Force.com: Secure Cloud Development. Varun Badhwar Force.com Security Manager
|
|
|
- Noah Wood
- 10 years ago
- Views:
Transcription
1 Force.com: Secure Cloud Development Varun Badhwar Force.com Security Manager
2 Safe Harbor Statement Safe harbor statement under the Private Securities Litigation Reform Act of 1995: This presentation may contain forwardlooking statements including but not limited to statements concerning the potential market for our existing service offerings and future offerings. All of our forward looking statements involve risks, uncertainties and assumptions. If any such risks or uncertainties materialize or if any of the assumptions proves incorrect, our results could differ materially from the results expressed or implied by the forward-looking statements we make. The risks and uncertainties referred to above include - but are not limited to - risks associated with possible fluctuations in our operating results and cash flows, rate of growth and anticipated revenue run rate, errors, interruptions or delays in our service or our Web hosting, our new business model, our history of operating losses, the possibility that we will not remain profitable, breach of our security measures, the emerging market in which we operate, our relatively limited operating history, our ability to hire, retain and motivate our employees and manage our growth, competition, our ability to continue to release and gain customer acceptance of new and improved versions of our service, customer and partner acceptance of the AppExchange, successful customer deployment and utilization of our services, unanticipated changes in our effective tax rate, fluctuations in the number of shares outstanding, the price of such shares, foreign currency exchange rates and interest rates. Further information on these and other factors that could affect our financial results is included in the reports on Forms 10- K, 10-Q and 8-K and in other filings we make with the Securities and Exchange Commission from time to time. These documents are available on the SEC Filings section of the Investor Information section of our website at Salesforce.com, inc. assumes no obligation and does not intend to update these forwardlooking statements, except as required by law.
3 Agenda Salesforce.com s Philosophy Vision Secure Cloud Development: Education Secure Design Secure Development Secure Testing Secure Release Resources Q&A
4 Salesforce.com Philosophy Success of cloud computing dependant on earning and maintaining customer trust Protecting the privacy of customer data is salesforce.com s core value Details available at:
5 Vision Value Trust as a Top Priority Create a security conscious community encompassing developers / ISVs Enabling Success Provide free educational resources, tools and processes that help deliver trusted Force.com applications Reduce Development Costs According to NIST*, eliminating vulnerabilities in the design stage can cost 30 times less than fixing them post-release * NIST The National Institute of Standard and Technology
6 Force.com Secure Cloud Development Education Release Design Test Develop Seamless integration of security into your existing SDLC
7 Secure Education Overview of Force.com Security Learn about the sharing model and various security controls available to org administrators Developer Training Get educated on writing secure code on Force.com Developer Quiz Assess your security awareness and learn to identify vulnerabilities within Force.com code
8 Secure Design Security Resources Generic Force.com articles and resources. Topics include SAML, sharing, etc. Security Self-Assessment Receive a customized report with links to security articles and resources specific to your application architecture Office Hours Receive free consultation from a member of the salesforce.com security team Security Discussion Board
9 Secure Development Secure Coding Guidelines Obtain platform-specific (Force.com, Java,.Net, etc.) recommendations on mitigating security vulnerabilities such as XSS, Injection, Session Management, etc. Secure Coding Library Open source library for implementing additional security features (CRUD/FLS, input validation, output encoding, etc.) Part of OWASP Enterprise Security API
10 Secure Testing Force.com Security Source Scanner On-demand static source code analysis tool to help identify potential vulnerabilities within your Apex and Visualforce code Web Application Security Scanner Integrating a web-application with Force.com? AppExchange partners are entitled to receive a free license for Burp Suite Professional
11 Secure Release Salesforce.com Security Review Periodic security review of AppExchange and OEM applications Details published at: Security_Review Incident Response (Coming Soon) Guidance on engaging with customers and salesforce.com in case of a security incident
12 Conclusion Free, ready to consume resources Secure Force.com ecosystem Reduced development costs Streamlined AppExchange security process Education Release Design Test Develop
13 Key Resources Secure Cloud Development Home Page On-Demand Security Source Code Scanner Security Discussion Board AppExchange Security Review OWASP
14 Q&A Security Discussion Board:
Developers: Build Next Generation Apps. Michael Yeganeh Solution Engineering Lead [email protected]
Developers: Build Next Generation Apps Michael Yeganeh Solution Engineering Lead [email protected] Safe harbor Safe harbor statement under the Private Securities Litigation Reform Act of 1995: This
Welcome to the Force.com Developer Day
Welcome to the Force.com Developer Day Sign up for a Developer Edition account at: http://developer.force.com/join Nicola Lalla [email protected] n_lalla nlalla26 Safe Harbor Safe harbor statement under
The Fastest Path to the Cloud Building Your SaaS Company on Force.com
The Fastest Path to the Cloud Building Your SaaS Company on Force.com Kai Mäkelä salesforce.com [email protected] Safe Harbor Safe harbor statement under the Private Securities Litigation Reform Act
PLATFORM AS A SERVICE MULTI TENANCY AND OPEN STANDARDS. Peter Chittum @pchittum salesforce.com!
