OS
Ofer Shezaf
Mon, Nov 12, 2012 10:17 AM
Hi All,
As promised I am opening the vote for making WAFEC a joined WASC and OWASP
project.
The proposed guidelines for this more are (updated based on comments from
the group and WASC officers):
Application Firewall Evaluation Criteria".
which is not within the project team itself has to be agreed upon by the
OWASP GPC (i.e. Project Committee) and by the WASC officers. The project
leader is the arbitrator in case of a conflict (this change is based on a
request by Jeremiah Grossman, WASC founder).
or a WASC member.
Vote Yes/No. Voting is open until Nov 19th EOD (American Samoa, that is
UTC-11, time zone)
Now for my voting pitch:
I think the change is important and would benefit WAFEC tremendously. I
would go a step further it is needed to ensure we actually succeed:
Why?
assigned and many are still waiting. Joining hands with OWASP will make
joining the project appealing to many more people.
about OWASP, and joining hands with OWASP would enable leveraging this to
reach more people. This includes chapters outreach (from Khartoum, The Sudan
to Omaha, Nebraska) as well as an official room in local and global
conferences.
the list of participants in WAFEC certainly proves that. Affiliation with
OWASP will
help popularize WAFEC also with customers, which I think is very good for
the project.
I must say I think it would be hard for me to complete the project
successfully otherwise.
~ Ofer
Ofer Shezaf
[+972-54-4431119; ofer@shezaf.com mailto:ofer@shezaf.com , www.shezaf.com]
Hi All,
As promised I am opening the vote for making WAFEC a joined WASC and OWASP
project.
The proposed guidelines for this more are (updated based on comments from
the group and WASC officers):
* The name, when affiliation is used, would be "The WASC/OWASP Web
Application Firewall Evaluation Criteria".
* Governance would be mutual, i.e. any decision about the project
which is not within the project team itself has to be agreed upon by the
OWASP GPC (i.e. Project Committee) and by the WASC officers. The project
leader is the arbitrator in case of a conflict (this change is based on a
request by Jeremiah Grossman, WASC founder).
* Participation is open for all and does not require being an OWASP
or a WASC member.
Vote Yes/No. Voting is open until Nov 19th EOD (American Samoa, that is
UTC-11, time zone)
Now for my voting pitch:
I think the change is important and would benefit WAFEC tremendously. I
would go a step further it is needed to ensure we actually succeed:
Why?
* Making it happen - we need more people. I now have two chapter
assigned and many are still waiting. Joining hands with OWASP will make
joining the project appealing to many more people.
* Outreach - people in the application security community have heard
about OWASP, and joining hands with OWASP would enable leveraging this to
reach more people. This includes chapters outreach (from Khartoum, The Sudan
to Omaha, Nebraska) as well as an official room in local and global
conferences.
* Vendor image - WASC is perceived as a "vendors' organization" and
the list of participants in WAFEC certainly proves that. Affiliation with
OWASP will
help popularize WAFEC also with customers, which I think is very good for
the project.
I must say I think it would be hard for me to complete the project
successfully otherwise.
~ Ofer
Ofer Shezaf
[+972-54-4431119; ofer@shezaf.com <mailto:ofer@shezaf.com> , www.shezaf.com]
AH
Achim Hoffmann
Mon, Nov 12, 2012 10:50 AM
Hi Ofer,
my vote is yes: join WASC and OWASP for WAFEC.
According your description, I'll have some questions for clarification, please
see inline below.
Cheers
Achim
Am 12.11.2012 11:17, schrieb Ofer Shezaf:
Hi All,
As promised I am opening the vote for making WAFEC a joined WASC and OWASP
project.
The proposed guidelines for this more are (updated based on comments from
the group and WASC officers):
Application Firewall Evaluation Criteria".
which is not within the project team itself has to be agreed upon by the
OWASP GPC (i.e. Project Committee) and by the WASC officers.
What does this mean: "decision about the project which is not within the project team"
Could you please give an example.
I.g. OWASP GPC only gives the "go" for a project, that's it.
If a project gets abandoned, it will be marked so.
The project
leader is the arbitrator in case of a conflict (this change is based on a
request by Jeremiah Grossman, WASC founder).
Does this mean that the (OWASP) project leader does not/must not participate in
writing the document?
@Jeremiah, I can imagine your objections due to other (probably;-) biased projects,
but a bit a description of what the leader should and should not do would be nice.
or a WASC member.
Vote Yes/No. Voting is open until Nov 19th EOD (American Samoa, that is
UTC-11, time zone)
Now for my voting pitch:
I think the change is important and would benefit WAFEC tremendously. I
would go a step further it is needed to ensure we actually succeed:
Why?
assigned and many are still waiting. Joining hands with OWASP will make
joining the project appealing to many more people.
about OWASP, and joining hands with OWASP would enable leveraging this to
reach more people. This includes chapters outreach (from Khartoum, The Sudan
to Omaha, Nebraska) as well as an official room in local and global
conferences.
the list of participants in WAFEC certainly proves that. Affiliation with
OWASP will
help popularize WAFEC also with customers, which I think is very good for
the project.
I must say I think it would be hard for me to complete the project
successfully otherwise.
~ Ofer
Hi Ofer,
my vote is yes: join WASC and OWASP for WAFEC.
According your description, I'll have some questions for clarification, please
see inline below.
Cheers
Achim
Am 12.11.2012 11:17, schrieb Ofer Shezaf:
>
>
> Hi All,
>
>
>
> As promised I am opening the vote for making WAFEC a joined WASC and OWASP
> project.
>
>
>
> The proposed guidelines for this more are (updated based on comments from
> the group and WASC officers):
>
> * The name, when affiliation is used, would be "The WASC/OWASP Web
> Application Firewall Evaluation Criteria".
>
> * Governance would be mutual, i.e. any decision about the project
> which is not within the project team itself has to be agreed upon by the
> OWASP GPC (i.e. Project Committee) and by the WASC officers.
What does this mean: "decision about the project which is not within the project team"
Could you please give an example.
I.g. OWASP GPC only gives the "go" for a project, that's it.
If a project gets abandoned, it will be marked so.
> The project
> leader is the arbitrator in case of a conflict (this change is based on a
> request by Jeremiah Grossman, WASC founder).
Does this mean that the (OWASP) project leader does not/must not participate in
writing the document?
@Jeremiah, I can imagine your objections due to other (probably;-) biased projects,
but a bit a description of what the leader should and should not do would be nice.
>
> * Participation is open for all and does not require being an OWASP
> or a WASC member.
>
>
>
> Vote Yes/No. Voting is open until Nov 19th EOD (American Samoa, that is
> UTC-11, time zone)
>
>
>
> Now for my voting pitch:
>
>
>
> I think the change is important and would benefit WAFEC tremendously. I
> would go a step further it is needed to ensure we actually succeed:
>
>
>
> Why?
>
> * Making it happen - we need more people. I now have two chapter
> assigned and many are still waiting. Joining hands with OWASP will make
> joining the project appealing to many more people.
>
>
>
> * Outreach - people in the application security community have heard
> about OWASP, and joining hands with OWASP would enable leveraging this to
> reach more people. This includes chapters outreach (from Khartoum, The Sudan
> to Omaha, Nebraska) as well as an official room in local and global
> conferences.
>
>
>
> * Vendor image - WASC is perceived as a "vendors' organization" and
> the list of participants in WAFEC certainly proves that. Affiliation with
> OWASP will
>
> help popularize WAFEC also with customers, which I think is very good for
> the project.
>
>
>
> I must say I think it would be hard for me to complete the project
> successfully otherwise.
>
>
>
> ~ Ofer
JT
Julian Totzek
Mon, Nov 12, 2012 10:55 AM
Hi,
my vote is as well yes: join WASC and OWASP for WAFEC.
Cheers
Julian Totzek-Hallhuber
Pre Sales Team Leader
Direct: +49 6124 70 25 50 2
Mobile : +49 160 97 28 50 04
jtotzek@denyall.commailto:jtotzek@denyall.com
Am 12.11.2012 um 11:17 schrieb Ofer Shezaf <ofer@shezaf.commailto:ofer@shezaf.com>
:
Hi All,
As promised I am opening the vote for making WAFEC a joined WASC and OWASP project.
The proposed guidelines for this more are (updated based on comments from the group and WASC officers):
• The name, when affiliation is used, would be "The WASC/OWASP Web Application Firewall Evaluation Criteria".
• Governance would be mutual, i.e. any decision about the project which is not within the project team itself has to be agreed upon by the OWASP GPC (i.e. Project Committee) and by the WASC officers. The project leader is the arbitrator in case of a conflict (this change is based on a request by Jeremiah Grossman, WASC founder).
• Participation is open for all and does not require being an OWASP or a WASC member.
Vote Yes/No. Voting is open until Nov 19th EOD (American Samoa, that is UTC-11, time zone)
Now for my voting pitch:
I think the change is important and would benefit WAFEC tremendously. I would go a step further it is needed to ensure we actually succeed:
Why?
• Making it happen – we need more people. I now have two chapter assigned and many are still waiting. Joining hands with OWASP will make joining the project appealing to many more people.
• Outreach – people in the application security community have heard about OWASP, and joining hands with OWASP would enable leveraging this to reach more people. This includes chapters outreach (from Khartoum, The Sudan to Omaha, Nebraska) as well as an official room in local and global conferences.
• Vendor image - WASC is perceived as a "vendors' organization" and the list of participants in WAFEC certainly proves that. Affiliation with OWASP will
help popularize WAFEC also with customers, which I think is very good for the project.
I must say I think it would be hard for me to complete the project successfully otherwise.
~ Ofer
Ofer Shezaf
[+972-54-4431119; ofer@shezaf.commailto:ofer@shezaf.com, www.shezaf.comhttp://www.shezaf.com]
wasc-wafec mailing list
wasc-wafec@lists.webappsec.orgmailto:wasc-wafec@lists.webappsec.org
http://lists.webappsec.org/mailman/listinfo/wasc-wafec_lists.webappsec.org
Hi,
my vote is as well yes: join WASC and OWASP for WAFEC.
Cheers
Julian Totzek-Hallhuber
Pre Sales Team Leader
Direct: +49 6124 70 25 50 2
Mobile : +49 160 97 28 50 04
jtotzek@denyall.com<mailto:jtotzek@denyall.com>
Am 12.11.2012 um 11:17 schrieb Ofer Shezaf <ofer@shezaf.com<mailto:ofer@shezaf.com>>
:
Hi All,
As promised I am opening the vote for making WAFEC a joined WASC and OWASP project.
The proposed guidelines for this more are (updated based on comments from the group and WASC officers):
• The name, when affiliation is used, would be "The WASC/OWASP Web Application Firewall Evaluation Criteria".
• Governance would be mutual, i.e. any decision about the project which is not within the project team itself has to be agreed upon by the OWASP GPC (i.e. Project Committee) and by the WASC officers. The project leader is the arbitrator in case of a conflict (this change is based on a request by Jeremiah Grossman, WASC founder).
• Participation is open for all and does not require being an OWASP or a WASC member.
Vote Yes/No. Voting is open until Nov 19th EOD (American Samoa, that is UTC-11, time zone)
Now for my voting pitch:
I think the change is important and would benefit WAFEC tremendously. I would go a step further it is needed to ensure we actually succeed:
Why?
• Making it happen – we need more people. I now have two chapter assigned and many are still waiting. Joining hands with OWASP will make joining the project appealing to many more people.
• Outreach – people in the application security community have heard about OWASP, and joining hands with OWASP would enable leveraging this to reach more people. This includes chapters outreach (from Khartoum, The Sudan to Omaha, Nebraska) as well as an official room in local and global conferences.
• Vendor image - WASC is perceived as a "vendors' organization" and the list of participants in WAFEC certainly proves that. Affiliation with OWASP will
help popularize WAFEC also with customers, which I think is very good for the project.
I must say I think it would be hard for me to complete the project successfully otherwise.
~ Ofer
Ofer Shezaf
[+972-54-4431119; ofer@shezaf.com<mailto:ofer@shezaf.com>, www.shezaf.com<http://www.shezaf.com>]
_______________________________________________
wasc-wafec mailing list
wasc-wafec@lists.webappsec.org<mailto:wasc-wafec@lists.webappsec.org>
http://lists.webappsec.org/mailman/listinfo/wasc-wafec_lists.webappsec.org
S
Seba
Mon, Nov 12, 2012 11:36 AM
I vote yes.
Seba
On Mon, Nov 12, 2012 at 11:17 AM, Ofer Shezaf ofer@shezaf.com wrote:
Hi All,****
As promised I am opening the vote for making WAFEC a joined WASC and OWASP
project.****
The proposed guidelines for this more are (updated based on comments from
the group and WASC officers):****
· The name, when affiliation is used, would be "The
WASC/OWASP Web Application Firewall Evaluation Criteria".
· Governance would be mutual, i.e. any decision about the
project which is not within the project team itself has to be agreed upon
by the OWASP GPC (i.e. Project Committee) and by the WASC officers. The
project leader is the arbitrator in case of a conflict (this change is
based on a request by Jeremiah Grossman, WASC founder).
· Participation is open for all and does not require being an
OWASP or a WASC member.
Vote Yes/No. Voting is open until Nov 19th EOD (American Samoa, that is
UTC-11, time zone)****
Now for my voting pitch:****
I think the change is important and would benefit WAFEC tremendously. I
would go a step further it is needed to ensure we actually succeed:****
Why?****
· Making it happen – we need more people. I now have two
chapter assigned and many are still waiting. Joining hands with OWASP will
make joining the project appealing to many more people.
· Outreach – people in the application security community
have heard about OWASP, and joining hands with OWASP would enable
leveraging this to reach more people. This includes chapters outreach (from
Khartoum, The Sudan to Omaha, Nebraska) as well as an official room in
local and global conferences.
· Vendor image - WASC is perceived as a "vendors'
organization" and the list of participants in WAFEC certainly proves that.
