OWASP is an open community dedicated to enabling organizations to conceive, develop, acquire, operate, and maintain applications that can be trusted. All of the OWASP tools, documents, forums, and chapters are free and open to anyone interested in improving application security.
OWASP is completely vendor neutral and does not endorse or certify any company, service, or product. All presentations, training, and talks performed for OWASP are required to meet this standard.
INTRODUCTION
Application Security leaders, software engineers, and researchers from all over the world gather at Global AppSec conferences to drive visibility and evolution in the safety and security of the world’s software and network, collaborate, and share the newest innovations in the field. The conference will take place on October 30 - 31, 2023, at the Marriott Marquis Washington DC. The event will also offer hands-on training with vetted and leading trainers from November 1-3, 2023.
Considering the ongoing international emergency regarding the COVID-19 Coronavirus, we are aware that an in-person conference may not be feasible. While we are moving forward with the planning of an in-person conference, there is a possibility we may need to make the conference virtual. We ask that you design content that could be effectively presented in either format. We will provide technical guidelines and assistance to speakers who may not be familiar with delivering virtual content should the decision be made to hold the conference virtually.
CALL FOR PRESENTATIONS (CFP) & SUBMISSION
The Global AppSec Program Team is formally issuing a call for presentations, re-opening March 5 2023, and closing May 5, 2023, at 11:59 PDT.
This year’s tracks are based on traditional OWASP tracks, but slightly changed and clarified. Speakers should focus on the following guidelines for each of the tracks below. Sessions will be scheduled for 1 hour, and you can include a 10-minute Q&A session if you choose.
- BUILDER / DEVELOPER - Show us how to build more secure apps, how to securely use technology in our code, and how to secure our systems at scale.
- BREAKER / TESTER - Show us how to test apps for security, and how to break secure systems.
- DEFENDER / OPS - Show us world-class application operational defense, tools and techniques enabling detection and response to attacks, automating your processes and pipelines, and running your production security program.
- MANAGER / CULTURE - Show us how to run your security teams effectively, create an effective security culture, selling security to your executives, or balancing the risk tradeoffs.
We’ve provided a few suggested topics below, but feel free to innovate!
- Web application security
- Mobile, Cloud, and Serverless security
- Blockchain & Internet of Things for security use
- Penetration testing & Application-level attacks
- Threat modeling, Application, and system architecture
- Security for DevOps engineers
- Privacy controls
- Planning and implementing an application security program
- Creating an AppSec team & culture
- Techniques to communicate risk and AppSec value to management - sharing what works and what doesn’t!
REVIEW PROCESS
CfP IMPORTANT DATES:
CfP Re-Opens March 5, 2023
CfP Closes May 5, 2023
Notification of submitters Week of June 12, 2023
Program announced the week of Week of July 10, 2023
Keep in mind: the better your description is, the better our review will be. Please review your proposal thoroughly, as your accepted abstract and bio will be published publicly as submitted on our site.
REVIEW CONSIDERATIONS
The Program Team will review your submission based on a descriptive abstract of your intended presentation.
Your presentation should:
Be Aimed at a Specific Audience - OWASP has a diverse audience of novice to advanced level practitioners. Your content should be developed to connect with a specific audience clearly.
Have a Clearly Written Abstract - Your Abstract is the only long-form marketing for your specific talk to our audience. It should be written so attendees can clearly understand what you will be discussing and what they will get out of your talk.
Have a Detailed Outline - Your detailed outline is your chance to frame your talk. Write this as thoroughly as possible, so the committee understands what you bring to the table.
Be Applicable - Talks that prioritize content that attendees will be able to implement immediately are preferred.
Not be a Marketing Pitch - Submissions which double as marketing talks or include sales pitches within the training will not be successful or accepted. All talks must be vendor agnostic, we do not approve of product demos.
Submissions must be provided by the speaker themselves, and not by the marketing department or agency. Show us what you know, and what you're passionate about!
We prefer new talks with fresh information, not ones that have been repeated many times before. If you wish to present a topic you’ve talked about in the past, please share with us what you have changed.
BLINDED REVIEW PROCESS
Please note that this is a blind submission.
It does not matter where you come from, what your gender is, or what formal education you have. We care about bringing our audience the most professional, interesting, and innovative content. The Review Committee is a diverse group as well.
We will review the submissions and choose the talks based on content only. Reviewers cannot view your personal details, and will score your submission based on its own quality and relevance. Please ensure you do not include your personal details or identifying information (such as name, company, location, etc) in any of the reviewed fields marked as such. There are specific fields provided that you can share a personal note, and these will be reviewed by the Program Committee before final acceptance. Submissions that violate this rule may be rejected.
TRAVEL ASSISTANCE
Global AppSec is a community event designated to support the Foundation, and we have a very limited budget. If personal travel costs would prevent you from participating, we will try to help cover part of your travel and accommodation costs so that you do not incur large expenses to come speak at our conference.
We cannot guarantee any sum at this time, however this should not dissuade you from submitting! We will not expect you to confirm attendance before we confirm how much assistance we can offer. This will NOT affect your acceptance at all and is not visible during the review.
TERMS
Following acceptance, we’ll provide guidance on presentation templates. All presentation slides will be published on the conference website after the conference. OWASP values vendor neutrality. Please make sure that any pictures and other materials in your slides do not violate any copyrights. You are solely liable for copyright violations. You may choose any CC license for your slides, including CC0. OWASP does suggest open licenses.
Additional Notes:
- OWASP is an inclusive organization for practitioners from all cultural, gender, ethnic, educational, ability, religious, and career backgrounds. We actively encourage speakers of all genders, sexual orientations, ages, religions, and ethnicity.
