By Dan Cornell
The OWASP DC folks put up the first batch of videos from the 2010 OWASP DC conference, including the video from my presentation “Application Portfolio Risk Ranking: Banishing FUD With Structure and Numbers” It can be seen online here:
Application Portfolio Risk Taking: Banishing FUD with Structure & Numbers with Dan Cornell, Denim Group from OWASP DC on Vimeo.
The slides from that presentation are also online:
Having an accurate application portfolio is critical because if you don’t know your organization’s attack surface then you don’t know what to defend. Building risk-ranking into that portfolio is also key because it allows you to properly allocate scarce assessment and remediation resources.
Please email me if you would like a copy of the Excel spreadsheet mentioned in the talk.
Contact us for help risk-ranking your application portfolio.
--Dan
dan _at_ denimgroup.com


Comments