Affiliation with OWASP will
help popularize WAFEC also with customers, which I think is very good for
the project.****
I must say I think it would be hard for me to complete the project
successfully otherwise. ****
~ Ofer****
Ofer Shezaf****
[+972-54-4431119; ofer@shezaf.com, www.shezaf.com]****
wasc-wafec mailing list
wasc-wafec@lists.webappsec.org
http://lists.webappsec.org/mailman/listinfo/wasc-wafec_lists.webappsec.org
I vote yes.
Seba
On Mon, Nov 12, 2012 at 11:17 AM, Ofer Shezaf <ofer@shezaf.com> wrote:
> ** **
>
> Hi All,****
>
> ** **
>
> As promised I am opening the vote for making WAFEC a joined WASC and OWASP
> project.****
>
> ** **
>
> The proposed guidelines for this more are (updated based on comments from
> the group and WASC officers):****
>
> **· **The name, when affiliation is used, would be "The
> WASC/OWASP Web Application Firewall Evaluation Criteria".****
>
> **· **Governance would be mutual, i.e. any decision about the
> project which is not within the project team itself has to be agreed upon
> by the OWASP GPC (i.e. Project Committee) and by the WASC officers. The
> project leader is the arbitrator in case of a conflict (this change is
> based on a request by Jeremiah Grossman, WASC founder).****
>
> **· **Participation is open for all and does not require being an
> OWASP or a WASC member.****
>
> ** **
>
> Vote Yes/No. Voting is open until Nov 19th EOD (American Samoa, that is
> UTC-11, time zone)****
>
> ** **
>
> Now for my voting pitch:****
>
> ** **
>
> I think the change is important and would benefit WAFEC tremendously. I
> would go a step further it is needed to ensure we actually succeed:****
>
> ** **
>
> Why?****
>
> **· **Making it happen – we need more people. I now have two
> chapter assigned and many are still waiting. Joining hands with OWASP will
> make joining the project appealing to many more people.****
>
> ** **
>
> **· **Outreach – people in the application security community
> have heard about OWASP, and joining hands with OWASP would enable
> leveraging this to reach more people. This includes chapters outreach (from
> Khartoum, The Sudan to Omaha, Nebraska) as well as an official room in
> local and global conferences.****
>
> ** **
>
> **· **Vendor image - WASC is perceived as a "vendors'
> organization" and the list of participants in WAFEC certainly proves that.
> Affiliation with OWASP will****
>
> help popularize WAFEC also with customers, which I think is very good for
> the project.****
>
> ** **
>
> I must say I think it would be hard for me to complete the project
> successfully otherwise. ****
>
> ** **
>
> ~ Ofer****
>
> ** **
>
> Ofer Shezaf****
>
> [+972-54-4431119; ofer@shezaf.com, www.shezaf.com]****
>
> ** **
>
> _______________________________________________
> wasc-wafec mailing list
> wasc-wafec@lists.webappsec.org
> http://lists.webappsec.org/mailman/listinfo/wasc-wafec_lists.webappsec.org
>
>
JW
Jeff Williams
Mon, Nov 12, 2012 2:21 PM
I vote yes.
Seba
On Mon, Nov 12, 2012 at 11:17 AM, Ofer Shezaf ofer@shezaf.com wrote:
Hi All,
As promised I am opening the vote for making WAFEC a joined WASC and OWASP project.
The proposed guidelines for this more are (updated based on comments from the group and WASC officers):
· The name, when affiliation is used, would be "The WASC/OWASP Web Application Firewall Evaluation Criteria".
· Governance would be mutual, i.e. any decision about the project which is not within the project team itself has to be agreed upon by the OWASP GPC (i.e. Project Committee) and by the WASC officers. The project leader is the arbitrator in case of a conflict (this change is based on a request by Jeremiah Grossman, WASC founder).
· Participation is open for all and does not require being an OWASP or a WASC member.
Vote Yes/No. Voting is open until Nov 19th EOD (American Samoa, that is UTC-11, time zone)
Now for my voting pitch:
I think the change is important and would benefit WAFEC tremendously. I would go a step further it is needed to ensure we actually succeed:
Why?
· Making it happen – we need more people. I now have two chapter assigned and many are still waiting. Joining hands with OWASP will make joining the project appealing to many more people.
· Outreach – people in the application security community have heard about OWASP, and joining hands with OWASP would enable leveraging this to reach more people. This includes chapters outreach (from Khartoum, The Sudan to Omaha, Nebraska) as well as an official room in local and global conferences.
· Vendor image - WASC is perceived as a "vendors' organization" and the list of participants in WAFEC certainly proves that. Affiliation with OWASP will
help popularize WAFEC also with customers, which I think is very good for the project.
I must say I think it would be hard for me to complete the project successfully otherwise.
~ Ofer
Ofer Shezaf
[+972-54-4431119; ofer@shezaf.com, www.shezaf.com]
wasc-wafec mailing list
wasc-wafec@lists.webappsec.org
http://lists.webappsec.org/mailman/listinfo/wasc-wafec_lists.webappsec.org
Yes.
--Jeff
On Nov 12, 2012, at 6:36 AM, "Seba" <seba@owasp.org> wrote:
> I vote yes.
>
> Seba
>
>
>
> On Mon, Nov 12, 2012 at 11:17 AM, Ofer Shezaf <ofer@shezaf.com> wrote:
>>
>>
>> Hi All,
>>
>>
>>
>> As promised I am opening the vote for making WAFEC a joined WASC and OWASP project.
>>
>>
>>
>> The proposed guidelines for this more are (updated based on comments from the group and WASC officers):
>>
>> · The name, when affiliation is used, would be "The WASC/OWASP Web Application Firewall Evaluation Criteria".
>>
>> · Governance would be mutual, i.e. any decision about the project which is not within the project team itself has to be agreed upon by the OWASP GPC (i.e. Project Committee) and by the WASC officers. The project leader is the arbitrator in case of a conflict (this change is based on a request by Jeremiah Grossman, WASC founder).
>>
>> · Participation is open for all and does not require being an OWASP or a WASC member.
>>
>>
>>
>> Vote Yes/No. Voting is open until Nov 19th EOD (American Samoa, that is UTC-11, time zone)
>>
>>
>>
>> Now for my voting pitch:
>>
>>
>>
>> I think the change is important and would benefit WAFEC tremendously. I would go a step further it is needed to ensure we actually succeed:
>>
>>
>>
>> Why?
>>
>> · Making it happen – we need more people. I now have two chapter assigned and many are still waiting. Joining hands with OWASP will make joining the project appealing to many more people.
>>
>>
>>
>> · Outreach – people in the application security community have heard about OWASP, and joining hands with OWASP would enable leveraging this to reach more people. This includes chapters outreach (from Khartoum, The Sudan to Omaha, Nebraska) as well as an official room in local and global conferences.
>>
>>
>>
>> · Vendor image - WASC is perceived as a "vendors' organization" and the list of participants in WAFEC certainly proves that. Affiliation with OWASP will
>>
>> help popularize WAFEC also with customers, which I think is very good for the project.
>>
>>
>>
>> I must say I think it would be hard for me to complete the project successfully otherwise.
>>
>>
>>
>> ~ Ofer
>>
>>
>>
>> Ofer Shezaf
>>
>> [+972-54-4431119; ofer@shezaf.com, www.shezaf.com]
>>
>>
>>
>>
>> _______________________________________________
>> wasc-wafec mailing list
>> wasc-wafec@lists.webappsec.org
>> http://lists.webappsec.org/mailman/listinfo/wasc-wafec_lists.webappsec.org
>
> _______________________________________________
> wasc-wafec mailing list
> wasc-wafec@lists.webappsec.org
> http://lists.webappsec.org/mailman/listinfo/wasc-wafec_lists.webappsec.org
PS
Przemyslaw Skowron
Mon, Nov 12, 2012 2:22 PM
Yes.
--
Przemyslaw Skowron, <przemyslaw.skowron {at} gmail.com>
Yes.
--
Przemyslaw Skowron, <przemyslaw.skowron {at} gmail.com>
RB
Ryan Barnett
Mon, Nov 12, 2012 5:31 PM
Hi All,
As promised I am opening the vote for making WAFEC a joined WASC and OWASP
project.
The proposed guidelines for this more are (updated based on comments from the
group and WASC officers):
· The name, when affiliation is used, would be "The WASC/OWASP Web
Application Firewall Evaluation Criteria".
· Governance would be mutual, i.e. any decision about the project
which is not within the project team itself has to be agreed upon by the OWASP
GPC (i.e. Project Committee) and by the WASC officers. The project leader is
the arbitrator in case of a conflict (this change is based on a request by
Jeremiah Grossman, WASC founder).
· Participation is open for all and does not require being an OWASP or
a WASC member.
Vote Yes/No. Voting is open until Nov 19th EOD (American Samoa, that is
UTC-11, time zone)
Now for my voting pitch:
I think the change is important and would benefit WAFEC tremendously. I would
go a step further it is needed to ensure we actually succeed:
Why?
· Making it happen we need more people. I now have two chapter
assigned and many are still waiting. Joining hands with OWASP will make
joining the project appealing to many more people.
· Outreach people in the application security community have heard
about OWASP, and joining hands with OWASP would enable leveraging this to
reach more people. This includes chapters outreach (from Khartoum, The Sudan
to Omaha, Nebraska) as well as an official room in local and global
conferences.
· Vendor image - WASC is perceived as a "vendors' organization" and
the list of participants in WAFEC certainly proves that. Affiliation with
OWASP will
help popularize WAFEC also with customers, which I think is very good for the
project.
I must say I think it would be hard for me to complete the project
successfully otherwise.
~ Ofer
Ofer Shezaf
[+972-54-4431119; ofer@shezaf.com, www.shezaf.com]
_______________________________________________ wasc-wafec mailing list
wasc-wafec@lists.webappsec.org
http://lists.webappsec.org/mailman/listinfo/wasc-wafec_lists.webappsec.org
I vote YES.
From: Ofer Shezaf <ofer@shezaf.com>
Date: Monday, November 12, 2012 5:17 AM
To: <wasc-wafec@lists.webappsec.org>
Subject: [WASC-WAFEC] Vote on making WAFEC a WASC/OWASP project
>
> Hi All,
>
> As promised I am opening the vote for making WAFEC a joined WASC and OWASP
> project.
>
> The proposed guidelines for this more are (updated based on comments from the
> group and WASC officers):
> · The name, when affiliation is used, would be "The WASC/OWASP Web
> Application Firewall Evaluation Criteria".
>
> · Governance would be mutual, i.e. any decision about the project
> which is not within the project team itself has to be agreed upon by the OWASP
> GPC (i.e. Project Committee) and by the WASC officers. The project leader is
> the arbitrator in case of a conflict (this change is based on a request by
> Jeremiah Grossman, WASC founder).
>
> · Participation is open for all and does not require being an OWASP or
> a WASC member.
>
>
> Vote Yes/No. Voting is open until Nov 19th EOD (American Samoa, that is
> UTC-11, time zone)
>
> Now for my voting pitch:
>
> I think the change is important and would benefit WAFEC tremendously. I would
> go a step further it is needed to ensure we actually succeed:
>
> Why?
> · Making it happen we need more people. I now have two chapter
> assigned and many are still waiting. Joining hands with OWASP will make
> joining the project appealing to many more people.
>
>
>
> · Outreach people in the application security community have heard
> about OWASP, and joining hands with OWASP would enable leveraging this to
> reach more people. This includes chapters outreach (from Khartoum, The Sudan
> to Omaha, Nebraska) as well as an official room in local and global
> conferences.
>
>
>
> · Vendor image - WASC is perceived as a "vendors' organization" and
> the list of participants in WAFEC certainly proves that. Affiliation with
> OWASP will
>
> help popularize WAFEC also with customers, which I think is very good for the
> project.
>
>
> I must say I think it would be hard for me to complete the project
> successfully otherwise.
>
> ~ Ofer
>
> Ofer Shezaf
> [+972-54-4431119; ofer@shezaf.com, www.shezaf.com]
>
> _______________________________________________ wasc-wafec mailing list
> wasc-wafec@lists.webappsec.org
> http://lists.webappsec.org/mailman/listinfo/wasc-wafec_lists.webappsec.org
OS
Ofer Shezaf
Mon, Nov 12, 2012 7:35 PM
I think that Jeremiah comment was about conflict between WASC and OWASP and not between team members, we are too many to assume a vote would end in a draw (and too few writers to allow me not to write anything).
This of course brings us back to the governance questions in the 1st place: when would a WASC officers and a GPC decision needed. As usual such clauses are there to avoid unintended results even if not foreseen now. Setting general guidelines for projects at OWASP or WASC would be a good example. A recent (and not very critical) example was a suggestion to have all projects move to a common source repository made several weeks ago. The common governance rules means that WAFEC would not have to follow that new guideline.
~ Ofer
-----Original Message-----
From: Achim Hoffmann [mailto:websec10@sic-sec.org]
Sent: Monday, November 12, 2012 12:51 PM
To: Ofer Shezaf
Cc: wasc-wafec@lists.webappsec.org
Subject: Re: [WASC-WAFEC] Vote on making WAFEC a WASC/OWASP project
Hi Ofer,
my vote is yes: join WASC and OWASP for WAFEC.
According your description, I'll have some questions for clarification, please see inline below.
Cheers
Achim
Am 12.11.2012 11:17, schrieb Ofer Shezaf:
Hi All,
As promised I am opening the vote for making WAFEC a joined WASC and
OWASP project.
The proposed guidelines for this more are (updated based on comments
from the group and WASC officers):
Application Firewall Evaluation Criteria".
which is not within the project team itself has to be agreed upon by
the OWASP GPC (i.e. Project Committee) and by the WASC officers.
What does this mean: "decision about the project which is not within the project team"
Could you please give an example.
I.g. OWASP GPC only gives the "go" for a project, that's it.
If a project gets abandoned, it will be marked so.
The project
leader is the arbitrator in case of a conflict (this change is based
on a request by Jeremiah Grossman, WASC founder).
Does this mean that the (OWASP) project leader does not/must not participate in writing the document?
