Online Training Special Offer: Get an iPad, ASUS Chromebook or Take $250 Off with Online Training!

Webcasts

To attend this webcast, login to your SANS Account or create your Account.

Building a Content Security Policy

  • Tuesday, August 19th, 2014 at 1:00 PM EDT (17:00:00 UTC)
  • Eric Johnson
This webcast has been archived. You can view the webcast presentation and download the slides by logging into your SANS Portal Account or creating an Account. Click the Register Now button after you have logged in to view the Webcast.

You can now attend the webcast using your mobile device!

Overview

Content Security Policy is gaining traction as a strong client side mitigating control for preventing Cross-Site Scripting attacks. However, because it is a relatively new security feature with inconsistent browser support, we are seeing very few CSP implementations in production environments. In this talk, we will explore the features available in CSP 1.0, what is coming in CSP 1.1, and how you can go about building a CSP in your web applications. We will also cover a few CSP tools that are available, and how they can help automate the process.

Speaker Bio

Eric Johnson

Eric is a co-founder and principal security engineer at Puma Security focusing on modern static analysis product development and DevSecOps automation. His experience includes application security automation, cloud security reviews, static source code analysis, web and mobile application penetration testing, secure development lifecycle consulting, and secure code review assessments.

Previously, Eric spent 5 years as a principal security consultant at an information security consulting firm helping companies deliver secure products to their customers, and another 10 years as an information security engineer at a large US financial institution performing source code audits.

As a Certified Instructor with the SANS Institute, Eric authors information security courses on DevSecOps, cloud security, secure coding, and defending mobile apps. He serves on the advisory board for the SANS Security Awareness Developer training program, delivers security training around the world, and presents security research at conferences including SANS, BlackHat, OWASP, BSides, JavaOne, UberConf, and ISSA.

Eric completed a bachelor's degree in computer engineering and a masters degree in information assurance at Iowa State University, and currently holds the CISSP, GWAPT, GSSP-.NET, and GSSP-Java certifications.

Need Help? Visit our FAQ page or email webcast-support@sans.org.

Not able to attend a SANS webcast? All Webcasts are archived so you may view and listen at a time convenient to your schedule. View our webcast archive and access webcast recordings/PDF slides.