PLATFORM AS A SERVICE MULTI TENANCY AND OPEN STANDARDS Peter Chittum @pchittum salesforce.com! Platform as a Service Multi Tenancy and Open Standards Peter Chittum Developer Evangelist @pchittum Safe Harbor
VerticalResponse for AppExchange: Past, Present and Future
VerticalResponse for AppExchange: Past, Present and Future Presented By: Joshua Feinberg: VP, Product Management Alex Scalisi: Sales Executive Special Guest Speaker: Judy Loehr: Senior Sales & Marketing
Salesforce.com and the financial services sector
Don t be clouded by the cloud: Salesforce.com and the financial services sector Martijn Simons Account Executive Financial Services @Martijn_On_Line In//martijn-simons Lien Ceulemans Corporate legal counsel
Cloud to Cloud Integrations with Force.com. Sandeep Bhanot Developer Evangelist @cloudysan
Cloud to Cloud Integrations with Force.com Sandeep Bhanot Developer Evangelist @cloudysan Safe Harbor Salesforce.com Safe harbor statement under the Private Securities Litigation Reform Act of 1995: This
Secure Coding. External App Integrations. Tim Bach Product Security Engineer salesforce.com. Astha Singhal Product Security Engineer salesforce.
Secure Coding External App Integrations Astha Singhal Product Security Engineer salesforce.com Tim Bach Product Security Engineer salesforce.com Safe Harbor Safe harbor statement under the Private Securities
The Desktop is Dead... Let s Talk About the Living! Bruce Richardson, Chief Enterprise Strategist [email protected]
The Desktop is Dead... Let s Talk About the Living! Bruce Richardson, Chief Enterprise Strategist [email protected] The Customer Revolution Safe Harbor Safe harbor statement under the Private
Secure Coding SSL, SOAP and REST. Astha Singhal Product Security Engineer salesforce.com
Secure Coding SSL, SOAP and REST Astha Singhal Product Security Engineer salesforce.com Safe Harbor Safe harbor statement under the Private Securities Litigation Reform Act of 1995: This presentation may
Salesforce Announces Fiscal 2016 First Quarter Results Becomes First Enterprise Cloud Computing Company to Reach $6 Billion Revenue Run Rate
John Cummings Salesforce Investor Relations 415-778-4188 [email protected] Chi Hea Cho Salesforce Public Relations 415-281-5304 [email protected] Salesforce Announces Fiscal 2016 First Quarter
Salesforce delivered the following results for its fiscal fourth quarter and full fiscal year 2015:
John Cummings Salesforce Investor Relations 415-778-4188 [email protected] Chi Hea Cho Salesforce Public Relations 415-281-5304 [email protected] Salesforce Announces Fiscal 2015 Fourth Quarter
Webhooks. Near-real time event processing with guaranteed delivery of HTTP callbacks. HBaseCon 2015
Webhooks Near-real time event processing with guaranteed delivery of HTTP callbacks HBaseCon 2015 Alan Steckley Principal Software Engineer, Salesforce 2 Poorna Chandra Software Engineer, Cask 3 Safe Harbor
WELCOME! Webinar on roundcorner's donor engagement platform roundcause. with Childfund International, IRC, Salesforce Foundation and roundcorner
WELCOME! Webinar on roundcorner's donor engagement platform roundcause with Childfund International, IRC, Salesforce Foundation and roundcorner Please stand by, we will get started soon. NOTE: Audio should
