<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic June 2022 Meeting Minutes in Cleveland Chapter Discussion Forum</title>
    <link>https://community.isc2.org/t5/Cleveland-Chapter-Discussion/June-2022-Meeting-Minutes/m-p/52260#M14</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(ISC)2 June 28th Monthly Chapter Meeting Notes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Total Registered: 49&lt;/P&gt;&lt;P&gt;Total Attendees: 36&lt;/P&gt;&lt;P&gt;Format: In-Person&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Meeting Agenda:&amp;nbsp;&lt;/STRONG&gt;(ISC)2 Cleveland Chapter Meeting, June 28, 2022&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;In person networking and conversation, Attendee Introductions&lt;/LI&gt;&lt;LI&gt;(ISC)2 Cleveland Chapter Meeting - In Person Welcome&lt;/LI&gt;&lt;LI&gt;Chatham House Rule&lt;/LI&gt;&lt;LI&gt;Chapter and (ISC)2 news and information&lt;/LI&gt;&lt;LI&gt;Officer Introductions for year 2022&lt;/LI&gt;&lt;LI&gt;Announcements - companies that are seeking &amp;amp; hiring&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Security Friends&amp;nbsp;&lt;/STRONG&gt;- A fun look at and discussion of current cyber security news stories, delivered in over the top, dramatic radio style.&lt;/LI&gt;&lt;LI&gt;Feature Presentation - Secure Software Development – how the OWASP framework can help you.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;U&gt;&amp;nbsp;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;U&gt;Notes:&lt;/U&gt;&lt;/P&gt;&lt;P&gt;5:30pm introductions and Announcements&lt;/P&gt;&lt;P&gt;5:45 – 6:15pm – Security Friends – Current Security news and events.&amp;nbsp; Included open discussion on recent Cyber attacks and new items.&lt;/P&gt;&lt;P&gt;6:15pm Featured presenter – Brandon Collins – Optiv Security – CSSLP (certified secure software lifecycle professional) - pursuing&lt;/P&gt;&lt;P&gt;Secure Software Development - How the OWAP SAMM Framework can help.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;A holistic approach.&lt;/LI&gt;&lt;LI&gt;SAMM 2.0&lt;/LI&gt;&lt;LI&gt;Broken into 5 business pillars.&lt;/LI&gt;&lt;LI&gt;Governance, Design, Implementation, Verification, and Operations&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TedKozenko_0-1659393339266.png" style="width: 400px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/6320i9D0B0B7ADB4A089F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="TedKozenko_0-1659393339266.png" alt="TedKozenko_0-1659393339266.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Breaking down the OWASP SAMM Structure&lt;/P&gt;&lt;P&gt;Business Function – Security Practice – Stream A&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How to assess? – Never Assess Yourself – Your bias will impact your assessment…&lt;/P&gt;&lt;P&gt;Self-assessment – Use assessors who are not impacted by the results to ask questions to fully understand the reality.&lt;/P&gt;&lt;P&gt;Involve many contributors….&amp;nbsp; Get down to the people doing the day to day…&lt;/P&gt;&lt;P&gt;Interview - Don’t Audit … This is to get a true gap analysis….&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;OWASP provides a spreadsheet with questions and a scoring system for each.&amp;nbsp; This is about getting as much of the detail as possible.&amp;nbsp; Understanding the reality, no judgement on why, and don’t solution during the assessment.&lt;/P&gt;&lt;P&gt;Allows you to develop a 3 yr – (12 quarter) plan to harden your SDLC environment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;Take-aways –&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Quantifiable ways to measure security posture.&lt;/P&gt;&lt;P&gt;Covers the ENTIRE SDLC&lt;/P&gt;&lt;P&gt;Low Hanging Fruit. – Focus training on Security SDLC participants – OWAS Top 10 Training.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Include the Dev teams to help select training that is engaging...&lt;/P&gt;&lt;P&gt;Keep it simple to get them engaged to start the journey.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspire E-Learning is a low cost option - around $3K.. (Attendee Suggestion)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Engage a partner to help adopt SAMM V2 Framework and to perform the assessment to understand your gap and set a Roadmap to Secure Software Development.&lt;/P&gt;&lt;P&gt;&lt;U&gt;Contact Info:&lt;/U&gt;&lt;/P&gt;&lt;P&gt;Brendon Collins&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:Brendon.Collins@Optiv.com" target="_blank" rel="noopener"&gt;Brendon.Collins@Optiv.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;330.807.5564&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 01 Aug 2022 22:38:04 GMT</pubDate>
    <dc:creator>TedKozenko</dc:creator>
    <dc:date>2022-08-01T22:38:04Z</dc:date>
    <item>
      <title>June 2022 Meeting Minutes</title>
