Getting Started

From OWASP
Revision as of 05:59, 29 March 2006 by Jeff Williams (Talk | contribs)

Jump to: navigation, search

Getting Started in Application Security

Contents

Application Security Overview

Drivers, market, business reasons. Links to articles about metrics, ROI, need for application security, what other companies are doing.

About Vulnerabilities

A writeup about application vulnerabilities and how to figure out their risk. This section would give people the background on the technologies and types of mistakes people make. Links to articles about:

 Design flaws and Implementation Bugs
 Common areas (Top 10)

Root Causes of Vulnerabilities

A writeup of how vulnerabilities get created and left undiscovered. This section points out weaknesses in most software development lifecycles. At a project level, this section talks about problems in staffing, roles, responsibilities, budget, and technology. At the organizational level, this section links to information about management structure, how to raise global organizataion awareness, establishing metrics, and standardizing technologies to help.

Project Improvements

A writeup of how application security fits into the software development lifecycle. The discussion would link to templates, tools, additional reading. (This is not intended to be a complete list (yet))

 Security Requirements
 Threat Modeling
 Architecture Review
 Code Review
 Penetration Testing
 Vulnerability Scanning
 Project Responsibility and Roles
 Budget

Organizational Improvements

The discussion would link to templates, tools, additional reading. (This is not intended to be a complete list (yet))

 Training and Awareness
 Application Security Teams (Infosec, Audit, Appsec, CSO)
 Metrics
 Policies
 Templates
 Standard Tools
 Legal
 Community of Interest
 Executive Responsibility and Roles
 Organizational Budget