SPRING 14 RELEASE NOTES
SPRING 14 RELEASE NOTES At Salesforce ExactTarget Marketing Cloud your success is our top priority and we re working hard to continuously improve the Marketing Cloud solutions you use. We recently reached
AKAMAI AND RIVERBED JOINTLY DEVELOP INNOVATIVE SAAS ACCELERATION SOLUTION
AKAMAI AND RIVERBED JOINTLY DEVELOP INNOVATIVE SAAS ACCELERATION SOLUTION Combined Best-in-Class Internet and WAN Optimization Technologies Deliver First of Its Kind Solution to Speed SaaS Application
Building the Global Cloud
Building the Global Cloud Beyond IT Migration to the Enterprise Peter Coffee Head of Platform Research salesforce.com inc. Safe Harbor Safe harbor statement under the Private Securities Litigation Reform
elivering CRM Success in the Cloud
Salesforce.com Services As a Cloud System Integrator Agama Solutions partners with you through the complete lifespam of your cloud journey while amplifying your returns from the cloud and minimizing the
IMS Health to Acquire Cegedim s Information Solutions And CRM Businesses
News For Immediate Release Contacts: Tor Constantino Tom Kinsley Media Relations Investor Relations +1.484.567.6732 +1.203.448.4691 [email protected] [email protected] IMS Health to Acquire
Adobe Systems Incorporated
Adobe Connect 9.2 Page 1 of 8 Adobe Systems Incorporated Adobe Connect 9.2 Hosted Solution June 20 th 2014 Adobe Connect 9.2 Page 2 of 8 Table of Contents Engagement Overview... 3 About Connect 9.2...
Big Data Use Cases. At Salesforce.com. Narayan Bharadwaj Director, Product Management Salesforce.com. @nadubharadwaj
Big Data Use Cases At Salesforce.com Narayan Bharadwaj Director, Product Management Salesforce.com @nadubharadwaj Safe harbor Safe harbor statement under the Private Securi9es Li9ga9on Reform Act of 1995:
SuccessFactors Announces Record First Quarter Fiscal 2009 Results
CONTACTS: Dominic Paschel SuccessFactors, Inc. Public & Investor Relations 415-262-4641 [email protected] SuccessFactors Announces Record First Quarter Fiscal 2009 Results Revenues Grow 50%,
Sierra Wireless Reports Second Quarter 2015 Results
Sierra Wireless Reports Second Quarter 2015 Results Q2 2015 revenue of $158 million; 17% year-over-year growth Record revenue of $158.0 million, an increase of 17.0% compared to Q2 2014 Non-GAAP earnings
Secure Development Lifecycle. Eoin Keary & Jim Manico
Secure Development Lifecycle Jim Manico @manicode OWASP Volunteer Global OWASP Board Member OWASP Cheat-Sheet Series Manager VP of Security Architecture, WhiteHat Security 16 years of web-based, database-driven
Safe Harbor Statement
Safe Harbor Statement Statements in this presentation relating to Oracle's future plans, expectations, beliefs, intentions and prospects, are "forwardlooking statements" and are subject to material risks
Cloud Sherpas. SALESFORCE Simplified Deployment Strategy. 2011-2012 Google Partner of the Year
SALESFORCE Simplified Deployment Strategy 2011-2012 Google Partner of the Year Table of Contents SOFTWARE DEVELOPMENT LIFECYCLE 1 Simple development 1 A Simplified Software Development Lifecycle 2 Complex
Embracing the Cloud 5 Key Benefits From Salesforce.com. Mark Easley Sr. Director Sales Engineering Service Cloud measley@salesforce.