      <link>https://community.isc2.org/t5/Cleveland-Chapter-Discussion/June-2022-Meeting-Minutes/m-p/52260#M14</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(ISC)2 June 28th Monthly Chapter Meeting Notes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Total Registered: 49&lt;/P&gt;&lt;P&gt;Total Attendees: 36&lt;/P&gt;&lt;P&gt;Format: In-Person&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Meeting Agenda:&amp;nbsp;&lt;/STRONG&gt;(ISC)2 Cleveland Chapter Meeting, June 28, 2022&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;In person networking and conversation, Attendee Introductions&lt;/LI&gt;&lt;LI&gt;(ISC)2 Cleveland Chapter Meeting - In Person Welcome&lt;/LI&gt;&lt;LI&gt;Chatham House Rule&lt;/LI&gt;&lt;LI&gt;Chapter and (ISC)2 news and information&lt;/LI&gt;&lt;LI&gt;Officer Introductions for year 2022&lt;/LI&gt;&lt;LI&gt;Announcements - companies that are seeking &amp;amp; hiring&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Security Friends&amp;nbsp;&lt;/STRONG&gt;- A fun look at and discussion of current cyber security news stories, delivered in over the top, dramatic radio style.&lt;/LI&gt;&lt;LI&gt;Feature Presentation - Secure Software Development – how the OWASP framework can help you.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;U&gt;&amp;nbsp;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;U&gt;Notes:&lt;/U&gt;&lt;/P&gt;&lt;P&gt;5:30pm introductions and Announcements&lt;/P&gt;&lt;P&gt;5:45 – 6:15pm – Security Friends – Current Security news and events.&amp;nbsp; Included open discussion on recent Cyber attacks and new items.&lt;/P&gt;&lt;P&gt;6:15pm Featured presenter – Brandon Collins – Optiv Security – CSSLP (certified secure software lifecycle professional) - pursuing&lt;/P&gt;&lt;P&gt;Secure Software Development - How the OWAP SAMM Framework can help.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;A holistic approach.&lt;/LI&gt;&lt;LI&gt;SAMM 2.0&lt;/LI&gt;&lt;LI&gt;Broken into 5 business pillars.&lt;/LI&gt;&lt;LI&gt;Governance, Design, Implementation, Verification, and Operations&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TedKozenko_0-1659393339266.png" style="width: 400px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/6320i9D0B0B7ADB4A089F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="TedKozenko_0-1659393339266.png" alt="TedKozenko_0-1659393339266.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Breaking down the OWASP SAMM Structure&lt;/P&gt;&lt;P&gt;Business Function – Security Practice – Stream A&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How to assess? – Never Assess Yourself – Your bias will impact your assessment…&lt;/P&gt;&lt;P&gt;Self-assessment – Use assessors who are not impacted by the results to ask questions to fully understand the reality.&lt;/P&gt;&lt;P&gt;Involve many contributors….&amp;nbsp; Get down to the people doing the day to day…&lt;/P&gt;&lt;P&gt;Interview - Don’t Audit … This is to get a true gap analysis….&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;OWASP provides a spreadsheet with questions and a scoring system for each.&amp;nbsp; This is about getting as much of the detail as possible.&amp;nbsp; Understanding the reality, no judgement on why, and don’t solution during the assessment.&lt;/P&gt;&lt;P&gt;Allows you to develop a 3 yr – (12 quarter) plan to harden your SDLC environment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;Take-aways –&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Quantifiable ways to measure security posture.&lt;/P&gt;&lt;P&gt;Covers the ENTIRE SDLC&lt;/P&gt;&lt;P&gt;Low Hanging Fruit. – Focus training on Security SDLC participants – OWAS Top 10 Training.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Include the Dev teams to help select training that is engaging...&lt;/P&gt;&lt;P&gt;Keep it simple to get them engaged to start the journey.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspire E-Learning is a low cost option - around $3K.. (Attendee Suggestion)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Engage a partner to help adopt SAMM V2 Framework and to perform the assessment to understand your gap and set a Roadmap to Secure Software Development.&lt;/P&gt;&lt;P&gt;&lt;U&gt;Contact Info:&lt;/U&gt;&lt;/P&gt;&lt;P&gt;Brendon Collins&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:Brendon.Collins@Optiv.com" target="_blank" rel="noopener"&gt;Brendon.Collins@Optiv.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;330.807.5564&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Aug 2022 22:38:04 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Cleveland-Chapter-Discussion/June-2022-Meeting-Minutes/m-p/52260#M14</guid>
      <dc:creator>TedKozenko</dc:creator>
      <dc:date>2022-08-01T22:38:04Z</dc:date>
    </item>
  </channel>
</rss>

