Difference between revisions of "OWASP Codes of Conduct"

From OWASP
Jump to: navigation, search
m (Testing anchor tags)
(29 intermediate revisions by 3 users not shown)
Line 1: Line 1:
==== Main  ====
+
= Main  =
 
===Project's Purpose ===
 
===Project's Purpose ===
 
[Page currently being put together, CW 15th June 2011]
 
  
 
OWASP needs to take advantage of every opportunity to affect software development everywhere to achieve our mission "to make application security visible so that people and organizations can make informed decisions about application security risks"
 
OWASP needs to take advantage of every opportunity to affect software development everywhere to achieve our mission "to make application security visible so that people and organizations can make informed decisions about application security risks"
Line 8: Line 6:
 
At the [[Summit 2011]] in Portugal, the idea was created to try to influence educational institutions, government bodies, standards groups, and trade organizations. We set out to define a set of minimal requirements for these organizations specifying what we believe to be the most effective ways to support our mission. We call these requirements a “code of conduct” to imply that these are normative standards, they represent a minimum baseline, and that they are not difficult to achieve.
 
At the [[Summit 2011]] in Portugal, the idea was created to try to influence educational institutions, government bodies, standards groups, and trade organizations. We set out to define a set of minimal requirements for these organizations specifying what we believe to be the most effective ways to support our mission. We call these requirements a “code of conduct” to imply that these are normative standards, they represent a minimum baseline, and that they are not difficult to achieve.
  
This project develops and maintains OWASP Codes of Conduct, and began with those initially created at the working sessions on [[:Summit 2011 Working Sessions/Session255|Defining a Minimal AppSec Program for Universities, Governments, and Standards Bodies]] and [[:Summit 2011 Working Sessions/Session039|Certification]] at the 2011 OWASP Summit in Portugal.
+
This project develops and maintains OWASP Codes of Conduct, and began with those initially created at the following working sessions at the 2011 OWASP Summit:
 +
* [[:Summit 2011 Working Sessions/Session255|Defining a Minimal AppSec Program for Universities, Governments, and Standards Bodies]]
 +
* [[:Summit 2011 Working Sessions/Session039|Certification]]  
 +
* [[:Summit 2011 Working Sessions/Session012|Outreach to Educational Institutions]]
  
 +
===The Codes of Conduct===
  
===The Codes of Conduct===
+
The current versions (all now Stable Release Quality) are listed below.  See each tab for more project details or read the summary pamphlet (English version [https://www.owasp.org/index.php/File:OWASP_Codes-of-Conduct_Pamphlet.pdf PDF] and [https://www.owasp.org/index.php/File:OWASP_Codes-of-Conduct_Pamphlet.docx MS Word]) and [http://www.appsecusa.org/p/codesofconduct.pdf presentation].  The Codes of Conduct are all licensed with a [http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution ShareAlike 3.0 license].
  
 
{| width="100%" cellspacing="20" cellpadding="10"
 
{| width="100%" cellspacing="20" cellpadding="10"
Line 22: Line 24:
 
'''Download the current release'''
 
'''Download the current release'''
  
v1.0 draft:
+
v1.17 Release:
  
* English version PDF
+
* [[Media:OWASP_Green_Book-Governmental_Bodies.pdf|English version PDF]]
* English version MS Word
+
* [[Media:OWASP_Green_Book-Governmental_Bodies.docx|English version MS Word]]
  
 
'''Translations'''
 
'''Translations'''
Line 33: Line 35:
  
 
| width="33%" style="background:#e6eef6" |
 
| width="33%" style="background:#e6eef6" |
 +
 
== OWASP Blue Book ==
 
== OWASP Blue Book ==
  
Line 39: Line 42:
 
'''Download the current release'''
 
'''Download the current release'''
  
v1.0 draft:
+
v1.17 Release:
  
* English version PDF
+
* [[Media:OWASP_Blue_Book-Educational_Institutions.pdf|English version PDF]]
* English version MS Word
+
* [[Media:OWASP_Blue_Book-Educational_Institutions.docx|English version MS Word]]
  
 
'''Translations'''
 
'''Translations'''
Line 50: Line 53:
  
 
| width="33%" style="background:#fafcdb" |
 
| width="33%" style="background:#fafcdb" |
 +
 
== OWASP Yellow Book ==
 
== OWASP Yellow Book ==
  
Line 56: Line 60:
 
'''Download the current release'''
 
'''Download the current release'''
  
v1.0 draft:
+
v1.17 Release:
  
* English version PDF
+
* [[Media:OWASP_Yellow_Book-Standards_Groups.pdf|English version PDF]]
* English version MS Word
+
* [[Media:OWASP_Yellow_Book-Standards_Groups.docx|English version MS Word]]
  