@Jeremiah, I can imagine your objections due to other (probably;-) biased projects, but a bit a description of what the leader should and should not do would be nice.
or a WASC member.
Vote Yes/No. Voting is open until Nov 19th EOD (American Samoa, that
is UTC-11, time zone)
Now for my voting pitch:
I think the change is important and would benefit WAFEC tremendously.
I would go a step further it is needed to ensure we actually succeed:
Why?
assigned and many are still waiting. Joining hands with OWASP will
make joining the project appealing to many more people.
about OWASP, and joining hands with OWASP would enable leveraging this
to reach more people. This includes chapters outreach (from Khartoum,
The Sudan to Omaha, Nebraska) as well as an official room in local and
global conferences.
the list of participants in WAFEC certainly proves that. Affiliation
with OWASP will
help popularize WAFEC also with customers, which I think is very good
for the project.
I must say I think it would be hard for me to complete the project
successfully otherwise.
~ Ofer
I think that Jeremiah comment was about conflict between WASC and OWASP and not between team members, we are too many to assume a vote would end in a draw (and too few writers to allow me not to write anything).
This of course brings us back to the governance questions in the 1st place: when would a WASC officers and a GPC decision needed. As usual such clauses are there to avoid unintended results even if not foreseen now. Setting general guidelines for projects at OWASP or WASC would be a good example. A recent (and not very critical) example was a suggestion to have all projects move to a common source repository made several weeks ago. The common governance rules means that WAFEC would not have to follow that new guideline.
~ Ofer
-----Original Message-----
From: Achim Hoffmann [mailto:websec10@sic-sec.org]
Sent: Monday, November 12, 2012 12:51 PM
To: Ofer Shezaf
Cc: wasc-wafec@lists.webappsec.org
Subject: Re: [WASC-WAFEC] Vote on making WAFEC a WASC/OWASP project
Hi Ofer,
my vote is yes: join WASC and OWASP for WAFEC.
According your description, I'll have some questions for clarification, please see inline below.
Cheers
Achim
Am 12.11.2012 11:17, schrieb Ofer Shezaf:
>
>
> Hi All,
>
>
>
> As promised I am opening the vote for making WAFEC a joined WASC and
> OWASP project.
>
>
>
> The proposed guidelines for this more are (updated based on comments
> from the group and WASC officers):
>
> * The name, when affiliation is used, would be "The WASC/OWASP Web
> Application Firewall Evaluation Criteria".
>
> * Governance would be mutual, i.e. any decision about the project
> which is not within the project team itself has to be agreed upon by
> the OWASP GPC (i.e. Project Committee) and by the WASC officers.
What does this mean: "decision about the project which is not within the project team"
Could you please give an example.
I.g. OWASP GPC only gives the "go" for a project, that's it.
If a project gets abandoned, it will be marked so.
> The project
> leader is the arbitrator in case of a conflict (this change is based
> on a request by Jeremiah Grossman, WASC founder).
Does this mean that the (OWASP) project leader does not/must not participate in writing the document?
@Jeremiah, I can imagine your objections due to other (probably;-) biased projects, but a bit a description of what the leader should and should not do would be nice.
>
> * Participation is open for all and does not require being an OWASP
> or a WASC member.
>
>
>
> Vote Yes/No. Voting is open until Nov 19th EOD (American Samoa, that
> is UTC-11, time zone)
>
>
>
> Now for my voting pitch:
>
>
>
> I think the change is important and would benefit WAFEC tremendously.
> I would go a step further it is needed to ensure we actually succeed:
>
>
>
> Why?
>
> * Making it happen - we need more people. I now have two chapter
> assigned and many are still waiting. Joining hands with OWASP will
> make joining the project appealing to many more people.
>
>
>
> * Outreach - people in the application security community have heard
> about OWASP, and joining hands with OWASP would enable leveraging this
> to reach more people. This includes chapters outreach (from Khartoum,
> The Sudan to Omaha, Nebraska) as well as an official room in local and
> global conferences.
>
>
>
> * Vendor image - WASC is perceived as a "vendors' organization" and
> the list of participants in WAFEC certainly proves that. Affiliation
> with OWASP will
>
> help popularize WAFEC also with customers, which I think is very good
> for the project.
>
>
>
> I must say I think it would be hard for me to complete the project
> successfully otherwise.
>
>
>
> ~ Ofer
CH
Christian Heinrich
Mon, Nov 12, 2012 8:55 PM
Ofer,
I have been able to address some but not all of your e-mail and I will
attempt to complete the reply over this weekend i.e. before 19
November.
Below is what I can address right at this moment:
On Mon, Nov 12, 2012 at 9:17 PM, Ofer Shezaf ofer@shezaf.com wrote:
· The name, when affiliation is used, would be "The WASC/OWASP Web
Application Firewall Evaluation Criteria".
This doesn't resolve the issue around the (false) vendor perception of
WASC, since "WASC" would still be quoted within the project title.
Hence, I would recommend that we remove "WASC" and give complete
project ownership to OWASP i.e. "The OWASP Web Application Firewall
Evaluation Criteria" otherwise this (false) perception would remain?
On Mon, Nov 12, 2012 at 9:17 PM, Ofer Shezaf ofer@shezaf.com wrote:
· Participation is open for all and does not require being an OWASP
or a WASC member.
Will I be able to present WAFEC at OWASP Conferences and Chapters?
On Mon, Nov 12, 2012 at 9:17 PM, Ofer Shezaf ofer@shezaf.com wrote:
Vote Yes/No. Voting is open until Nov 19th EOD (American Samoa, that is
UTC-11, time zone)
I believe the vote should be weighted somehow based on people
allegiance to OWASP and/or WASC otherwise the vote could be perceived
as bias?
--
Regards,
Christian Heinrich
http://cmlh.id.au/contact
Ofer,
I have been able to address some but not all of your e-mail and I will
attempt to complete the reply over this weekend i.e. before 19
November.
Below is what I can address right at this moment:
On Mon, Nov 12, 2012 at 9:17 PM, Ofer Shezaf <ofer@shezaf.com> wrote:
> · The name, when affiliation is used, would be "The WASC/OWASP Web
> Application Firewall Evaluation Criteria".
This doesn't resolve the issue around the (false) vendor perception of
WASC, since "WASC" would still be quoted within the project title.
Hence, I would recommend that we remove "WASC" and give complete
project ownership to OWASP i.e. "The OWASP Web Application Firewall
Evaluation Criteria" otherwise this (false) perception would remain?
On Mon, Nov 12, 2012 at 9:17 PM, Ofer Shezaf <ofer@shezaf.com> wrote:
> · Participation is open for all and does not require being an OWASP
> or a WASC member.
Will I be able to present WAFEC at OWASP Conferences and Chapters?
On Mon, Nov 12, 2012 at 9:17 PM, Ofer Shezaf <ofer@shezaf.com> wrote:
> Vote Yes/No. Voting is open until Nov 19th EOD (American Samoa, that is
> UTC-11, time zone)
I believe the vote should be weighted somehow based on people
allegiance to OWASP and/or WASC otherwise the vote could be perceived
as bias?
--
Regards,
Christian Heinrich
http://cmlh.id.au/contact
OS
Ofer Shezaf
Mon, Nov 12, 2012 9:13 PM
With regards to most of your comments: I am not going to change the voting
agenda and process now.
With regard to presenting WAFEC in OWASP events, I think this is an
important comment and my answer is that as a WAFEC project member you should
be able to and I will make sure this is known. I need to say I don't think
you are limited from presenting in OWASP meetings today - presentation is
not limited to OWASP members.
~ Ofer
-----Original Message-----
From: Christian Heinrich [mailto:christian.heinrich@cmlh.id.au]
Sent: Monday, November 12, 2012 10:56 PM
To: Ofer Shezaf
Cc: wasc-wafec@lists.webappsec.org
Subject: Re: [WASC-WAFEC] Vote on making WAFEC a WASC/OWASP project
Ofer,
I have been able to address some but not all of your e-mail and I will
attempt to complete the reply over this weekend i.e. before 19 November.
Below is what I can address right at this moment:
On Mon, Nov 12, 2012 at 9:17 PM, Ofer Shezaf ofer@shezaf.com wrote:
. The name, when affiliation is used, would be "The WASC/OWASP Web
Application Firewall Evaluation Criteria".
This doesn't resolve the issue around the (false) vendor perception of WASC,
since "WASC" would still be quoted within the project title.
Hence, I would recommend that we remove "WASC" and give complete project
ownership to OWASP i.e. "The OWASP Web Application Firewall Evaluation
Criteria" otherwise this (false) perception would remain?
On Mon, Nov 12, 2012 at 9:17 PM, Ofer Shezaf ofer@shezaf.com wrote:
. Participation is open for all and does not require being an
Will I be able to present WAFEC at OWASP Conferences and Chapters?
On Mon, Nov 12, 2012 at 9:17 PM, Ofer Shezaf ofer@shezaf.com wrote:
Vote Yes/No. Voting is open until Nov 19th EOD (American Samoa, that
is UTC-11, time zone)
I believe the vote should be weighted somehow based on people allegiance to
OWASP and/or WASC otherwise the vote could be perceived as bias?
--
Regards,
Christian Heinrich
http://cmlh.id.au/contact
With regards to most of your comments: I am not going to change the voting
agenda and process now.
With regard to presenting WAFEC in OWASP events, I think this is an
important comment and my answer is that as a WAFEC project member you should
be able to and I will make sure this is known. I need to say I don't think
you are limited from presenting in OWASP meetings today - presentation is
not limited to OWASP members.
~ Ofer
-----Original Message-----
From: Christian Heinrich [mailto:christian.heinrich@cmlh.id.au]
Sent: Monday, November 12, 2012 10:56 PM
To: Ofer Shezaf
Cc: wasc-wafec@lists.webappsec.org
Subject: Re: [WASC-WAFEC] Vote on making WAFEC a WASC/OWASP project
Ofer,
I have been able to address some but not all of your e-mail and I will
attempt to complete the reply over this weekend i.e. before 19 November.
Below is what I can address right at this moment:
On Mon, Nov 12, 2012 at 9:17 PM, Ofer Shezaf <ofer@shezaf.com> wrote:
> . The name, when affiliation is used, would be "The WASC/OWASP Web
> Application Firewall Evaluation Criteria".
This doesn't resolve the issue around the (false) vendor perception of WASC,
since "WASC" would still be quoted within the project title.
Hence, I would recommend that we remove "WASC" and give complete project
ownership to OWASP i.e. "The OWASP Web Application Firewall Evaluation
Criteria" otherwise this (false) perception would remain?
On Mon, Nov 12, 2012 at 9:17 PM, Ofer Shezaf <ofer@shezaf.com> wrote:
> . Participation is open for all and does not require being an
OWASP
> or a WASC member.
Will I be able to present WAFEC at OWASP Conferences and Chapters?
On Mon, Nov 12, 2012 at 9:17 PM, Ofer Shezaf <ofer@shezaf.com> wrote:
> Vote Yes/No. Voting is open until Nov 19th EOD (American Samoa, that
> is UTC-11, time zone)
I believe the vote should be weighted somehow based on people allegiance to
OWASP and/or WASC otherwise the vote could be perceived as bias?
--
Regards,
Christian Heinrich
http://cmlh.id.au/contact
RA
Robert A.
Mon, Nov 12, 2012 9:28 PM
· The name, when affiliation is used, would be "The WASC/OWASP Web
Application Firewall Evaluation Criteria".
This doesn't resolve the issue around the (false) vendor perception of
WASC, since "WASC" would still be quoted within the project title.
Hence, I would recommend that we remove "WASC" and give complete
project ownership to OWASP i.e. "The OWASP Web Application Firewall
Evaluation Criteria" otherwise this (false) perception would remain?
If there's a perception issue of WASC (which I haven't seen for a few
years now myself), I don't think the answer is for us to abandon our
sucessful projects entirely to OWASP. If I'm misunderstanding please let
me know.
Open to Ofer's thoughts.
Regards,
> On Mon, Nov 12, 2012 at 9:17 PM, Ofer Shezaf <ofer@shezaf.com> wrote:
>> · The name, when affiliation is used, would be "The WASC/OWASP Web
>> Application Firewall Evaluation Criteria".
>
> This doesn't resolve the issue around the (false) vendor perception of
> WASC, since "WASC" would still be quoted within the project title.
>
> Hence, I would recommend that we remove "WASC" and give complete
> project ownership to OWASP i.e. "The OWASP Web Application Firewall
> Evaluation Criteria" otherwise this (false) perception would remain?
If there's a perception issue of WASC (which I haven't seen for a few
years now myself), I don't think the answer is for us to abandon our
sucessful projects entirely to OWASP. If I'm misunderstanding please let
me know.
Open to Ofer's thoughts.
Regards,
- Robert Auger
CH
Christian Heinrich
Mon, Nov 12, 2012 11:14 PM
With regard to presenting WAFEC in OWASP events, I think this is an
important comment and my answer is that as a WAFEC project member you should
be able to and I will make sure this is known. I need to say I don't think
you are limited from presenting in OWASP meetings today - presentation is
not limited to OWASP members.
Ofer,
On Tue, Nov 13, 2012 at 8:13 AM, Ofer Shezaf <ofer@shezaf.com> wrote:
> With regard to presenting WAFEC in OWASP events, I think this is an
> important comment and my answer is that as a WAFEC project member you should
> be able to and I will make sure this is known. I need to say I don't think
> you are limited from presenting in OWASP meetings today - presentation is
> not limited to OWASP members.
Yes I am and this restriction was made up by the OWASP Board within
http://lists.owasp.org/pipermail/owasp-leaders/2012-February/006813.html
i.e. "disqualification from CFT/CFP for Global or Regional AppSec
events" (I'd assume this extends to Chapter events) and upheld when I
my presentation on BSIMM was accepted for
https://www.owasp.org/index.php/AppSecAsiaPac2012.
