OWASP A9: A Year Later - Are you still using components with known vulnerabilities? - AppSecUSA 2014

771 views · Published 28 September 2014 · 45:23 · Indexed 24 September 2026

Channel: OWASP Foundation · 2014 · Science & Technology

Watch on YouTube

Recorded at AppSecUSA 2014 in Denver
http://2014.appsecusa.org/

Friday, September 19 • 3:00pm - 3:45pm
OWASP A9: A Year Later - Are you still using components with known vulnerabilities?
 
It's been more than a year now since the introduction of the new A9 to the OWASP Top Ten list. How are you doing to ensure you are not "using components with known vulnerabilities" in your applications? Join this session to hear real-world case studies of organizations who have taken steps to follow the best practices in this guideline to manage the use of comments across the software lifecycle. Hear what is working well and where there are still challenges. Trend data from thousands of application analyses will also be shared to provide a broader view of how we are doing as an industry to manage this risk.


Speaker

Ryan Berg
Chief Security Officer, Sonatype
Ryan is the Chief Security Officer at Sonatype. Before joining Sonatype, Ryan was a co-founder and chief scientist for Ounce Labs which was acquired by IBM in 2009. Ryan holds multiple patents and is a popular speaker, instructor and author, in the fields of security, risk management, and secure application development.

-

Managed by the official OWASP Media Project https://www.owasp.org/index.php/OWASP_Media_Project

More from this channel