtime environment. From details about threats and likely attacks against each project, the organization as a whole operates more effectively through better decisions about prioritization of initiatives for security. Additionally, decisions for risk acceptance are more informed, therefore better aligned to the business. By starting with simple threat models and building application risk profiles, an organization improves over time.Threat Modelinghttps://owaspsamm.org/model/design/threat-assessment/stream-b/Mon, 01 Jan 0001 00:00:00 +0000https://owaspsamm.org/model/design/threat-assessment/stream-b/Training and Awarenesshttps://owaspsamm.org/model/Governance/Education%20&%20Guidance/stream-A/Mon, 01 Jan 0001 00:00:00 +0000https://owaspsamm.org/model/Governance/Education%20&%20Guidance/stream-A/Training and Awarenesshttps://owaspsamm.org/model/governance/education-and-guidance/stream-a/Mon, 01 Jan 0001 00:00:00 +0000https://owaspsamm.org/model/governance/education-and-guidance/stream-a/User Dayhttps://owaspsamm.org/user-day/cfp/Mon, 01 Jan 0001 00:00:00 +0000https://owaspsamm.org/user-day/cfp/2024 SAMM User Day! The OWASP SAMM team is thrilled to announce its upcoming User Day, as part of Global AppSec Lisbon, on Wednesday, June 26th. diff --git a/team/index.html b/team/index.html index cef5c767..9287e5be 100644 --- a/team/index.html +++ b/team/index.html @@ -3,7 +3,7 @@ The team - go to homepage

The team

Who is behind SAMM?

SAMM Core Team

SAMM is a community-based project and there have been many contributors throughout its history.

The OWASP SAMM community is powered by security knowledgeable volunteers from businesses and educational organizations. This global collective collaborates to create freely-available articles, methodologies, documentation, tools, and technologies.

The OWASP SAMM Core Team

These are the people who are currently part of the Core Team, participating actively in regular meetings and summits, and contributing to the project with their work.

Seba Deleersnyder

Seba Deleersnyder

Project leader

Co-founder & CTO at Toreon, COO & trainer at DPI, Cybersecurity Personality of the Year 2022 in Belgium

Bart De Win

Bart De Win

Project leader

Director Cyber&Privacy unit PwC Belgium, AppSec enthusiast

Maxim Baele

Maxim Baele

Core Team member

Product security consultant with a background in linux system engineering, architecture, and automation

Chris Cooper

Chris Cooper

Core Team member

Product Security Director at News Corp. Formerly Sage appsec and pentesting. Passionate STEM ambassador.

John DiLeo

John DiLeo

Core Team member

Application Security Consultant and Trainer, Solution Architect, Auckland-area leader of the OWASP New Zealand Chapter

Patricia Duarte

Patricia Duarte

Core Team member

Technical writer, UX person, developer

John Ellingsworth

John Ellingsworth

Core Team member

Cybersecurity & web technology expert, leader of the OWASP Maine Chapter

Brian Glas

Brian Glas

Core Team member

Professor and security consultant



Aram Hovsepyan

Aram Hovsepyan

Core Team member

CEO of Codific, security and privacy expert


Daniel Kefer

Daniel Kefer

Core Team member

InfoSec leader at Germany’s largest mail and cloud provider. OWASP SecurityRAT co-lead.

Romuald Szkudlarek

Romuald Szkudlarek

Core Team member

Cyber security and data protection specialist building & managing trust in digital systems

Contributors

SAMM has also been enriched by a diverse group of contributors who have poured their expertise and passion into shaping the project. To all our contributors, we extend our heartfelt thanks for your dedication and invaluable contributions. Your tireless efforts are truly appreciated and, together, we are making the digital world a safer place.

  • Sebastian Arriada
  • Brett Crawley
  • Bruce Jenkins
  • Yan Kravchenko
  • Timo Pagel
  • Hardik Parekh
  • Rob van der Veer
  • Felipe Zipitria

If you think someone is missing, do let us know!


Willing to contribute? If you want to learn more, check out our contributing page.

About us

This is an OWASP Project.
OWASP is an open community dedicated to enabling organizations to conceive, develop, acquire, operate, and maintain applications that can be trusted. All of the OWASP tools, documents, forums, and chapters are free and open to anyone interested in improving application security.

The team

The team

Who is behind SAMM?

SAMM Core Team

SAMM is a community-based project and there have been many contributors throughout its history.

The OWASP SAMM community is powered by security knowledgeable volunteers from businesses and educational organizations. This global collective collaborates to create freely-available articles, methodologies, documentation, tools, and technologies.

The OWASP SAMM Core Team

These are the people who are currently part of the Core Team, participating actively in regular meetings and summits, and contributing to the project with their work.

Seba Deleersnyder

Seba Deleersnyder

Project leader

Co-founder & CTO at Toreon, COO & trainer at DPI, Cybersecurity Personality of the Year 2022 in Belgium

Bart De Win

Bart De Win

Project leader

Director Cyber&Privacy unit PwC Belgium, AppSec enthusiast

Nariman Aga-Tagiyev

Nariman Aga-Tagiyev

Core Team member

Application Security Architect, Cybersecurity Engineering Manager at Dassault Systems, dedicated to advancing SSDLC maturity

Maxim Baele

Maxim Baele

Core Team member

Product security consultant with a background in linux system engineering, architecture, and automation

John DiLeo

John DiLeo

Core Team member

Application Security Consultant and Trainer, Solution Architect, Auckland-area leader of the OWASP New Zealand Chapter

Patricia Duarte

Patricia Duarte

Core Team member

Technical writer, UX person, developer

John Ellingsworth

John Ellingsworth

Core Team member

Cybersecurity & web technology expert, leader of the OWASP Maine Chapter

Brian Glas

Brian Glas

Core Team member

Professor and security consultant



Aram Hovsepyan

Aram Hovsepyan

Core Team member

CEO of Codific, security and privacy expert


Daniel Kefer

Daniel Kefer

Core Team member

InfoSec leader at Germany’s largest mail and cloud provider. OWASP SecurityRAT co-lead.

Contributors

SAMM has also been enriched by a diverse group of contributors who have poured their expertise and passion into shaping the project. To all our contributors, we extend our heartfelt thanks for your dedication and invaluable contributions. Your tireless efforts are truly appreciated and, together, we are making the digital world a safer place.

  • Sebastian Arriada
  • Chris Cooper
  • Brett Crawley
  • Bruce Jenkins
  • Yan Kravchenko
  • Timo Pagel
  • Hardik Parekh
  • Romuald Szkudlarek
  • Rob van der Veer
  • Felipe Zipitria

If you think someone is missing, do let us know!


Willing to contribute? If you want to learn more, check out our contributing page.

About us

This is an OWASP Project.
OWASP is an open community dedicated to enabling organizations to conceive, develop, acquire, operate, and maintain applications that can be trusted. All of the OWASP tools, documents, forums, and chapters are free and open to anyone interested in improving application security.

The team