--
Regards,
Christian Heinrich
http://cmlh.id.au/contact
JG
Jeremiah Grossman
Tue, Nov 13, 2012 12:39 AM
On Nov 12, 2012, at 1:28 PM, Robert A. wrote:
· The name, when affiliation is used, would be "The WASC/OWASP Web
Application Firewall Evaluation Criteria".
This doesn't resolve the issue around the (false) vendor perception of
WASC, since "WASC" would still be quoted within the project title.
Hence, I would recommend that we remove "WASC" and give complete
project ownership to OWASP i.e. "The OWASP Web Application Firewall
Evaluation Criteria" otherwise this (false) perception would remain?
If there's a perception issue of WASC (which I haven't seen for a few
years now myself), I don't think the answer is for us to abandon our
sucessful projects entirely to OWASP. If I'm misunderstanding please let
me know.
Open to Ofer's thoughts.
Regards,
Some may have this perception of WASC, no matter how underserving it is. Despite this, WASC projects have a very high adoption rate in the industry by nature of the way the organization do things. This speaks to deliverable quality, and to me, this is what ultimately matters the most. This is what I wish for this project. When this many of the right kind of experts are brought together under a highly collaborative and peer reviewed environment, you can't help but get this outcome.
Of course as this is an all volunteer project, people are of course free choose to contribute their time whenever and wherever they choose. Having said that, this is a project that "WASC" has voted to create and something it's committed to keeping under it's label. While it's never been done before, there is nothing technically preventing a collaborative project with OWASP provided that's what the group chooses to do.
Regards,
Jeremiah-
On Nov 12, 2012, at 1:28 PM, Robert A. wrote:
>
>> On Mon, Nov 12, 2012 at 9:17 PM, Ofer Shezaf <ofer@shezaf.com> wrote:
>>> · The name, when affiliation is used, would be "The WASC/OWASP Web
>>> Application Firewall Evaluation Criteria".
>>
>> This doesn't resolve the issue around the (false) vendor perception of
>> WASC, since "WASC" would still be quoted within the project title.
>>
>> Hence, I would recommend that we remove "WASC" and give complete
>> project ownership to OWASP i.e. "The OWASP Web Application Firewall
>> Evaluation Criteria" otherwise this (false) perception would remain?
>
> If there's a perception issue of WASC (which I haven't seen for a few
> years now myself), I don't think the answer is for us to abandon our
> sucessful projects entirely to OWASP. If I'm misunderstanding please let
> me know.
>
> Open to Ofer's thoughts.
>
> Regards,
> - Robert Auger
Some may have this perception of WASC, no matter how underserving it is. Despite this, WASC projects have a very high adoption rate in the industry by nature of the way the organization do things. This speaks to deliverable quality, and to me, this is what ultimately matters the most. This is what I wish for this project. When this many of the right kind of experts are brought together under a highly collaborative and peer reviewed environment, you can't help but get this outcome.
Of course as this is an all volunteer project, people are of course free choose to contribute their time whenever and wherever they choose. Having said that, this is a project that "WASC" has voted to create and something it's committed to keeping under it's label. While it's never been done before, there is nothing technically preventing a collaborative project with OWASP provided that's what the group chooses to do.
Regards,
Jeremiah-
OS
Ofer Shezaf
Tue, Nov 13, 2012 6:19 AM
Bob and Jeremiah,
For better or worse I would not give Christian suggestion to keep only OWASP
in the name a lot of weight (sorry Christian). It is not a general opinion
but a single voice. As Christian has reservations about OWASP and hence a
joined project , I would take it is away to convey his (valid) opinion about
the initiative.
Whether or not WASC carries a vendor perception is worth discussing,
probably more generally than the context of this thread and in the officers
list. However I would add that I don't see it necessarily as an issue but
rather stating an opinion. People seem to prefer being able to classify
things in order to give them differentiating value and compartmentalizing
WASC in such a way makes it easier for people to relate. We may want to
divert that to "Security Gurus" categorization, but we certainly want a
distinction.
Specifically for WAFEC the vendor perspective is less a perspective and more
evident: on the WAFEC contributor list, more than half represent WAF
vendors. The same is true for people volunteering so far to write sections.
~ Ofer
-----Original Message-----
From: Jeremiah Grossman [mailto:jeremiah@whitehatsec.com]
Sent: Tuesday, November 13, 2012 2:40 AM
To: Robert A.
Cc: Christian Heinrich; Ofer Shezaf; wasc-wafec@lists.webappsec.org;
wasc-members@webappsec.org
Subject: Re: [WASC-WAFEC] Vote on making WAFEC a WASC/OWASP project
On Nov 12, 2012, at 1:28 PM, Robert A. wrote:
. The name, when affiliation is used, would be "The WASC/OWASP
Application Firewall Evaluation Criteria".
This doesn't resolve the issue around the (false) vendor perception
of WASC, since "WASC" would still be quoted within the project title.
Hence, I would recommend that we remove "WASC" and give complete
project ownership to OWASP i.e. "The OWASP Web Application Firewall
Evaluation Criteria" otherwise this (false) perception would remain?
If there's a perception issue of WASC (which I haven't seen for a few
years now myself), I don't think the answer is for us to abandon our
sucessful projects entirely to OWASP. If I'm misunderstanding please
let me know.
Open to Ofer's thoughts.
Regards,
Some may have this perception of WASC, no matter how underserving it is.
Despite this, WASC projects have a very high adoption rate in the industry
by nature of the way the organization do things. This speaks to deliverable
quality, and to me, this is what ultimately matters the most. This is what I
wish for this project. When this many of the right kind of experts are
brought together under a highly collaborative and peer reviewed environment,
you can't help but get this outcome.
Of course as this is an all volunteer project, people are of course free
choose to contribute their time whenever and wherever they choose. Having
said that, this is a project that "WASC" has voted to create and something
it's committed to keeping under it's label. While it's never been done
before, there is nothing technically preventing a collaborative project with
OWASP provided that's what the group chooses to do.
Regards,
Jeremiah-=
Bob and Jeremiah,
For better or worse I would not give Christian suggestion to keep only OWASP
in the name a lot of weight (sorry Christian). It is not a general opinion
but a single voice. As Christian has reservations about OWASP and hence a
joined project , I would take it is away to convey his (valid) opinion about
the initiative.
Whether or not WASC carries a vendor perception is worth discussing,
probably more generally than the context of this thread and in the officers
list. However I would add that I don't see it necessarily as an issue but
rather stating an opinion. People seem to prefer being able to classify
things in order to give them differentiating value and compartmentalizing
WASC in such a way makes it easier for people to relate. We may want to
divert that to "Security Gurus" categorization, but we certainly want a
distinction.
Specifically for WAFEC the vendor perspective is less a perspective and more
evident: on the WAFEC contributor list, more than half represent WAF
vendors. The same is true for people volunteering so far to write sections.
~ Ofer
-----Original Message-----
From: Jeremiah Grossman [mailto:jeremiah@whitehatsec.com]
Sent: Tuesday, November 13, 2012 2:40 AM
To: Robert A.
Cc: Christian Heinrich; Ofer Shezaf; wasc-wafec@lists.webappsec.org;
wasc-members@webappsec.org
Subject: Re: [WASC-WAFEC] Vote on making WAFEC a WASC/OWASP project
On Nov 12, 2012, at 1:28 PM, Robert A. wrote:
>
>> On Mon, Nov 12, 2012 at 9:17 PM, Ofer Shezaf <ofer@shezaf.com> wrote:
>>> . The name, when affiliation is used, would be "The WASC/OWASP
Web
>>> Application Firewall Evaluation Criteria".
>>
>> This doesn't resolve the issue around the (false) vendor perception
>> of WASC, since "WASC" would still be quoted within the project title.
>>
>> Hence, I would recommend that we remove "WASC" and give complete
>> project ownership to OWASP i.e. "The OWASP Web Application Firewall
>> Evaluation Criteria" otherwise this (false) perception would remain?
>
> If there's a perception issue of WASC (which I haven't seen for a few
> years now myself), I don't think the answer is for us to abandon our
> sucessful projects entirely to OWASP. If I'm misunderstanding please
> let me know.
>
> Open to Ofer's thoughts.
>
> Regards,
> - Robert Auger
Some may have this perception of WASC, no matter how underserving it is.
Despite this, WASC projects have a very high adoption rate in the industry
by nature of the way the organization do things. This speaks to deliverable
quality, and to me, this is what ultimately matters the most. This is what I
wish for this project. When this many of the right kind of experts are
brought together under a highly collaborative and peer reviewed environment,
you can't help but get this outcome.
Of course as this is an all volunteer project, people are of course free
choose to contribute their time whenever and wherever they choose. Having
said that, this is a project that "WASC" has voted to create and something
it's committed to keeping under it's label. While it's never been done
before, there is nothing technically preventing a collaborative project with
OWASP provided that's what the group chooses to do.
Regards,
Jeremiah-=
IB
Ido Breger
Tue, Nov 13, 2012 6:29 AM
Yes
Ido Breger
From: wasc-wafec [mailto:wasc-wafec-bounces@lists.webappsec.org] On Behalf Of Ofer Shezaf
Sent: Monday, November 12, 2012 12:18 PM
To: wasc-wafec@lists.webappsec.org
Subject: [WASC-WAFEC] Vote on making WAFEC a WASC/OWASP project
Hi All,
As promised I am opening the vote for making WAFEC a joined WASC and OWASP project.
The proposed guidelines for this more are (updated based on comments from the group and WASC officers):
-
The name, when affiliation is used, would be "The WASC/OWASP Web Application Firewall Evaluation Criteria".
-
Governance would be mutual, i.e. any decision about the project which is not within the project team itself has to be agreed upon by the OWASP GPC (i.e. Project Committee) and by the WASC officers. The project leader is the arbitrator in case of a conflict (this change is based on a request by Jeremiah Grossman, WASC founder).
-
Participation is open for all and does not require being an OWASP or a WASC member.
Vote Yes/No. Voting is open until Nov 19th EOD (American Samoa, that is UTC-11, time zone)
Now for my voting pitch:
I think the change is important and would benefit WAFEC tremendously. I would go a step further it is needed to ensure we actually succeed:
Why?
-
Making it happen - we need more people. I now have two chapter assigned and many are still waiting. Joining hands with OWASP will make joining the project appealing to many more people.
-
Outreach - people in the application security community have heard about OWASP, and joining hands with OWASP would enable leveraging this to reach more people. This includes chapters outreach (from Khartoum, The Sudan to Omaha, Nebraska) as well as an official room in local and global conferences.
-
Vendor image - WASC is perceived as a "vendors' organization" and the list of participants in WAFEC certainly proves that. Affiliation with OWASP will
help popularize WAFEC also with customers, which I think is very good for the project.
I must say I think it would be hard for me to complete the project successfully otherwise.
~ Ofer
Ofer Shezaf
[+972-54-4431119; ofer@shezaf.commailto:ofer@shezaf.com, www.shezaf.comhttp://www.shezaf.com]
Yes
Ido Breger
From: wasc-wafec [mailto:wasc-wafec-bounces@lists.webappsec.org] On Behalf Of Ofer Shezaf
Sent: Monday, November 12, 2012 12:18 PM
To: wasc-wafec@lists.webappsec.org
Subject: [WASC-WAFEC] Vote on making WAFEC a WASC/OWASP project
Hi All,
As promised I am opening the vote for making WAFEC a joined WASC and OWASP project.
The proposed guidelines for this more are (updated based on comments from the group and WASC officers):
* The name, when affiliation is used, would be "The WASC/OWASP Web Application Firewall Evaluation Criteria".
* Governance would be mutual, i.e. any decision about the project which is not within the project team itself has to be agreed upon by the OWASP GPC (i.e. Project Committee) and by the WASC officers. The project leader is the arbitrator in case of a conflict (this change is based on a request by Jeremiah Grossman, WASC founder).
* Participation is open for all and does not require being an OWASP or a WASC member.
Vote Yes/No. Voting is open until Nov 19th EOD (American Samoa, that is UTC-11, time zone)
Now for my voting pitch:
I think the change is important and would benefit WAFEC tremendously. I would go a step further it is needed to ensure we actually succeed:
Why?
* Making it happen - we need more people. I now have two chapter assigned and many are still waiting. Joining hands with OWASP will make joining the project appealing to many more people.
* Outreach - people in the application security community have heard about OWASP, and joining hands with OWASP would enable leveraging this to reach more people. This includes chapters outreach (from Khartoum, The Sudan to Omaha, Nebraska) as well as an official room in local and global conferences.
* Vendor image - WASC is perceived as a "vendors' organization" and the list of participants in WAFEC certainly proves that. Affiliation with OWASP will
help popularize WAFEC also with customers, which I think is very good for the project.
I must say I think it would be hard for me to complete the project successfully otherwise.
~ Ofer
Ofer Shezaf
[+972-54-4431119; ofer@shezaf.com<mailto:ofer@shezaf.com>, www.shezaf.com<http://www.shezaf.com>]
CH
Christian Heinrich
Tue, Nov 13, 2012 7:48 AM
For better or worse I would not give Christian suggestion to keep only OWASP
in the name a lot of weight (sorry Christian). It is not a general opinion
but a single voice. As Christian has reservations about OWASP and hence a
joined project , I would take it is away to convey his (valid) opinion about
the initiative.
In the context of the above (project name) item then no I don't have
reservations about OWASP based on the reasons stated in your proposal
hence my recommendation to remove WASC from the name of the (WAFEC)
project.
However, if WASC would like to a) remove the vendor perception and b)
promote it to the wider community then this could be (better) achieved
by with end users (not vendors) presenting WAFEC at OWASP Chapters and
Conferences.
--
Regards,
Christian Heinrich
http://cmlh.id.au/contact
Ofer,
On Tue, Nov 13, 2012 at 5:19 PM, Ofer Shezaf <ofer@shezaf.com> wrote:
> For better or worse I would not give Christian suggestion to keep only OWASP
> in the name a lot of weight (sorry Christian). It is not a general opinion
> but a single voice. As Christian has reservations about OWASP and hence a
> joined project , I would take it is away to convey his (valid) opinion about
> the initiative.