- Fields denoted by an asterisk are mandatory. Failure to complete your submission can result in your submission being excluded from the review process.
- Multiple submissions by a speaker will be reviewed. However, only one talk will be selected. We’re looking to expand speaking opportunities across our diverse community.
- Submissions must be provided by the speaker themselves, and not by the marketing department or agency. There is an option to add a 2nd speaker as well.
- This is a fully blinded review process, and submissions must be appropriately blinded as well. Personal details will not be shared with reviewers, please do not include them in the other fields in any way.
- While we do not offer an honorarium, a free registration is included, and we hope to create an epic speaker experience this year!
- All personal data collected during the submission process will be only for contacting submitters regarding their submission and will not be used for any marketing or commercials purposes. All data collected will be deleted once the selection process is complete.

About
The Lonestar Application Security Conference (LASCON) is an OWASP-associated conference held annually in Austin, TX. It is a gathering of 400+ web app developers, security engineers, mobile developers and information security professionals. LASCON is held in Texas where more Fortune 500 companies call home than any other state and it is held in Austin which is a hub for startups in the state of Texas. At LASCON, leaders at these companies along with security architects and developers gather to share cutting-edge ideas, initiatives, and technology advancements.
The conference will take place October 26 - 27, 2023 at the Norris Conference Center in Austin, Texas. The conference will also offer pre-conference training on October 24-25.
CFP Submission
Use this form to submit your proposed talk for LASCON. The CFP will close on Thursday, June 1, 2023. Submissions will be reviewed, using blind submission selection, and you will be contacted via the email address you provide on the form. All selections will be completed by Saturday, July 1, 2023.
The LASCON conferences are true security conferences with all talks and presentations focusing on various areas of information security. Topics should focus on the technical and social aspects of security, and should not contain marketing or sales pitches.
You can review the past LASCON talks. to get an idea of types of talks we are seeking.
Speaker Information
Selected speakers will …
- be expected to adhere to the OWASP Conference Policies
- read and electronically submit OWASP Speaker Agreement (please read thoroughly)
We know speakers are key to the success of a conference and hope you will submit a talk. In appreciation of your efforts, we include the following:
- All speakers receive full, free admission to the entire two-day conference.
- Speakers are given speaker badges and speaker SWAG.
- Speakers are invited to a Speakers Dinner (a casual event, held the evening before the conference).
- For international speakers, if accepted, we can provide a letter of confirmation for your visa submission.
- Your abstract and recording will be archived on LASCON sites. (See previous LASCON talks.)
INTRODUCTION
The OWASP Foundation is hosting a variety of fresh virtual application security training courses June 6-7, 2023 beginning at 9 am/EDT. Submissions are being accepted for an 8-hour virtual training course. Please note in your submission if you are proposing 2 (8) hour days or (2) 4 hour days.
CALL FOR TRAINERS (CFT) & SUBMISSION
The OWASP Foundation is formally issuing a call for Trainers, opening March 24, 2023 and running through April 20, 2023.
Trainers are not allowed to make multiple submissions. We will do our best not to offer repeating courses. The training audience will include developers interested in security as well as security professionals.
We are looking for training courses at all levels from someone new to the application security field to advanced topics for experienced professionals. However, all training submissions should have a focus on practical skills which are immediately applicable to an attendee’s job and have a significant hands-on element with tasks and exercises for attendees to attempt during the training.
It is highly encouraged for trainers to have previous virtual training experience.
REVIEW PROCESS
IMPORTANT DATES:
- CFT Opens March 24, 2023
- CFT Closes April 20, 2023
- Notification to submitters week of May 1, 2023
- The program announced the week of May 8, 2023
REVIEW CONSIDERATIONS
The reviewers will review your submission based on a descriptive abstract and detailed outline of your course. Including additional course materials will be helpful in our evaluation. Please review your proposal thoroughly as all accepted abstracts and bios will be published on our site as submitted.
Training should:
- Be Aimed at a Specific Audience - OWASP has a diverse audience that consists of novice to advanced level practitioners in different fields. Your content should be developed to clearly connect with a specific audience.
- Not be a Marketing Pitch - Submissions that double as marketing or include sales pitches within the training will not be accepted.
- Have a Clearly Written Abstract - Your Abstract is the only long-form marketing for your specific talk to our audience. It should be written so that attendees can clearly understand what you will be discussing and what they will get out of your class. Your abstract should include the learning objectives of the training.
- Have a Detailed Outline - Detailed description of how you are structuring the course. Walk the reviewer through the training.
- Be Clearly Applicable - Classes that prioritize content that attendees will be able to immediately implement are preferred.
- Include Hands-on training - Hands-on labs which allow attendees to connect meaningfully with content are preferred.
- Demonstrate the Expertise of Trainer(s) - The submission should highlight the experience of the trainer(s) in the subject of training and in delivering professional training.
TERMS All trainers will be required to submit a trainer agreement. The following conditions apply for those that want to provide training at the conference. Trainer provides:
- Class syllabus/training materials.
- All course materials for students.
- Promotion of training on all available media eg. Twitter, Linkedin
- Trainers may brand training materials to increase their exposure.
OWASP provides:
- Training Platform
- Registration Logistics
- Marketing
REMUNERATION AND PAYMENT
As a trainer of a Virtual Training, I am eligible to share 40% of net revenue up to $7,500 USD, and 50% of net revenues above $7,500 USD.
https://owasp.org/www-policy/legal/speaker-agreement
All personal data collected during the submission process will be only for contacting submitters regarding their submission and will not be used for any marketing or commercials purposes. All data collected will be deleted once the selection process is complete.