It appears JavaScript is currently disabled in your browser. JavaScript needs to be enabled to view this recording.

Ken van WykKen van Wyk

Ken van Wyk is a CERT® Certified Computer Security Incident Handler, an internationally recognized information security expert and author of two popular O'Reilly books, Incident Response: Planning & Management and Secure Coding: Principles and Practices, as well as a monthly columnist for eSecurityPlanet. Ken is a Visiting Scientist at the Software Engineering Institute at Carnegie Mellon University, where he is a course instructor and consultant to the CERT® Coordination Center.

Ken has previously held senior information security technologist roles at Tekmark's Technology Risk Management practice, Para-Protect Services, Inc., and Science Applications International Corporation (SAIC). Ken was also the Operations Chief for the U.S. Defense Information Systems Agency's DoD-CERT incident response team, as well as a founding employee of the CERT® Coordination Center at Carnegie Mellon University's Software Engineering Institute.

Ken has previously served as the Chairman and as a member of the Steering Committee for the Forum of Incident Response and Security Teams (FIRST), a non-profit professional organization supporting the incident response community. He currently sits on their Steering Committee and Board of Directors.


description

Security testing

Learning objectives

  • design and implement application security testing campaigns
  • describe methods and tools used for security testing
  • understand the benefits and limitations of black- and white-box testing
  • perform basic penetration tests

Overview

This session covers the slew of testing practices specific to software security, applied through the different phases of a typical SDLC process. The strengths and weaknesses of different test practices are discussed in depth, along with a discussion of how to get the most out of these practices.

Partners:

Solvay Brussels School of Economics and Management Katholieke Universiteit Leuven

Affiliated organizations:

OWASP NESSoS STREWS
Creative Commons

Contents of the secappdev.org website are licensed under a Creative Commons Attribution-NonCommercial 3.0 License.