In the context of the above (project name) item then *no* I don't have
reservations about OWASP based on the reasons stated in your proposal
hence my recommendation to remove WASC from the name of the (WAFEC)
project.
However, if WASC would like to a) remove the vendor perception and b)
promote it to the wider community then this could be (better) achieved
by with end users (not vendors) presenting WAFEC at OWASP Chapters and
Conferences.
--
Regards,
Christian Heinrich
http://cmlh.id.au/contact
OS
Ofer Shezaf
Tue, Nov 13, 2012 8:10 AM
Presenting WAFEC by someone who does not represent a vendor makes a lot of
sense. I would like to point that there is no "WASC wants". WASC and WAFEC
are ours to make. WAFEC will be presented and promoted in conferences,
meetings, blogs etc if any of us as individuals select to do so. I will, you
can, and everyone else is also more than welcomed to.
~ Ofer
-----Original Message-----
From: Christian Heinrich [mailto:christian.heinrich@cmlh.id.au]
Sent: Tuesday, November 13, 2012 9:49 AM
To: Ofer Shezaf
Cc: Jeremiah Grossman; Robert A.; wasc-wafec@lists.webappsec.org;
wasc-members@webappsec.org
Subject: Re: [WASC-WAFEC] Vote on making WAFEC a WASC/OWASP project
Ofer,
On Tue, Nov 13, 2012 at 5:19 PM, Ofer Shezaf ofer@shezaf.com wrote:
For better or worse I would not give Christian suggestion to keep only
OWASP in the name a lot of weight (sorry Christian). It is not a
general opinion but a single voice. As Christian has reservations
about OWASP and hence a joined project , I would take it is away to
convey his (valid) opinion about the initiative.
In the context of the above (project name) item then no I don't have
reservations about OWASP based on the reasons stated in your proposal hence
my recommendation to remove WASC from the name of the (WAFEC) project.
However, if WASC would like to a) remove the vendor perception and b)
promote it to the wider community then this could be (better) achieved by
with end users (not vendors) presenting WAFEC at OWASP Chapters and
Conferences.
--
Regards,
Christian Heinrich
http://cmlh.id.au/contact
Presenting WAFEC by someone who does not represent a vendor makes a lot of
sense. I would like to point that there is no "WASC wants". WASC and WAFEC
are ours to make. WAFEC will be presented and promoted in conferences,
meetings, blogs etc if any of us as individuals select to do so. I will, you
can, and everyone else is also more than welcomed to.
~ Ofer
-----Original Message-----
From: Christian Heinrich [mailto:christian.heinrich@cmlh.id.au]
Sent: Tuesday, November 13, 2012 9:49 AM
To: Ofer Shezaf
Cc: Jeremiah Grossman; Robert A.; wasc-wafec@lists.webappsec.org;
wasc-members@webappsec.org
Subject: Re: [WASC-WAFEC] Vote on making WAFEC a WASC/OWASP project
Ofer,
On Tue, Nov 13, 2012 at 5:19 PM, Ofer Shezaf <ofer@shezaf.com> wrote:
> For better or worse I would not give Christian suggestion to keep only
> OWASP in the name a lot of weight (sorry Christian). It is not a
> general opinion but a single voice. As Christian has reservations
> about OWASP and hence a joined project , I would take it is away to
> convey his (valid) opinion about the initiative.
In the context of the above (project name) item then *no* I don't have
reservations about OWASP based on the reasons stated in your proposal hence
my recommendation to remove WASC from the name of the (WAFEC) project.
However, if WASC would like to a) remove the vendor perception and b)
promote it to the wider community then this could be (better) achieved by
with end users (not vendors) presenting WAFEC at OWASP Chapters and
Conferences.
--
Regards,
Christian Heinrich
http://cmlh.id.au/contact
AH
Achim Hoffmann
Tue, Nov 13, 2012 12:45 PM
Hi,
as we (OWASP Germany) are currently planing for AppSec EU2013, I can reserve
a slot for a talk/presentation and also for a one or half day training or workshop.
I guess another 6-8 month should be enough to bring the project to a valuable extent
and then present it.
Should we go for that?
I'd realy like to push it and show it a greater audience.
Achim
-------- Original-Nachricht --------
Betreff: Re: [WASC-WAFEC] Vote on making WAFEC a WASC/OWASP project
Datum: Tue, 13 Nov 2012 10:10:00 +0200
..
Kopie (CC): wasc-wafec@lists.webappsec.org, wasc-members@webappsec.org
Presenting WAFEC by someone who does not represent a vendor makes a lot of
sense. I would like to point that there is no "WASC wants". WASC and WAFEC
are ours to make. WAFEC will be presented and promoted in conferences,
meetings, blogs etc if any of us as individuals select to do so. I will, you
can, and everyone else is also more than welcomed to.
Hi,
as we (OWASP Germany) are currently planing for AppSec EU2013, I can reserve
a slot for a talk/presentation and also for a one or half day training or workshop.
I guess another 6-8 month should be enough to bring the project to a valuable extent
and then present it.
Should we go for that?
I'd realy like to push it and show it a greater audience.
Achim
-------- Original-Nachricht --------
Betreff: Re: [WASC-WAFEC] Vote on making WAFEC a WASC/OWASP project
Datum: Tue, 13 Nov 2012 10:10:00 +0200
..
Kopie (CC): wasc-wafec@lists.webappsec.org, wasc-members@webappsec.org
Presenting WAFEC by someone who does not represent a vendor makes a lot of
sense. I would like to point that there is no "WASC wants". WASC and WAFEC
are ours to make. WAFEC will be presented and promoted in conferences,
meetings, blogs etc if any of us as individuals select to do so. I will, you
can, and everyone else is also more than welcomed to.
JG
Jeremiah Grossman
Tue, Nov 13, 2012 2:28 PM
I agree. This issue, if indeed it even is an issue, is part of a larger discussion about WASC and beyond WAFEC. I'm happy to share my opinion on the matter here.
WASC started as a group of people that had a vested interested in solving a particular problem in the industry, at the time, a nomenclature issue. Consumers were confused by the differing jargon between "us vendors." Again, at the time. So we got together to solve that problem problem in the shape of the Threat Classification. During the process of v1 and v2 of the project, of course no one… including non-vendors, were excluded from participating. What was most important was that the best experts in the world participated, who yes also happened to work for vendors, collectively created something really good that could be quickly adopted. And, it worked.
WAFEC is essentially identical in this regard. That to me, is what WASC does. Each project operates extremely independently, with only the bare minimum of necessary oversight from the Officers.
So, while their may or may not be a vendor stigma associated to WASC, it hasn't prevent us from bringing together enough of the right kind people with a vested interest in solving a problem. As is demonstrated here inside WAFEC. It hasn't prevented the creation and adoption of its projects. Perhaps the issue has prevented us from being successful in other ways, but not in the ways we valued most as an organization. WASC fills a very particular niche.
Simply the opinion of 1 WASC officer...
On Nov 12, 2012, at 10:19 PM, Ofer Shezaf wrote:
Bob and Jeremiah,
For better or worse I would not give Christian suggestion to keep only OWASP
in the name a lot of weight (sorry Christian). It is not a general opinion
but a single voice. As Christian has reservations about OWASP and hence a
joined project , I would take it is away to convey his (valid) opinion about
the initiative.
Whether or not WASC carries a vendor perception is worth discussing,
probably more generally than the context of this thread and in the officers
list. However I would add that I don't see it necessarily as an issue but
rather stating an opinion. People seem to prefer being able to classify
things in order to give them differentiating value and compartmentalizing
WASC in such a way makes it easier for people to relate. We may want to
divert that to "Security Gurus" categorization, but we certainly want a
distinction.
Specifically for WAFEC the vendor perspective is less a perspective and more
evident: on the WAFEC contributor list, more than half represent WAF
vendors. The same is true for people volunteering so far to write sections.
~ Ofer
-----Original Message-----
From: Jeremiah Grossman [mailto:jeremiah@whitehatsec.com]
Sent: Tuesday, November 13, 2012 2:40 AM
To: Robert A.
Cc: Christian Heinrich; Ofer Shezaf; wasc-wafec@lists.webappsec.org;
wasc-members@webappsec.org
Subject: Re: [WASC-WAFEC] Vote on making WAFEC a WASC/OWASP project
On Nov 12, 2012, at 1:28 PM, Robert A. wrote:
. The name, when affiliation is used, would be "The WASC/OWASP
Application Firewall Evaluation Criteria".
This doesn't resolve the issue around the (false) vendor perception
of WASC, since "WASC" would still be quoted within the project title.
Hence, I would recommend that we remove "WASC" and give complete
project ownership to OWASP i.e. "The OWASP Web Application Firewall
Evaluation Criteria" otherwise this (false) perception would remain?
If there's a perception issue of WASC (which I haven't seen for a few
years now myself), I don't think the answer is for us to abandon our
sucessful projects entirely to OWASP. If I'm misunderstanding please
let me know.
Open to Ofer's thoughts.
Regards,
Some may have this perception of WASC, no matter how underserving it is.
Despite this, WASC projects have a very high adoption rate in the industry
by nature of the way the organization do things. This speaks to deliverable
quality, and to me, this is what ultimately matters the most. This is what I
wish for this project. When this many of the right kind of experts are
brought together under a highly collaborative and peer reviewed environment,
you can't help but get this outcome.
Of course as this is an all volunteer project, people are of course free
choose to contribute their time whenever and wherever they choose. Having
said that, this is a project that "WASC" has voted to create and something
it's committed to keeping under it's label. While it's never been done
before, there is nothing technically preventing a collaborative project with
OWASP provided that's what the group chooses to do.
Regards,
Jeremiah-=
I agree. This issue, if indeed it even is an issue, is part of a larger discussion about WASC and beyond WAFEC. I'm happy to share my opinion on the matter here.
WASC started as a group of people that had a vested interested in solving a particular problem in the industry, at the time, a nomenclature issue. Consumers were confused by the differing jargon between "us vendors." Again, at the time. So we got together to solve that problem problem in the shape of the Threat Classification. During the process of v1 and v2 of the project, of course no one… including non-vendors, were excluded from participating. What was most important was that the best experts in the world participated, who yes also happened to work for vendors, collectively created something really good that could be quickly adopted. And, it worked.
WAFEC is essentially identical in this regard. That to me, is what WASC does. Each project operates extremely independently, with only the bare minimum of necessary oversight from the Officers.
So, while their may or may not be a vendor stigma associated to WASC, it hasn't prevent us from bringing together enough of the right kind people with a vested interest in solving a problem. As is demonstrated here inside WAFEC. It hasn't prevented the creation and adoption of its projects. Perhaps the issue has prevented us from being successful in other ways, but not in the ways we valued most as an organization. WASC fills a very particular niche.
Simply the opinion of 1 WASC officer...
On Nov 12, 2012, at 10:19 PM, Ofer Shezaf wrote:
>
> Bob and Jeremiah,
>
> For better or worse I would not give Christian suggestion to keep only OWASP
> in the name a lot of weight (sorry Christian). It is not a general opinion
> but a single voice. As Christian has reservations about OWASP and hence a
> joined project , I would take it is away to convey his (valid) opinion about
> the initiative.
>
> Whether or not WASC carries a vendor perception is worth discussing,
> probably more generally than the context of this thread and in the officers
> list. However I would add that I don't see it necessarily as an issue but
> rather stating an opinion. People seem to prefer being able to classify
> things in order to give them differentiating value and compartmentalizing
> WASC in such a way makes it easier for people to relate. We may want to
> divert that to "Security Gurus" categorization, but we certainly want a
> distinction.
>
> Specifically for WAFEC the vendor perspective is less a perspective and more
> evident: on the WAFEC contributor list, more than half represent WAF
> vendors. The same is true for people volunteering so far to write sections.
>
> ~ Ofer
>
> -----Original Message-----
> From: Jeremiah Grossman [mailto:jeremiah@whitehatsec.com]
> Sent: Tuesday, November 13, 2012 2:40 AM
> To: Robert A.
> Cc: Christian Heinrich; Ofer Shezaf; wasc-wafec@lists.webappsec.org;
> wasc-members@webappsec.org
> Subject: Re: [WASC-WAFEC] Vote on making WAFEC a WASC/OWASP project
>
>
> On Nov 12, 2012, at 1:28 PM, Robert A. wrote:
>
>>
>>> On Mon, Nov 12, 2012 at 9:17 PM, Ofer Shezaf <ofer@shezaf.com> wrote:
>>>> . The name, when affiliation is used, would be "The WASC/OWASP
> Web
>>>> Application Firewall Evaluation Criteria".
>>>
>>> This doesn't resolve the issue around the (false) vendor perception
>>> of WASC, since "WASC" would still be quoted within the project title.
>>>
>>> Hence, I would recommend that we remove "WASC" and give complete
>>> project ownership to OWASP i.e. "The OWASP Web Application Firewall
>>> Evaluation Criteria" otherwise this (false) perception would remain?
>>
>> If there's a perception issue of WASC (which I haven't seen for a few
>> years now myself), I don't think the answer is for us to abandon our
>> sucessful projects entirely to OWASP. If I'm misunderstanding please
>> let me know.
>>
>> Open to Ofer's thoughts.
>>
>> Regards,
>> - Robert Auger
>
> Some may have this perception of WASC, no matter how underserving it is.
> Despite this, WASC projects have a very high adoption rate in the industry
> by nature of the way the organization do things. This speaks to deliverable
> quality, and to me, this is what ultimately matters the most. This is what I
> wish for this project. When this many of the right kind of experts are
> brought together under a highly collaborative and peer reviewed environment,
> you can't help but get this outcome.
>
> Of course as this is an all volunteer project, people are of course free
> choose to contribute their time whenever and wherever they choose. Having
> said that, this is a project that "WASC" has voted to create and something
> it's committed to keeping under it's label. While it's never been done
> before, there is nothing technically preventing a collaborative project with
> OWASP provided that's what the group chooses to do.
