OWASP Codes of Conduct

= Main =

Project's Purpose
OWASP needs to take advantage of every opportunity to affect software development everywhere to achieve our mission "to make application security visible so that people and organizations can make informed decisions about application security risks".

At the Summit 2011 in Portugal, the idea was created to try to influence educational institutions, government bodies, standards groups, and trade organizations. We set out to define a set of minimal requirements for these organizations specifying what we believe to be the most effective ways to support our mission. We call these requirements a “code of conduct” to imply that these are normative standards, they represent a minimum baseline, and that they are not difficult to achieve.

This project develops and maintains OWASP Codes of Conduct, and began with those initially created at the following working sessions at the 2011 OWASP Summit:
 * Defining a Minimal AppSec Program for Universities, Governments, and Standards Bodies
 * Certification
 * Outreach to Educational Institutions

The Codes of Conduct
The current versions (all now Stable Release Quality) are listed below. See each tab for more project details or read the summary pamphlet (English version and ) and presentation.

{| width="100%" cellspacing="20" cellpadding="10"
 * - valign="top"
 * width="33%" style="background:#e6f5e9" |

OWASP Green Book
The OWASP Application Security Code of Conduct for Government Bodies

Download the current release

v1.17 Release:


 * [[Media:OWASP_Green_Book-Governmental_Bodies.pdf|English version PDF]]
 * [[Media:OWASP_Green_Book-Governmental_Bodies.docx|English version MS Word]]

Translations

None are currently available.


 * width="33%" style="background:#e6eef6" |

OWASP Blue Book
The OWASP Application Security Code of Conduct for Educational Institutions

Download the current release

v1.17 Release:


 * [[Media:OWASP_Blue_Book-Educational_Institutions.pdf|English version PDF]]
 * [[Media:OWASP_Blue_Book-Educational_Institutions.docx|English version MS Word]]

Translations

None are currently available.


 * width="33%" style="background:#fafcdb" |

OWASP Yellow Book
The OWASP Application Security Code of Conduct for Standards Groups

Download the current release

v1.17 Release:


 * [[Media:OWASP_Yellow_Book-Standards_Groups.pdf|English version PDF]]
 * [[Media:OWASP_Yellow_Book-Standards_Groups.docx|English version MS Word]]

Translations

None are currently available.


 * - valign="top"
 * style="background:#ecdcfd" |

OWASP Purple Book
The OWASP Application Security Code of Conduct for Trade Organizations

Download the current release

v1.17 Release:


 * [[Media:OWASP_Purple_Book-Trade_Organizations.pdf|English version PDF]]
 * [[Media:OWASP_Purple_Book-Trade_Organizations.docx|English version MS Word]]

Translations

None are currently available. Can you help?


 * style="background:#f1d8d7" |

OWASP Red Book
The OWASP Application Security Code of Conduct for Certifying Bodies

Download the current release

v1.17 Release:


 * [[Media:OWASP_Red_Book-Certifying_Bodies.pdf|English version PDF]]
 * [[Media:OWASP_Red_Book-Certifying_Bodies.docx|English version MS Word]]

Translations

None are currently available.


 * style="background:#cccccc" |

OWASP Gray Book
The OWASP Application Security Code of Conduct for Development Organizations

Download the current release

v1.17 Release:


 * [[Media:OWASP_Gray_Book-Development_Organizations.pdf‎|English version PDF]]
 * [[Media:OWASP_Gray_Book-Development_Organizations.docx|English version MS Word]]

Translations

None are currently available.


 * }

{| style="padding:0;margin:0;margin-top:10px;text-align:left;"
 * valign="top" width="67%" style="padding-right:25px;" |
 * valign="top" width="67%" style="padding-right:25px;" |

What's Missing?
What other types of organization might be able to support OWASP's mission? What are the most important things they should do?

Join in the OWASP Codes of Conduct Mailing List with your suggestions and feedback.

Statements of Compliance
The implications and format of any statements of compliance is currently being discussed on the Codes of Conduct Project mailing list. The thread starts here.

Project Details
Click on the other tabs to see project information on each of the codes, including contributors, releases, assessment status and prior versions. All the Codes are discussed on a single shared mailing list. It is free and open.

Licensing
The OWASP Codes of Conduct are free to use. It is licensed under the Creative Commons Attribution-ShareAlike 3.0 license, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.

&copy; OWASP Foundation


 * valign="top" width="33%" |

Aggregated Book
There is also an aggregated booklet format (English version ) incorporating all six. This is also available to buy at cost printed in colour from Lulu.com.




 * valign="top" |
 * valign="top" |

Lost? Not What You Were Looking For?
These Codes relate to OWASP's aspirations for other types of organization. If you were looking for OWASP internal strategic and operational policies and processes, you might want to look at some of the following. They are not part of the OWASP Codes of Conduct Project.


 * OWASP Core Values, Core Purpose, Code of Ethics and Principles
 * Brand usage
 * By-laws
 * General disclaimer
 * Projects
 * Projects Handbook (coming soon)
 * Local Chapters
 * Chapter Handbook
 * Speaker Agreement
 * Finance
 * Conferences
 * Speaker Agreement
 * Training Instructor Agreement
 * All Global Conferences Committee Policies
 * Privacy


 * valign="top" |

Classifications

 * }

= Government Bodies =

= Educational Institutions =

= Standards Groups =

=Trade Organizations =

= Certifying Bodies =

= Development Organizations =