 
'''Translations'''
 
'''Translations'''
Line 68: Line 72:
 
|- valign="top"
 
|- valign="top"
 
| style="background:#ecdcfd" |
 
| style="background:#ecdcfd" |
 +
 
== OWASP Purple Book ==
 
== OWASP Purple Book ==
  
Line 74: Line 79:
 
'''Download the current release'''
 
'''Download the current release'''
  
v1.0 draft:
+
v1.17 Release:
  
* English version PDF
+
* [[Media:OWASP_Purple_Book-Trade_Organizations.pdf|English version PDF]]
* English version MS Word
+
* [[Media:OWASP_Purple_Book-Trade_Organizations.docx|English version MS Word]]
  
 
'''Translations'''
 
'''Translations'''
Line 85: Line 90:
  
 
| style="background:#f1d8d7" |
 
| style="background:#f1d8d7" |
 +
 
== OWASP Red Book ==
 
== OWASP Red Book ==
  
Line 91: Line 97:
 
'''Download the current release'''
 
'''Download the current release'''
  
v1.0 draft:
+
v1.17 Release:
  
* English version PDF
+
* [[Media:OWASP_Red_Book-Certifying_Bodies.pdf|English version PDF]]
* English version MS Word
+
* [[Media:OWASP_Red_Book-Certifying_Bodies.docx|English version MS Word]]
  
 
'''Translations'''
 
'''Translations'''
Line 100: Line 106:
 
None are currently available.
 
None are currently available.
  
| style="background:#ffffff" |
+
| style="background:#cccccc" |
== What's missing? ==
+
 
 +
== OWASP Gray Book ==
 +
 
 +
''The OWASP Application Security Code of Conduct for Development Organizations''
 +
 
 +
'''Download the current release'''
 +
 
 +
v1.17 Release:
 +
 
 +
* [[Media:OWASP_Gray_Book-Development_Organizations.pdf‎|English version PDF]]
 +
* [[Media:OWASP_Gray_Book-Development_Organizations.docx|English version MS Word]]
 +
 
 +
'''Translations'''
 +
 
 +
None are currently available.
  
What other types of organization might be able to support OWASP's mission?  What are the most important things they should do?
 
  
Join in the [https://lists.owasp.org/mailman/listinfo/owasp-codes-of-conduct OWASP Codes of Conduct Mailing List] with your suggestions and feedback.
 
  
 
|}
 
|}
  
The Codes of Conduct are all licensed with a [http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution ShareAlike 3.0 license].
+
=== <div id="missing">What's missing?</div> ===
 +
 
 +
What other types of organization might be able to support OWASP's mission?  What are the most important things they should do?
 +
 
 +
Join in the [https://lists.owasp.org/mailman/listinfo/owasp-codes-of-conduct OWASP Codes of Conduct Mailing List] with your suggestions and feedback.
 +
 
 +
=== <div id="compliance">Statements of Compliance</div> ===
  
 +
The implications and format of any statements of compliance is currently being discussed on the Codes of Conduct Project mailing list.  The [https://lists.owasp.org/pipermail/owasp-codes-of-conduct/2011-September/000012.html thread starts here].
  
 
===Project Details===
 
===Project Details===
  
Click on the other tabs to see project information on each of the codes, including contributors, releases, assessment status and prior versions.  All the Codes are discussed on a single shared mailing list.  It is free and open.
+
Click on the other tabs to see project information on each of the codes, including contributors, releases, assessment status and prior versions.  All the Codes are discussed on a single shared [https://lists.owasp.org/mailman/listinfo/owasp-codes-of-conduct mailing list].  It is free and open.
  
  
==== Government Bodies ====
+
===Lost? Not What You Were Looking For?===
<span id="Green Book"></span>
+
 
 +
These Codes relate to OWASP's aspirations for other types of organization.  If you were looking for OWASP internal strategic and operational policies and processes, you might want to look at some of the following.  They are ''not'' part of the OWASP Codes of Conduct Project.
 +
 
 +
* [[:About OWASP|OWASP Core Values, Core Purpose, Code of Ethics and Principles]]
 +
** [[:OWASP brand usage rules|Brand usage]]
 +
** [[:File:2012ByLawsFINAL.pdf|By-laws]]
 +
** [[:OWASP:General disclaimer|General disclaimer]]
 +
* Projects
 +
** Projects Handbook (coming soon)
 +
* Local Chapters
 +
** [[:Category:Chapter Handbook|Chapter Handbook]]
 +
** [[:Speaker Agreement|Speaker Agreement]]
 +
** [[:Chapter Finance Policy and Procedure|Finance]]
 +
* Conferences
 +
** [[:Speaker Agreement|Speaker Agreement]]
 +
** [[:File:Training Instructor Agreement.doc|Training Instructor Agreement]]
 +
** [[:Global Conferences Committee/Policies|All Global Conferences Committee Policies]]
 +
* [[:OWASP:Privacy policy|Privacy]]
 +
 