>
> Regards,
>
> Jeremiah-=
>
AH
Achim Hoffmann
Tue, Nov 13, 2012 3:20 PM
I fully agree with Jeremiah (as I remember the work on TCv1:)
For WAFEC we need the vendors as they can provide the most detailled information
on some technical things which needs to be described correctly.
So far the concerns about "vendor biased comments" have been discussed on this list
and there is (at least seems to be) an agreement that very vendor-specific items
and not directly WAF-related items are put together in an Appendix (see mails from
Ofer and Christian).
Just my 2 pence ...
Achim
Am 13.11.2012 15:28, schrieb Jeremiah Grossman:
I agree. This issue, if indeed it even is an issue, is part of a larger discussion about WASC and beyond WAFEC. I'm happy to share my opinion on the matter here.
WASC started as a group of people that had a vested interested in solving a particular problem in the industry, at the time, a nomenclature issue. Consumers were confused by the differing jargon between "us vendors." Again, at the time. So we got together to solve that problem problem in the shape of the Threat Classification. During the process of v1 and v2 of the project, of course no one… including non-vendors, were excluded from participating. What was most important was that the best experts in the world participated, who yes also happened to work for vendors, collectively created something really good that could be quickly adopted. And, it worked.
WAFEC is essentially identical in this regard. That to me, is what WASC does. Each project operates extremely independently, with only the bare minimum of necessary oversight from the Officers.
So, while their may or may not be a vendor stigma associated to WASC, it hasn't prevent us from bringing together enough of the right kind people with a vested interest in solving a problem. As is demonstrated here inside WAFEC. It hasn't prevented the creation and adoption of its projects. Perhaps the issue has prevented us from being successful in other ways, but not in the ways we valued most as an organization. WASC fills a very particular niche.
Simply the opinion of 1 WASC officer...
On Nov 12, 2012, at 10:19 PM, Ofer Shezaf wrote:
Bob and Jeremiah,
For better or worse I would not give Christian suggestion to keep only OWASP
in the name a lot of weight (sorry Christian). It is not a general opinion
but a single voice. As Christian has reservations about OWASP and hence a
joined project , I would take it is away to convey his (valid) opinion about
the initiative.
Whether or not WASC carries a vendor perception is worth discussing,
probably more generally than the context of this thread and in the officers
list. However I would add that I don't see it necessarily as an issue but
rather stating an opinion. People seem to prefer being able to classify
things in order to give them differentiating value and compartmentalizing
WASC in such a way makes it easier for people to relate. We may want to
divert that to "Security Gurus" categorization, but we certainly want a
distinction.
Specifically for WAFEC the vendor perspective is less a perspective and more
evident: on the WAFEC contributor list, more than half represent WAF
vendors. The same is true for people volunteering so far to write sections.
~ Ofer
-----Original Message-----
From: Jeremiah Grossman [mailto:jeremiah@whitehatsec.com]
Sent: Tuesday, November 13, 2012 2:40 AM
To: Robert A.
Cc: Christian Heinrich; Ofer Shezaf; wasc-wafec@lists.webappsec.org;
wasc-members@webappsec.org
Subject: Re: [WASC-WAFEC] Vote on making WAFEC a WASC/OWASP project
On Nov 12, 2012, at 1:28 PM, Robert A. wrote:
. The name, when affiliation is used, would be "The WASC/OWASP
Application Firewall Evaluation Criteria".
This doesn't resolve the issue around the (false) vendor perception
of WASC, since "WASC" would still be quoted within the project title.
Hence, I would recommend that we remove "WASC" and give complete
project ownership to OWASP i.e. "The OWASP Web Application Firewall
Evaluation Criteria" otherwise this (false) perception would remain?
If there's a perception issue of WASC (which I haven't seen for a few
years now myself), I don't think the answer is for us to abandon our
sucessful projects entirely to OWASP. If I'm misunderstanding please
let me know.
Open to Ofer's thoughts.
Regards,
Some may have this perception of WASC, no matter how underserving it is.
Despite this, WASC projects have a very high adoption rate in the industry
by nature of the way the organization do things. This speaks to deliverable
quality, and to me, this is what ultimately matters the most. This is what I
wish for this project. When this many of the right kind of experts are
brought together under a highly collaborative and peer reviewed environment,
you can't help but get this outcome.
Of course as this is an all volunteer project, people are of course free
choose to contribute their time whenever and wherever they choose. Having
said that, this is a project that "WASC" has voted to create and something
it's committed to keeping under it's label. While it's never been done
before, there is nothing technically preventing a collaborative project with
OWASP provided that's what the group chooses to do.
Regards,
Jeremiah-=
I fully agree with Jeremiah (as I remember the work on TCv1:)
For WAFEC we need the vendors as they can provide the most detailled information
on some technical things which needs to be described correctly.
So far the concerns about "vendor biased comments" have been discussed on this list
and there is (at least seems to be) an agreement that very vendor-specific items
and not directly WAF-related items are put together in an Appendix (see mails from
Ofer and Christian).
Just my 2 pence ...
Achim
Am 13.11.2012 15:28, schrieb Jeremiah Grossman:
> I agree. This issue, if indeed it even is an issue, is part of a larger discussion about WASC and beyond WAFEC. I'm happy to share my opinion on the matter here.
>
> WASC started as a group of people that had a vested interested in solving a particular problem in the industry, at the time, a nomenclature issue. Consumers were confused by the differing jargon between "us vendors." Again, at the time. So we got together to solve that problem problem in the shape of the Threat Classification. During the process of v1 and v2 of the project, of course no one… including non-vendors, were excluded from participating. What was most important was that the best experts in the world participated, who yes also happened to work for vendors, collectively created something really good that could be quickly adopted. And, it worked.
>
> WAFEC is essentially identical in this regard. That to me, is what WASC does. Each project operates extremely independently, with only the bare minimum of necessary oversight from the Officers.
>
> So, while their may or may not be a vendor stigma associated to WASC, it hasn't prevent us from bringing together enough of the right kind people with a vested interest in solving a problem. As is demonstrated here inside WAFEC. It hasn't prevented the creation and adoption of its projects. Perhaps the issue has prevented us from being successful in other ways, but not in the ways we valued most as an organization. WASC fills a very particular niche.
>
> Simply the opinion of 1 WASC officer...
>
>
> On Nov 12, 2012, at 10:19 PM, Ofer Shezaf wrote:
>
>>
>> Bob and Jeremiah,
>>
>> For better or worse I would not give Christian suggestion to keep only OWASP
>> in the name a lot of weight (sorry Christian). It is not a general opinion
>> but a single voice. As Christian has reservations about OWASP and hence a
>> joined project , I would take it is away to convey his (valid) opinion about
>> the initiative.
>>
>> Whether or not WASC carries a vendor perception is worth discussing,
>> probably more generally than the context of this thread and in the officers
>> list. However I would add that I don't see it necessarily as an issue but
>> rather stating an opinion. People seem to prefer being able to classify
>> things in order to give them differentiating value and compartmentalizing
>> WASC in such a way makes it easier for people to relate. We may want to
>> divert that to "Security Gurus" categorization, but we certainly want a
>> distinction.
>>
>> Specifically for WAFEC the vendor perspective is less a perspective and more
>> evident: on the WAFEC contributor list, more than half represent WAF
>> vendors. The same is true for people volunteering so far to write sections.
>>
>> ~ Ofer
>>
>> -----Original Message-----
>> From: Jeremiah Grossman [mailto:jeremiah@whitehatsec.com]
>> Sent: Tuesday, November 13, 2012 2:40 AM
>> To: Robert A.
>> Cc: Christian Heinrich; Ofer Shezaf; wasc-wafec@lists.webappsec.org;
>> wasc-members@webappsec.org
>> Subject: Re: [WASC-WAFEC] Vote on making WAFEC a WASC/OWASP project
>>
>>
>> On Nov 12, 2012, at 1:28 PM, Robert A. wrote:
>>
>>>
>>>> On Mon, Nov 12, 2012 at 9:17 PM, Ofer Shezaf <ofer@shezaf.com> wrote:
>>>>> . The name, when affiliation is used, would be "The WASC/OWASP
>> Web
>>>>> Application Firewall Evaluation Criteria".
>>>>
>>>> This doesn't resolve the issue around the (false) vendor perception
>>>> of WASC, since "WASC" would still be quoted within the project title.
>>>>
>>>> Hence, I would recommend that we remove "WASC" and give complete
>>>> project ownership to OWASP i.e. "The OWASP Web Application Firewall
>>>> Evaluation Criteria" otherwise this (false) perception would remain?
>>>
>>> If there's a perception issue of WASC (which I haven't seen for a few
>>> years now myself), I don't think the answer is for us to abandon our
>>> sucessful projects entirely to OWASP. If I'm misunderstanding please
>>> let me know.
>>>
>>> Open to Ofer's thoughts.
>>>
>>> Regards,
>>> - Robert Auger
>>
>> Some may have this perception of WASC, no matter how underserving it is.
>> Despite this, WASC projects have a very high adoption rate in the industry
>> by nature of the way the organization do things. This speaks to deliverable
>> quality, and to me, this is what ultimately matters the most. This is what I
>> wish for this project. When this many of the right kind of experts are
>> brought together under a highly collaborative and peer reviewed environment,
>> you can't help but get this outcome.
>>
>> Of course as this is an all volunteer project, people are of course free
>> choose to contribute their time whenever and wherever they choose. Having
>> said that, this is a project that "WASC" has voted to create and something
>> it's committed to keeping under it's label. While it's never been done
>> before, there is nothing technically preventing a collaborative project with
>> OWASP provided that's what the group chooses to do.
>>
>> Regards,
>>
>> Jeremiah-=
DW
Dirk Wetter
Tue, Nov 13, 2012 5:20 PM
again here's my yes (whatever the child's name is gonna be)
Dirk
Am 11/12/2012 11:17 AM, schrieb Ofer Shezaf:
Hi All,
As promised I am opening the vote for making WAFEC a joined WASC and
OWASP project.
The proposed guidelines for this more are (updated based on comments
from the group and WASC officers):
· The name, when affiliation is used, would be "The WASC/OWASP
Web Application Firewall Evaluation Criteria".
· Governance would be mutual, i.e. any decision about the
project which is not within the project team itself has to be agreed
upon by the OWASP GPC (i.e. Project Committee) and by the WASC officers.
The project leader is the arbitrator in case of a conflict (this change
is based on a request by Jeremiah Grossman, WASC founder).
· Participation is open for all and does not require being an
OWASP or a WASC member.
Vote Yes/No. Voting is open until Nov 19^th EOD (American Samoa, that is
UTC-11, time zone)
Now for my voting pitch:
I think the change is important and would benefit WAFEC tremendously. I
would go a step further it is needed to ensure we actually succeed:
Why?
· Making it happen – we need more people. I now have two chapter
assigned and many are still waiting. Joining hands with OWASP will make
joining the project appealing to many more people.
· Outreach – people in the application security community have
heard about OWASP, and joining hands with OWASP would enable leveraging
this to reach more people. This includes chapters outreach (from
Khartoum, The Sudan to Omaha, Nebraska) as well as an official room in
local and global conferences.
· Vendor image - WASC is perceived as a "vendors' organization"
and the list of participants in WAFEC certainly proves that. Affiliation
with OWASP will
help popularize WAFEC also with customers, which I think is very good
for the project.
I must say I think it would be hard for me to complete the project
successfully otherwise.
~ Ofer
Ofer Shezaf
[+972-54-4431119; ofer@shezaf.com mailto:ofer@shezaf.com, www.shezaf.com]
wasc-wafec mailing list
wasc-wafec@lists.webappsec.org
http://lists.webappsec.org/mailman/listinfo/wasc-wafec_lists.webappsec.org
again here's my yes (whatever the child's name is gonna be)
Dirk
Am 11/12/2012 11:17 AM, schrieb Ofer Shezaf:
>
>
> Hi All,
>
>
>
> As promised I am opening the vote for making WAFEC a joined WASC and
> OWASP project.
>
>
>
> The proposed guidelines for this more are (updated based on comments
> from the group and WASC officers):
>
> · The name, when affiliation is used, would be "The WASC/OWASP
> Web Application Firewall Evaluation Criteria".
>
> · Governance would be mutual, i.e. any decision about the
> project which is not within the project team itself has to be agreed
> upon by the OWASP GPC (i.e. Project Committee) and by the WASC officers.
> The project leader is the arbitrator in case of a conflict (this change
> is based on a request by Jeremiah Grossman, WASC founder).
>
> · Participation is open for all and does not require being an
> OWASP or a WASC member.
>
>
>
> Vote Yes/No. Voting is open until Nov 19^th EOD (American Samoa, that is
> UTC-11, time zone)
>
>
>
> Now for my voting pitch:
>
>
>
> I think the change is important and would benefit WAFEC tremendously. I
> would go a step further it is needed to ensure we actually succeed:
>
>
>
> Why?
>
> · Making it happen – we need more people. I now have two chapter
> assigned and many are still waiting. Joining hands with OWASP will make
> joining the project appealing to many more people.
>
>
>
> · Outreach – people in the application security community have
> heard about OWASP, and joining hands with OWASP would enable leveraging
> this to reach more people. This includes chapters outreach (from
> Khartoum, The Sudan to Omaha, Nebraska) as well as an official room in
> local and global conferences.
>
>
>
> · Vendor image - WASC is perceived as a "vendors' organization"
> and the list of participants in WAFEC certainly proves that. Affiliation
> with OWASP will
>
> help popularize WAFEC also with customers, which I think is very good
> for the project.
>
>
>
> I must say I think it would be hard for me to complete the project
> successfully otherwise.
>
>
>
> ~ Ofer
>
>
>
> Ofer Shezaf
>
> [+972-54-4431119; ofer@shezaf.com <mailto:ofer@shezaf.com>, www.shezaf.com]
>
>
>
>
>
> _______________________________________________
> wasc-wafec mailing list
> wasc-wafec@lists.webappsec.org
> http://lists.webappsec.org/mailman/listinfo/wasc-wafec_lists.webappsec.org
>
WT
Wujek, Thorsten [STEIN-IT GmbH]
Tue, Nov 13, 2012 8:27 PM
A yes is reasonable wether there are pros and cons.
