2013.02.22 CAS AppSec Working Group Call

CAS AppSec Working Group Call

Meeting Details

Participants

Agenda

Meeting Notes

After brief introductions the previous meeting minutes were reviewed and approved.

Potential Tools list started and discussed.

Discussed the potential need for separate public and private mailing list for the working group.  For now continue use cas-dev for public communication, and look into setting up a private list for vulnerability discussions.

Consider adopting OWASP model (Builders, Breakers, Defenders) to help organize and prioritize various work activities.

Refine WG scope and objectives via draft charter.

Meetings to be scheduled bi-weekly preferably not on Fridays.

With the OWASP model in mind, where should the group focus our efforts first? 

Action Items

Post Meeting Notes (catch-all, Alibi's)