Embracing the Cloud 5 Key Benefits From Salesforce.com. Mark Easley Sr. Director Sales Engineering Service Cloud [email protected] Two Market Leaders Come Together Gartner Magic Quadrants Customer
The AppSec How-To: 10 Steps to Secure Agile Development
The AppSec How-To: 10 Steps to Secure Agile Development Source Code Analysis Made Easy 10 Steps In Agile s fast-paced environment and frequent releases, security reviews and testing sound like an impediment
WebGoat for testing your Application Security tools
WebGoat for testing your Application Security tools NAISG-DFW February 28 th, 2012 Michael A Ortega, CISSP CEH CISM GCFA Sr Application Security Professional IBM Security Systems 312.523.1538 [email protected]
5 Reasons CIOs are Adopting Cloud Computing in 2009 Application Development that s 5 Times Faster at 1/2 the Cost
5 Reasons CIOs are Adopting Cloud Computing in 2009 Application Development that s 5 Times Faster at 1/2 the Cost Contents Introduction... 2 Why Choose Cloud Computing?... 2 1. Delivers Faster Time to
Oracle Database 12c. Andy Mendelsohn. Senior Vice President, Oracle Database Server Technologies
Oracle Database 12c Andy Mendelsohn Senior Vice President, Oracle Database Server Technologies 1 Safe Harbor Statement "Safe Harbor" Statement: Statements in this presentation relating to Oracle's future
Oracle Cloud: Line of Business PaaS Services. Balaji Yelamanchili Senior Vice President Product Development
Oracle Cloud: Line of Business PaaS Services Balaji Yelamanchili Senior Vice President Product Development Safe Harbor Statement "Safe Harbor" Statement: Statements in this presentation relating to Oracle's
BlackBerry Reports Software and Services Growth of 106 Percent for Q4 and 113 Percent for Fiscal 2016
April 1, FOR IMMEDIATE RELEASE BlackBerry Reports Software and Services Growth of 106 Percent for Q4 and 113 Percent for Fiscal Company reports positive free cash flow for eighth consecutive quarter and
ACI Worldwide, Inc. Reports Financial Results for the Quarter Ended March 31, 2014
News Release ACI Worldwide, Inc. Reports Financial Results for the Quarter Ended March 31, 2014 HIGHLIGHTS SNET bookings of $122 million, up 59% from Q1 last year Recurring revenue up 57% from last year,
4Q15 Earnings February 2016
4Q15 Earnings February 2016 Forward-Looking Statements The statements contained in this presentation that refer to plans and expectations for the next quarter, the full year or the future are forward-looking
Western Union. Khalid Fellahi, SVP & GM WU Digital. March 25, 2014
Western Union Khalid Fellahi, SVP & GM WU Digital March 25, 2014 SAFE HARBOR This presentation contains certain statements that are forward-looking within the meaning of the Private Securities Litigation
PAYCHEX, INC. REPORTS SECOND QUARTER RESULTS
PAYCHEX, INC. REPORTS SECOND QUARTER RESULTS December 19, 2014 SECOND QUARTER FISCAL 2015 HIGHLIGHTS Total service revenue increased 10% to $665.9 million. Payroll service revenue increased 4% to $411.2
SAP The World s Leading Business Software Company. Rainer Zinow, Senior Vice President SAP Cloud, SAP SE Frankfurt am Main, September 9, 2014
SAP The World s Leading Business Software Company Rainer Zinow, Senior Vice President SAP Cloud, SAP SE Frankfurt am Main, September 9, 2014 Safe Harbor Statement Any statements contained in this document
Microsoft Cloud Strength Highlights Second Quarter Results
Microsoft Cloud Strength Highlights Second Quarter Results Commercial cloud annualized revenue run rate exceeds $9.4 billion; Windows 10 active on over 200 million devices REDMOND, Wash. January 28, 2016
KICK-START CLOUD VENTURES
Contents SALESFORCE & CRM PRACTICE GROUP 3 MARKETING & CAMPAIGN MESSAGE ORCHESTRATION 4 FORCE.COM & ISV PARTNER INTEGRATED COLLABORATION & CAMPAIGN MANAGEMENT 4 MARKETING & OPERATIONAL MESSAGE ORCHESTRATION
617-444-3913 617-274-7130 AKAMAI REPORTS SECOND QUARTER 2015 FINANCIAL RESULTS
FOR IMMEDIATE RELEASE Contacts: Jeff Young Tom Barth Media Relations Investor Relations Akamai Technologies Akamai Technologies 617-444-3913 617-274-7130 [email protected] [email protected] AKAMAI REPORTS
