Category:OWASP Project

From OWASP

Jump to: navigation, search

An OWASP project is a collection of related tasks that have a defined roadmap and team members. OWASP project leaders are responsible for defining the vision, roadmap, and tasks for the project. The project leader also promotes the project and builds the team. Tools and documents are organized into the following categories:

  • PROTECT - These are tools and documents that can be used to guard against security-related design and implementation flaws.
  • DETECT - These are tools and documents that can be used to find security-related design and implementation flaws.
  • LIFE CYCLE - These are tools and documents that can be used to add security-related activities into the Software Development Life Cycle (SDLC).

If you would like to start a new project please review the How to Start an OWASP Project guide. Please contact the Global Project Committee members to discuss project ideas and how they might fit into OWASP. All OWASP projects must be free and open and have their homepage on the OWASP portal. You can read all the guidelines in the Project Assessment Criteria.

Every project has an associated mail list. You can view all the lists, examine their archives, and subscribe to any of them on the OWASP Project Mailing Lists page.

A list of Projects that have been identified as orphaned ones has been set up. Please glance at it and see you find interest in leading any of them.

  • Release quality projects are generally the level of quality of professional tools or documents.
  • Projects are listed below.
ToolsDocumentation

PROTECT:

OWASP AntiSamy Java Project
an API for validating rich HTML/CSS input from users without exposure to cross-site scripting and phishing attacks (Assessment Criteria v1.0)
OWASP AntiSamy .NET Project
an API for validating rich HTML/CSS input from users without exposure to cross-site scripting and phishing attacks. (Assessment Criteria v1.0)
OWASP Enterprise Security API (ESAPI) Project
a free and open collection of all the security methods that a developer needs to build a secure web application. (Assessment Criteria v1.0)


DETECT:

OWASP Live CD Project
this CD collects some of the best open source security projects in a single environment. Web developers, testers and security professionals can boot from this Live CD and have access to a full security testing suite. (Assessment Criteria v1.0)
OWASP WebScarab Project
a tool for performing all types of security testing on web applications and web services (Assessment Criteria v1.0)


LIFE CYCLE:

OWASP WebGoat Project
an online training environment for hands-on learning about application security (Assessment Criteria v1.0)


PROTECT:

OWASP Development Guide
a massive document covering all aspects of web application and web service security (Assessment Criteria v1.0)
OWASP .NET Project
the purpose of the this project is to provide a central repository of information and tools for software professionals that use the Microsoft .NET Framework for web applications and services. (Assessment Criteria v1.0)
OWASP Ruby on Rails Security Guide V2
this Project is the one and only source of information about Rails security topics. (Assessment Criteria v1.0)


DETECT:

OWASP Application Security Verification Standard Project
The ASVS defines the first internationally-recognized standard for conducting application security assessments. It covers both automated and manual approaches for assessing (verifying) applications using both security testing and code review techniques. (Assessment Criteria v1.0)
OWASP Code Review Guide
a project to capture best practices for reviewing code. (Assessment Criteria v1.0)
OWASP Testing Guide
a project focused on application security testing procedures and checklists (Assessment Criteria v1.0)
OWASP Top Ten Project
an awareness document that describes the top ten web application security vulnerabilities (Assessment Criteria v1.0)


LIFE CYCLE:

OWASP AppSec FAQ Project
FAQ covering many application security topics (Assessment Criteria v1.0)
OWASP Legal Project
a project focused on providing contract language for acquiring secure software (Assessment Criteria v1.0)
OWASP Source Code Review for OWASP-Projects
a workflow for OWASP projects to incorporate static analysis into the Software Development Life Cycle (SDLC). (Assessment Criteria v1.0)


How to add a new OWASP Project article

You can follow the instructions to make a new OWASP Project article. Please use the appropriate structure and follow the Tutorial. Be sure to paste the following at the end of your article to make it show up in the OWASP Project category:

[[Category:OWASP Project]]

Subcategories

This category has the following 132 subcategories, out of 132 total.

.

A

B

C

D

E

E cont.

F

G

I

J

L

O

O cont.

P

S

T

V

W

X

Personal tools
Language