Thorsten Wujek
Von meinem iPad gesendet
Kleines Gerät, kleine Mails.
Tiny device, tiny mails.
Am 13.11.2012 um 18:20 schrieb "Dirk Wetter" spam@drwetter.org:
again here's my yes (whatever the child's name is gonna be)
Dirk
Am 11/12/2012 11:17 AM, schrieb Ofer Shezaf:
Hi All,
As promised I am opening the vote for making WAFEC a joined WASC
OWASP project.
The proposed guidelines for this more are (updated based on comments
from the group and WASC officers):
· The name, when affiliation is used, would be "The WASC/OWASP
Web Application Firewall Evaluation Criteria".
· Governance would be mutual, i.e. any decision about the
project which is not within the project team itself has to be agreed
upon by the OWASP GPC (i.e. Project Committee) and by the WASC officers.
The project leader is the arbitrator in case of a conflict (this change
is based on a request by Jeremiah Grossman, WASC founder).
· Participation is open for all and does not require being an
OWASP or a WASC member.
Vote Yes/No. Voting is open until Nov 19^th EOD (American Samoa, that is
UTC-11, time zone)
Now for my voting pitch:
I think the change is important and would benefit WAFEC tremendously. I
would go a step further it is needed to ensure we actually succeed:
Why?
· Making it happen – we need more people. I now have two chapter
assigned and many are still waiting. Joining hands with OWASP will make
joining the project appealing to many more people.
· Outreach – people in the application security community have
heard about OWASP, and joining hands with OWASP would enable leveraging
this to reach more people. This includes chapters outreach (from
Khartoum, The Sudan to Omaha, Nebraska) as well as an official room in
local and global conferences.
· Vendor image - WASC is perceived as a "vendors' organization"
and the list of participants in WAFEC certainly proves that. Affiliation
with OWASP will
help popularize WAFEC also with customers, which I think is very good
for the project.
I must say I think it would be hard for me to complete the project
successfully otherwise.
~ Ofer
Ofer Shezaf
[+972-54-4431119; ofer@shezaf.com mailto:ofer@shezaf.com, www.shezaf.com]
wasc-wafec mailing list
wasc-wafec@lists.webappsec.org
http://lists.webappsec.org/mailman/listinfo/wasc-wafec_lists.webappsec.org
A yes is reasonable wether there are pros and cons.
Thorsten Wujek
Von meinem iPad gesendet
Kleines Gerät, kleine Mails.
Tiny device, tiny mails.
Am 13.11.2012 um 18:20 schrieb "Dirk Wetter" <spam@drwetter.org>:
>
> again here's my yes (whatever the child's name is gonna be)
>
> Dirk
>
>
> Am 11/12/2012 11:17 AM, schrieb Ofer Shezaf:
>>
>>
>> Hi All,
>>
>>
>>
>> As promised I am opening the vote for making WAFEC a joined WASC
>> OWASP project.
>>
>>
>> The proposed guidelines for this more are (updated based on comments
>> from the group and WASC officers):
>>
>> · The name, when affiliation is used, would be "The WASC/OWASP
>> Web Application Firewall Evaluation Criteria".
>>
>> · Governance would be mutual, i.e. any decision about the
>> project which is not within the project team itself has to be agreed
>> upon by the OWASP GPC (i.e. Project Committee) and by the WASC officers.
>> The project leader is the arbitrator in case of a conflict (this change
>> is based on a request by Jeremiah Grossman, WASC founder).
>>
>> · Participation is open for all and does not require being an
>> OWASP or a WASC member.
>>
>>
>>
>> Vote Yes/No. Voting is open until Nov 19^th EOD (American Samoa, that is
>> UTC-11, time zone)
>>
>>
>>
>> Now for my voting pitch:
>>
>>
>>
>> I think the change is important and would benefit WAFEC tremendously. I
>> would go a step further it is needed to ensure we actually succeed:
>>
>>
>>
>> Why?
>>
>> · Making it happen – we need more people. I now have two chapter
>> assigned and many are still waiting. Joining hands with OWASP will make
>> joining the project appealing to many more people.
>>
>>
>>
>> · Outreach – people in the application security community have
>> heard about OWASP, and joining hands with OWASP would enable leveraging
>> this to reach more people. This includes chapters outreach (from
>> Khartoum, The Sudan to Omaha, Nebraska) as well as an official room in
>> local and global conferences.
>>
>>
>>
>> · Vendor image - WASC is perceived as a "vendors' organization"
>> and the list of participants in WAFEC certainly proves that. Affiliation
>> with OWASP will
>>
>> help popularize WAFEC also with customers, which I think is very good
>> for the project.
>>
>>
>>
>> I must say I think it would be hard for me to complete the project
>> successfully otherwise.
>>
>>
>>
>> ~ Ofer
>>
>>
>>
>> Ofer Shezaf
>>
>> [+972-54-4431119; ofer@shezaf.com <mailto:ofer@shezaf.com>, www.shezaf.com]
>>
>>
>>
>>
>>
>> _______________________________________________
>> wasc-wafec mailing list
>> wasc-wafec@lists.webappsec.org
>> http://lists.webappsec.org/mailman/listinfo/wasc-wafec_lists.webappsec.org
>>
>
>
> _______________________________________________
> wasc-wafec mailing list
> wasc-wafec@lists.webappsec.org
> http://lists.webappsec.org/mailman/listinfo/wasc-wafec_lists.webappsec.org
CH
Christian Heinrich
Tue, Nov 13, 2012 8:55 PM
Hi,
as we (OWASP Germany) are currently planing for AppSec EU2013, I can reserve
a slot for a talk/presentation and also for a one or half day training or workshop.
I guess another 6-8 month should be enough to bring the project to a valuable extent
and then present it.
Should we go for that?
I'd realy like to push it and show it a greater audience.
Achim,
I would support speaking at this event provided we are not scheduled
during the break between the break and the evening social event again
i.e. http://www.appsecresearch.org/wafec-workshop-at-owasp-appsec-research-in-athens/
which your e-mail suggests would not be the case.
Based on https://lists.owasp.org/pipermail/global_conference_committee/2011-March/001122.html
I would expect that flights and accommodation for each presenter would
be paid for by OWASP and that the profit for delivering training would
be paid to WASC?
On Tue, Nov 13, 2012 at 11:45 PM, Achim Hoffmann <websec10@sic-sec.org> wrote:
> Hi,
>
> as we (OWASP Germany) are currently planing for AppSec EU2013, I can reserve
> a slot for a talk/presentation and also for a one or half day training or workshop.
>
> I guess another 6-8 month should be enough to bring the project to a valuable extent
> and then present it.
>
> Should we go for that?
> I'd realy like to push it and show it a greater audience.
--
Regards,
Christian Heinrich
http://cmlh.id.au/contact
OS
Ofer Shezaf
Tue, Nov 13, 2012 10:09 PM
I think that a presentation is a no brainer. As to workshop, since I really hope we would have a result to show, workshop for discussion would not be very useful. A training workshop would require an agenda and a commitment of a trainer to prepare a quality course that people will pay for. I personally am not sure what would be the content of such a training session. If anyone has a clear ideas as to what that be, we can either launch that as a WAFEC initiative or leave it to anyone who think it is a good business to do.
~ Ofer
-----Original Message-----
From: Achim Hoffmann [mailto:websec10@sic-sec.org]
Sent: Tuesday, November 13, 2012 2:45 PM
To: wasc-wafec@lists.webappsec.org
Cc: 'Christian Heinrich'; Ofer Shezaf
Subject: WASC/OWASP Web,Application Firewall Evaluation Criteria at AppSec EU2013
Hi,
as we (OWASP Germany) are currently planing for AppSec EU2013, I can reserve a slot for a talk/presentation and also for a one or half day training or workshop.
I guess another 6-8 month should be enough to bring the project to a valuable extent and then present it.
Should we go for that?
I'd realy like to push it and show it a greater audience.
Achim
-------- Original-Nachricht --------
Betreff: Re: [WASC-WAFEC] Vote on making WAFEC a WASC/OWASP project
Datum: Tue, 13 Nov 2012 10:10:00 +0200
..
Kopie (CC): wasc-wafec@lists.webappsec.org, wasc-members@webappsec.org
Presenting WAFEC by someone who does not represent a vendor makes a lot of sense. I would like to point that there is no "WASC wants". WASC and WAFEC are ours to make. WAFEC will be presented and promoted in conferences, meetings, blogs etc if any of us as individuals select to do so. I will, you can, and everyone else is also more than welcomed to.
I think that a presentation is a no brainer. As to workshop, since I really hope we would have a result to show, workshop for discussion would not be very useful. A training workshop would require an agenda and a commitment of a trainer to prepare a quality course that people will pay for. I personally am not sure what would be the content of such a training session. If anyone has a clear ideas as to what that be, we can either launch that as a WAFEC initiative or leave it to anyone who think it is a good business to do.
~ Ofer
-----Original Message-----
From: Achim Hoffmann [mailto:websec10@sic-sec.org]
Sent: Tuesday, November 13, 2012 2:45 PM
To: wasc-wafec@lists.webappsec.org
Cc: 'Christian Heinrich'; Ofer Shezaf
Subject: WASC/OWASP Web,Application Firewall Evaluation Criteria at AppSec EU2013
Hi,
as we (OWASP Germany) are currently planing for AppSec EU2013, I can reserve a slot for a talk/presentation and also for a one or half day training or workshop.
I guess another 6-8 month should be enough to bring the project to a valuable extent and then present it.
Should we go for that?
I'd realy like to push it and show it a greater audience.
Achim
-------- Original-Nachricht --------
Betreff: Re: [WASC-WAFEC] Vote on making WAFEC a WASC/OWASP project
Datum: Tue, 13 Nov 2012 10:10:00 +0200
..
Kopie (CC): wasc-wafec@lists.webappsec.org, wasc-members@webappsec.org
Presenting WAFEC by someone who does not represent a vendor makes a lot of sense. I would like to point that there is no "WASC wants". WASC and WAFEC are ours to make. WAFEC will be presented and promoted in conferences, meetings, blogs etc if any of us as individuals select to do so. I will, you can, and everyone else is also more than welcomed to.
CH
Christian Heinrich
Tue, Nov 13, 2012 10:20 PM
I think that a presentation is a no brainer. As to workshop, since I really hope we would have a result to show, workshop for discussion would not be very useful. A training workshop would require an agenda and a commitment of a trainer to prepare a quality course that people will pay for. I personally am not sure what would be the content of such a training session. If anyone has a clear ideas as to what that be, we can either launch that as a WAFEC initiative or leave it to anyone who think it is a good business to do.
Ofer,
I believe the intended audience of a workshop would be:
1. WAF Vendor(s) preparing documentation to support WAFEC.
2a. https://www.nsslabs.com/, https://www.icsalabs.com/, etc
preforming independent verification of WAFEC against WAF Vendor claim
on behalf of an end user.
2b. http://www.dsd.gov.au/infosec/aisep/providers.htm with the
specific end user being Government.
3. End User evaluating WAF solutions based on a combination of the above.
On Wed, Nov 14, 2012 at 9:09 AM, Ofer Shezaf <ofer@shezaf.com> wrote:
> I think that a presentation is a no brainer. As to workshop, since I really hope we would have a result to show, workshop for discussion would not be very useful. A training workshop would require an agenda and a commitment of a trainer to prepare a quality course that people will pay for. I personally am not sure what would be the content of such a training session. If anyone has a clear ideas as to what that be, we can either launch that as a WAFEC initiative or leave it to anyone who think it is a good business to do.
--
Regards,
Christian Heinrich
http://cmlh.id.au/contact
RA
Robert A.
Tue, Nov 13, 2012 10:26 PM
Quick question.
Should a workshop or training session be part of a wafec discussion? I see
that people will want to give a talk on it which is fantastic, but I guess
I see it as a separate thing not directly associated/promoted by the
project itself.
Regards,
On Wed, 14 Nov 2012, Christian Heinrich wrote:
I think that a presentation is a no brainer. As to workshop, since I really hope we would have a result to show, workshop for discussion would not be very useful. A training workshop would require an agenda and a commitment of a trainer to prepare a quality course that people will pay for. I personally am not sure what would be the content of such a training session. If anyone has a clear ideas as to what that be, we can either launch that as a WAFEC initiative or leave it to anyone who think it is a good business to do.
Quick question.
Should a workshop or training session be part of a wafec discussion? I see
that people will want to give a talk on it which is fantastic, but I guess
I see it as a separate thing not directly associated/promoted by the
project itself.
Regards,
- Robert A.
http://www.cgisecurity.com/
http://www.webappsec.org/
http://www.qasec.com/
On Wed, 14 Nov 2012, Christian Heinrich wrote:
> Ofer,
>
> I believe the intended audience of a workshop would be:
>
> 1. WAF Vendor(s) preparing documentation to support WAFEC.
> 2a. https://www.nsslabs.com/, https://www.icsalabs.com/, etc
> preforming independent verification of WAFEC against WAF Vendor claim
> on behalf of an end user.
> 2b. http://www.dsd.gov.au/infosec/aisep/providers.htm with the
> specific end user being Government.
> 3. End User evaluating WAF solutions based on a combination of the above.
>
> On Wed, Nov 14, 2012 at 9:09 AM, Ofer Shezaf <ofer@shezaf.com> wrote:
>> I think that a presentation is a no brainer. As to workshop, since I really hope we would have a result to show, workshop for discussion would not be very useful. A training workshop would require an agenda and a commitment of a trainer to prepare a quality course that people will pay for. I personally am not sure what would be the content of such a training session. If anyone has a clear ideas as to what that be, we can either launch that as a WAFEC initiative or leave it to anyone who think it is a good business to do.
>
>
> --
> Regards,
> Christian Heinrich
>
> http://cmlh.id.au/contact
>
> _______________________________________________
> wasc-wafec mailing list
> wasc-wafec@lists.webappsec.org
> http://lists.webappsec.org/mailman/listinfo/wasc-wafec_lists.webappsec.org
>
CH
Christian Heinrich
Tue, Nov 13, 2012 10:28 PM
Robert,
I believe it should considering it would affect the WASC brand as part
of its promotion?