IBM Rational AppScan: Application security and risk management
IBM Software Security November 2011 IBM Rational AppScan: Application security and risk management Identify, prioritize, track and remediate critical security vulnerabilities and compliance demands 2 IBM
Vivint Wireless Internet Update. September 23, 2015
Vivint Wireless Internet Update September 23, 2015 preliminary statement This presentation includes forward-looking statements as defined by the Private Securities Litigation Reform Act of 1995 including
A Strategic Approach to Web Application Security The importance of a secure software development lifecycle
A Strategic Approach to Web Application Security The importance of a secure software development lifecycle Rachna Goel Technical Lead Enterprise Technology Web application security is clearly the new frontier
Key Considerations for Information Technology Governance. 900 Monroe NW Grand Rapids, MI 49503 (616) 632-8000
Key Considerations for Information Technology Governance What is IT Governance? Big Picture approach to information and data management Sets priorities: Managing performance Delivering value Managing risk
Regal Beloit Corporation Third Quarter 2014 Earnings Conference Call
Regal Beloit Corporation Third Quarter 2014 Earnings Conference Call November 4, 2014 Mark Gliebe Chairman and Chief Executive Officer Jon Schlemmer Chief Operating Officer Chuck Hinrichs Vice President
Management Discussion and Analysis For The 9 Months Ended, June 30 2015
Management Discussion and Analysis For The 9 Months Ended, June 30 2015 The following discussion and analysis as of August 31, 2015 should be read in conjunction with the consolidated financial statements
Debt Investors Call First Quarter 2015. Walldorf, Germany Monday, May 4, 2015
Debt Investors Call First Quarter 2015 Walldorf, Germany Monday, May 4, 2015 Safe Harbor Statement Any statements contained in this document that are not historical facts are forward-looking statements
5 Reasons CIOs are Adopting Cloud Computing in 2010 Application Development that s 5 Times Faster at 1/2 the Cost
5 Reasons CIOs are Adopting Cloud Computing in 2010 Application Development that s 5 Times Faster at 1/2 the Cost WHITE PAPER Contents Introduction... 2 Why choose cloud computing?... 2 1. Delivers faster
Q4 2015 Financial Results
Q4 2015 Financial Results January 28, 2016 Copyright Fortinet Inc. All rights reserved. Safe Harbor Statement Information, statements and projections contained in these presentation slides and related
Integrating Remedyforce
White Paper Integrating Remedyforce Robert Monton (BMC Software) Shikha Jaiswal (Persistent Systems) 06 March 2015 Welcome to the Getting Started with BMC Remedyforce Series Today s IT departments must
Brookfield Property Partners Offer to Purchase Any or All Issued and Outstanding Common Shares of Brookfield Office Properties Inc.
Brookfield Property Partners Offer to Purchase Any or All Issued and Outstanding Common Shares of Brookfield Office Properties Inc. Shareholder Q&A Brookfield Property Partners L.P. ( Brookfield Property
PAYCHEX, INC. REPORTS THIRD QUARTER RESULTS
PAYCHEX, INC. REPORTS THIRD QUARTER RESULTS March 25, 2015 THIRD QUARTER FISCAL 2015 HIGHLIGHTS Total service revenue increased 8% to $693.6 million for the third quarter; 9% for the nine months. Payroll
Third-Quarter 2015 Earnings Conference Call Executive Commentary Highlights. October 27, 2015
Third-Quarter 2015 Earnings Conference Call Executive Commentary Highlights October 27, 2015 Forward-Looking Statement of Merck & Co., Inc., Kenilworth, N.J., USA This presentation of Merck & Co., Inc.,
2015 Second Quarter Business Review (unaudited) July 23, 2015
2015 Second Quarter Business Review (unaudited) July 23, 2015 1 Forward Looking Statement This presentation contains forward-looking information about 3M's financial results and estimates and business
Course Details V1.0. Selinis Technologies Pvt Ltd. 2012, All Rights Reserved
Salesforce.com CRM Administration & Development Course Details V1.0 Selinis Pvt Ltd. 2012, All Rights Reserved Salesforce.com Administration Course Details V1.0 CRM Overview Introduction to CRM? Why CRM?
Learning objectives for today s session
Black Box versus White Box: Different App Testing Strategies John B. Dickson, CISSP Learning objectives for today s session Understand what a black box and white box assessment is and how they differ Identify
Project #1: Supporting Development Needs Across Multiple Salesforce Projects for a US Company
Project #1: Supporting Development Needs Across Multiple Salesforce Projects for a US Company Brief Description Client Project Project type Type of activity Technology Status Salesforce integration company
Successful Platform-as-a-Service Requires a Supporting Ecosystem for HR Applications
Successful Platform-as-a-Service Requires a Supporting Ecosystem for HR Applications Platform-as-a-Service is the computing term used to describe a hosted web-based computing environment and the associated
Strategic Information Security. Attacking and Defending Web Services
Security PS Strategic Information Security. Attacking and Defending Web Services Presented By: David W. Green, CISSP [email protected] Introduction About Security PS Application Security Assessments
Public Cloud Offerings and Private Cloud Options. Week 2 Lecture 4. M. Ali Babar
Public Cloud Offerings and Private Cloud Options Week 2 Lecture 4 M. Ali Babar Lecture Outline Public and private clouds Some key public cloud providers (More details in the lab) Private clouds Main Aspects
Fourth Quarter 2015 Earnings Release February 3, 2016
Fourth Quarter 2015 Earnings Release February 3, 2016 Alexander M. Cutler Forward-looking Statements and Non-GAAP Financial Information This presentation or the comments we make on our call today contain
Salesforce Admin Course Content: Chapter 1 CRM Introduction Introduction to CRM? Why CRM?
Salesforce Admin Course Content: Chapter 1 CRM Introduction Introduction to CRM? Why CRM? Chapter 2 Introduction to Cloud Computing & Salesforce.com Cloud Computing - Overview What is Software-as-a-Service
PAYCHEX, INC. REPORTS FOURTH QUARTER AND FISCAL 2015 RESULTS
PAYCHEX, INC. REPORTS FOURTH QUARTER AND FISCAL 2015 RESULTS July 1, 2015 FOURTH QUARTER AND FULL YEAR FISCAL 2015 HIGHLIGHTS Total service revenue increased 8% to $681.4 million for the fourth quarter;
White Paper. Automating Your Code Review: Moving to a SaaS Model for Application Security
White Paper Automating Your Code Review: Moving to a SaaS Model for Application Security Contents Overview... 3 Executive Summary... 3 Code Review and Security Analysis Methods... 5 Source Code Review
Driving Shareholder Value
Driving Shareholder Value Business Model and Capital Allocation Strategy Wolfgang Nickl CFO, Western Digital September 13, 2012 SAFE HARBOR Forward-Looking Statements This presentation contains forward-looking
Challenging quarter for Mobile Devices. Daily order rates improving. Free Cash Flow > Net Income. FCT acquisition. Page 3
August 7, 2013 Page 1 Statements in this release that are not historical are forward-looking and are subject to various risks and uncertainties that could cause actual results to vary materially from those
Test Challenges and Approaches With SaaS and PaaS. Dr. Ganesh Neelakanta Iyer Principal QA Engineer Progress Software
Test Challenges and Approaches With SaaS and PaaS Dr. Ganesh Neelakanta Iyer Principal QA Engineer Progress Software About Me Completed B.Tech. in Computer Science and Engineering from Mahatma Gandhi University,
CITIGROUP GLOBAL TECHNOLOGY CONFERENCE. September 2, 2014
CITIGROUP GLOBAL TECHNOLOGY CONFERENCE September 2, 2014 SAFE HARBOR This presentation contains forward-looking statements, including, among other things, statements regarding our growth prospects; our
SECURITY AND REGULATORY COMPLIANCE OVERVIEW
Powering Cloud IT SECURITY AND REGULATORY COMPLIANCE OVERVIEW BetterCloud for Office 365 Executive Summary BetterCloud provides critical insights, automated management, and intelligent data security for
SAP The World s Leading Business Software Company. Investor Presentation SAP Senior Management Global Investor Roadshow, Nov.
SAP The World s Leading Business Software Company Investor Presentation SAP Senior Management Global Investor Roadshow, Nov. 2-4, 2011 Safe Harbor Statement Any statements contained in this document that
Sierra Wireless Corporate Overview. February 2015
Sierra Wireless Corporate Overview February 2015 1 Safe harbor statement Certain statements and information in this presentation are not based on historical facts and constitute forward-looking statements