On Wed, Nov 14, 2012 at 9:26 AM, Robert A. robert@webappsec.org wrote:
Quick question.
Should a workshop or training session be part of a wafec discussion? I see
that people will want to give a talk on it which is fantastic, but I guess I
see it as a separate thing not directly associated/promoted by the project
itself.
Regards,
On Wed, 14 Nov 2012, Christian Heinrich wrote:
I think that a presentation is a no brainer. As to workshop, since I
really hope we would have a result to show, workshop for discussion would
not be very useful. A training workshop would require an agenda and a
commitment of a trainer to prepare a quality course that people will pay
for. I personally am not sure what would be the content of such a training
session. If anyone has a clear ideas as to what that be, we can either
launch that as a WAFEC initiative or leave it to anyone who think it is a
good business to do.
Robert,
I believe it should considering it would affect the WASC brand as part
of its promotion?
On Wed, Nov 14, 2012 at 9:26 AM, Robert A. <robert@webappsec.org> wrote:
>
> Quick question.
>
> Should a workshop or training session be part of a wafec discussion? I see
> that people will want to give a talk on it which is fantastic, but I guess I
> see it as a separate thing not directly associated/promoted by the project
> itself.
>
> Regards,
> - Robert A.
> http://www.cgisecurity.com/
> http://www.webappsec.org/
> http://www.qasec.com/
>
>
> On Wed, 14 Nov 2012, Christian Heinrich wrote:
>
>> Ofer,
>>
>> I believe the intended audience of a workshop would be:
>>
>> 1. WAF Vendor(s) preparing documentation to support WAFEC.
>> 2a. https://www.nsslabs.com/, https://www.icsalabs.com/, etc
>> preforming independent verification of WAFEC against WAF Vendor claim
>> on behalf of an end user.
>> 2b. http://www.dsd.gov.au/infosec/aisep/providers.htm with the
>> specific end user being Government.
>> 3. End User evaluating WAF solutions based on a combination of the above.
>>
>> On Wed, Nov 14, 2012 at 9:09 AM, Ofer Shezaf <ofer@shezaf.com> wrote:
>>>
>>> I think that a presentation is a no brainer. As to workshop, since I
>>> really hope we would have a result to show, workshop for discussion would
>>> not be very useful. A training workshop would require an agenda and a
>>> commitment of a trainer to prepare a quality course that people will pay
>>> for. I personally am not sure what would be the content of such a training
>>> session. If anyone has a clear ideas as to what that be, we can either
>>> launch that as a WAFEC initiative or leave it to anyone who think it is a
>>> good business to do.
>>
>>
>>
>> --
>> Regards,
>> Christian Heinrich
>>
>> http://cmlh.id.au/contact
>>
>> _______________________________________________
>> wasc-wafec mailing list
>> wasc-wafec@lists.webappsec.org
>> http://lists.webappsec.org/mailman/listinfo/wasc-wafec_lists.webappsec.org
>>
>
--
Regards,
Christian Heinrich
http://cmlh.id.au/contact
OS
Ofer Shezaf
Tue, Nov 13, 2012 10:30 PM
I know who is WAFEC target audience, however I wonder what would a paid
workshop on WAFEC include.
~ Ofer
-----Original Message-----
From: Christian Heinrich [mailto:christian.heinrich@cmlh.id.au]
Sent: Wednesday, November 14, 2012 12:20 AM
To: Ofer Shezaf
Cc: Achim Hoffmann; wasc-wafec@lists.webappsec.org
Subject: Re: WASC/OWASP Web,Application Firewall Evaluation Criteria at
AppSec EU2013
Ofer,
I believe the intended audience of a workshop would be:
- WAF Vendor(s) preparing documentation to support WAFEC.
2a. https://www.nsslabs.com/, https://www.icsalabs.com/, etc preforming
independent verification of WAFEC against WAF Vendor claim on behalf of an
end user.
2b. http://www.dsd.gov.au/infosec/aisep/providers.htm with the specific end
user being Government.
- End User evaluating WAF solutions based on a combination of the above.
On Wed, Nov 14, 2012 at 9:09 AM, Ofer Shezaf ofer@shezaf.com wrote:
I think that a presentation is a no brainer. As to workshop, since I
really hope we would have a result to show, workshop for discussion would
not be very useful. A training workshop would require an agenda and a
commitment of a trainer to prepare a quality course that people will pay
for. I personally am not sure what would be the content of such a training
session. If anyone has a clear ideas as to what that be, we can either
launch that as a WAFEC initiative or leave it to anyone who think it is a
good business to do.
--
Regards,
Christian Heinrich
http://cmlh.id.au/contact
I know who is WAFEC target audience, however I wonder what would a paid
workshop on WAFEC include.
~ Ofer
-----Original Message-----
From: Christian Heinrich [mailto:christian.heinrich@cmlh.id.au]
Sent: Wednesday, November 14, 2012 12:20 AM
To: Ofer Shezaf
Cc: Achim Hoffmann; wasc-wafec@lists.webappsec.org
Subject: Re: WASC/OWASP Web,Application Firewall Evaluation Criteria at
AppSec EU2013
Ofer,
I believe the intended audience of a workshop would be:
1. WAF Vendor(s) preparing documentation to support WAFEC.
2a. https://www.nsslabs.com/, https://www.icsalabs.com/, etc preforming
independent verification of WAFEC against WAF Vendor claim on behalf of an
end user.
2b. http://www.dsd.gov.au/infosec/aisep/providers.htm with the specific end
user being Government.
3. End User evaluating WAF solutions based on a combination of the above.
On Wed, Nov 14, 2012 at 9:09 AM, Ofer Shezaf <ofer@shezaf.com> wrote:
> I think that a presentation is a no brainer. As to workshop, since I
really hope we would have a result to show, workshop for discussion would
not be very useful. A training workshop would require an agenda and a
commitment of a trainer to prepare a quality course that people will pay
for. I personally am not sure what would be the content of such a training
session. If anyone has a clear ideas as to what that be, we can either
launch that as a WAFEC initiative or leave it to anyone who think it is a
good business to do.
--
Regards,
Christian Heinrich
http://cmlh.id.au/contact
OS
Ofer Shezaf
Tue, Nov 13, 2012 10:31 PM
I tend to agree. Generally speaking building a training material might be a
task within a project, however I am not sure how this would work for WAFEC.
~ Ofer
-----Original Message-----
From: Robert A. [mailto:robert@webappsec.org]
Sent: Wednesday, November 14, 2012 12:26 AM
To: Christian Heinrich
Cc: Ofer Shezaf; wasc-wafec@lists.webappsec.org
Subject: Re: [WASC-WAFEC] WASC/OWASP Web, Application Firewall Evaluation
Criteria at AppSec EU2013
Quick question.
Should a workshop or training session be part of a wafec discussion? I see
that people will want to give a talk on it which is fantastic, but I guess I
see it as a separate thing not directly associated/promoted by the project
itself.
Regards,
On Wed, 14 Nov 2012, Christian Heinrich wrote:
I think that a presentation is a no brainer. As to workshop, since I
really hope we would have a result to show, workshop for discussion would
not be very useful. A training workshop would require an agenda and a
commitment of a trainer to prepare a quality course that people will pay
for. I personally am not sure what would be the content of such a training
session. If anyone has a clear ideas as to what that be, we can either
launch that as a WAFEC initiative or leave it to anyone who think it is a
good business to do.
I tend to agree. Generally speaking building a training material might be a
task within a project, however I am not sure how this would work for WAFEC.
~ Ofer
-----Original Message-----
From: Robert A. [mailto:robert@webappsec.org]
Sent: Wednesday, November 14, 2012 12:26 AM
To: Christian Heinrich
Cc: Ofer Shezaf; wasc-wafec@lists.webappsec.org
Subject: Re: [WASC-WAFEC] WASC/OWASP Web, Application Firewall Evaluation
Criteria at AppSec EU2013
Quick question.
Should a workshop or training session be part of a wafec discussion? I see
that people will want to give a talk on it which is fantastic, but I guess I
see it as a separate thing not directly associated/promoted by the project
itself.
Regards,
- Robert A.
http://www.cgisecurity.com/
http://www.webappsec.org/
http://www.qasec.com/
On Wed, 14 Nov 2012, Christian Heinrich wrote:
> Ofer,
>
> I believe the intended audience of a workshop would be:
>
> 1. WAF Vendor(s) preparing documentation to support WAFEC.
> 2a. https://www.nsslabs.com/, https://www.icsalabs.com/, etc
> preforming independent verification of WAFEC against WAF Vendor claim
> on behalf of an end user.
> 2b. http://www.dsd.gov.au/infosec/aisep/providers.htm with the
> specific end user being Government.
> 3. End User evaluating WAF solutions based on a combination of the above.
>
> On Wed, Nov 14, 2012 at 9:09 AM, Ofer Shezaf <ofer@shezaf.com> wrote:
>> I think that a presentation is a no brainer. As to workshop, since I
really hope we would have a result to show, workshop for discussion would
not be very useful. A training workshop would require an agenda and a
commitment of a trainer to prepare a quality course that people will pay
for. I personally am not sure what would be the content of such a training
session. If anyone has a clear ideas as to what that be, we can either
launch that as a WAFEC initiative or leave it to anyone who think it is a
good business to do.
>
>
> --
> Regards,
> Christian Heinrich
>
> http://cmlh.id.au/contact
>
> _______________________________________________
> wasc-wafec mailing list
> wasc-wafec@lists.webappsec.org
> http://lists.webappsec.org/mailman/listinfo/wasc-wafec_lists.webappsec
> .org
>
RA
Robert A.
Tue, Nov 13, 2012 10:34 PM
For some context.
Historically WASC has created content but hasn't promoted a product, service, workshop, or training event as part of the project. The purpose
of this is to remain vendor neutral as an organization. WASC's members have supported such things on their own (if they want), but the group as a
whole has never discussed supporting an event/product/service as part of a project.
I'm not trying to discourage such communication, just that we don't find ourselves doing this on behalf of WASC (without an officer vote since
this would be setting a precident).
Ofer,
Comments/opinion?
Regards,
On Wed, 14 Nov 2012, Christian Heinrich wrote:
Robert,
I believe it should considering it would affect the WASC brand as part
of its promotion?
On Wed, Nov 14, 2012 at 9:26 AM, Robert A. robert@webappsec.org wrote:
Quick question.
Should a workshop or training session be part of a wafec discussion? I see
that people will want to give a talk on it which is fantastic, but I guess I
see it as a separate thing not directly associated/promoted by the project
itself.
Regards,
On Wed, 14 Nov 2012, Christian Heinrich wrote:
I think that a presentation is a no brainer. As to workshop, since I
really hope we would have a result to show, workshop for discussion would
not be very useful. A training workshop would require an agenda and a
commitment of a trainer to prepare a quality course that people will pay
for. I personally am not sure what would be the content of such a training
session. If anyone has a clear ideas as to what that be, we can either
launch that as a WAFEC initiative or leave it to anyone who think it is a
good business to do.
For some context.
Historically WASC has created content but hasn't promoted a product, service, workshop, or training event as part of the project. The purpose
of this is to remain vendor neutral as an organization. WASC's members have supported such things on their own (if they want), but the group as a
whole has never discussed supporting an event/product/service as part of a project.
I'm not trying to discourage such communication, just that we don't find ourselves doing this on behalf of WASC (without an officer vote since
this would be setting a precident).
Ofer,
Comments/opinion?
Regards,
- Robert
On Wed, 14 Nov 2012, Christian Heinrich wrote:
> Robert,
>
> I believe it should considering it would affect the WASC brand as part
> of its promotion?
>
> On Wed, Nov 14, 2012 at 9:26 AM, Robert A. <robert@webappsec.org> wrote:
>>
>> Quick question.
>>
>> Should a workshop or training session be part of a wafec discussion? I see
>> that people will want to give a talk on it which is fantastic, but I guess I
>> see it as a separate thing not directly associated/promoted by the project
>> itself.
>>
>> Regards,
>> - Robert A.
>> http://www.cgisecurity.com/
>> http://www.webappsec.org/
>> http://www.qasec.com/
>>
>>
>> On Wed, 14 Nov 2012, Christian Heinrich wrote:
>>
>>> Ofer,
>>>
>>> I believe the intended audience of a workshop would be:
>>>
>>> 1. WAF Vendor(s) preparing documentation to support WAFEC.
>>> 2a. https://www.nsslabs.com/, https://www.icsalabs.com/, etc
>>> preforming independent verification of WAFEC against WAF Vendor claim
>>> on behalf of an end user.
>>> 2b. http://www.dsd.gov.au/infosec/aisep/providers.htm with the
>>> specific end user being Government.
>>> 3. End User evaluating WAF solutions based on a combination of the above.
>>>
>>> On Wed, Nov 14, 2012 at 9:09 AM, Ofer Shezaf <ofer@shezaf.com> wrote:
>>>>
>>>> I think that a presentation is a no brainer. As to workshop, since I
>>>> really hope we would have a result to show, workshop for discussion would
>>>> not be very useful. A training workshop would require an agenda and a
>>>> commitment of a trainer to prepare a quality course that people will pay
>>>> for. I personally am not sure what would be the content of such a training
>>>> session. If anyone has a clear ideas as to what that be, we can either
>>>> launch that as a WAFEC initiative or leave it to anyone who think it is a
>>>> good business to do.
>>>
>>>
>>>
>>> --
>>> Regards,
>>> Christian Heinrich
>>>
>>> http://cmlh.id.au/contact
>>>
>>> _______________________________________________
>>> wasc-wafec mailing list
>>> wasc-wafec@lists.webappsec.org
>>> http://lists.webappsec.org/mailman/listinfo/wasc-wafec_lists.webappsec.org
>>>
>>
>
>
>
> --
> Regards,
> Christian Heinrich
>
> http://cmlh.id.au/contact
>