 +
=  Government Bodies =
 
{{:Projects/The OWASP "Green Book" | Project About}}
 
{{:Projects/The OWASP "Green Book" | Project About}}
  
==== Educational Institutions ====
+
= Educational Institutions =
<span id="Blue Book"></span>
+
 
{{:Projects/The OWASP "Blue Book" | Project About}}  
 
{{:Projects/The OWASP "Blue Book" | Project About}}  
  
==== Standards Groups ====
+
= Standards Groups =
 
{{:Projects/The OWASP "Yellow Book" | Project About}}  
 
{{:Projects/The OWASP "Yellow Book" | Project About}}  
  
==== Trade Organizations ====
+
=Trade Organizations =
 
{{:Projects/The OWASP "Purple Book" | Project About}}  
 
{{:Projects/The OWASP "Purple Book" | Project About}}  
  
==== Certifying Bodies ====
+
= Certifying Bodies =
 
{{:Projects/The OWASP "Red Book" | Project About}}  
 
{{:Projects/The OWASP "Red Book" | Project About}}  
 +
 +
= Development Organizations =
 +
{{:Projects/The OWASP "Gray Book" | Project About}}
  
 
<!---==== Project About  ====
 
<!---==== Project About  ====
Line 141: Line 187:
 
__NOTOC__ <headertabs />  
 
__NOTOC__ <headertabs />  
  
[[Category:OWASP_Project|Codes of Conduct]] [[Category:OWASP_Document]] [[Category:OWASP_Download]] [[Category:OWASP_Alpha_Quality_Document]]
+
[[Category:OWASP_Project|Codes of Conduct]] [[Category:OWASP_Document]] [[Category:OWASP_Download]] [[Category:OWASP_Release_Quality_Document]]

Revision as of 14:56, 27 March 2013

[edit]

Project's Purpose

OWASP needs to take advantage of every opportunity to affect software development everywhere to achieve our mission "to make application security visible so that people and organizations can make informed decisions about application security risks"

At the Summit 2011 in Portugal, the idea was created to try to influence educational institutions, government bodies, standards groups, and trade organizations. We set out to define a set of minimal requirements for these organizations specifying what we believe to be the most effective ways to support our mission. We call these requirements a “code of conduct” to imply that these are normative standards, they represent a minimum baseline, and that they are not difficult to achieve.

This project develops and maintains OWASP Codes of Conduct, and began with those initially created at the following working sessions at the 2011 OWASP Summit:

The Codes of Conduct

The current versions (all now Stable Release Quality) are listed below. See each tab for more project details or read the summary pamphlet (English version PDF and MS Word) and presentation. The Codes of Conduct are all licensed with a Creative Commons Attribution ShareAlike 3.0 license.

OWASP Green Book

The OWASP Application Security Code of Conduct for Government Bodies

Download the current release

v1.17 Release:

Translations

None are currently available.


OWASP Blue Book

The OWASP Application Security Code of Conduct for Educational Institutions

Download the current release

v1.17 Release:

Translations

None are currently available.


OWASP Yellow Book

The OWASP Application Security Code of Conduct for Standards Groups

Download the current release

v1.17 Release:

Translations

None are currently available.


OWASP Purple Book

The OWASP Application Security Code of Conduct for Trade Organizations

Download the current release

v1.17 Release:

Translations

None are currently available.


OWASP Red Book

The OWASP Application Security Code of Conduct for Certifying Bodies

Download the current release

v1.17 Release:

Translations

None are currently available.

OWASP Gray Book

The OWASP Application Security Code of Conduct for Development Organizations

Download the current release

v1.17 Release:

Translations

None are currently available.


What's missing?

What other types of organization might be able to support OWASP's mission? What are the most important things they should do?

Join in the OWASP Codes of Conduct Mailing List with your suggestions and feedback.

Statements of Compliance

The implications and format of any statements of compliance is currently being discussed on the Codes of Conduct Project mailing list. The thread starts here.

Project Details

Click on the other tabs to see project information on each of the codes, including contributors, releases, assessment status and prior versions. All the Codes are discussed on a single shared mailing list. It is free and open.


Lost? Not What You Were Looking For?

These Codes relate to OWASP's aspirations for other types of organization. If you were looking for OWASP internal strategic and operational policies and processes, you might want to look at some of the following. They are not part of the OWASP Codes of Conduct Project.

PROJECT INFO
What does this OWASP project offer you?
RELEASE(S) INFO
What releases are available for this project?
what is this project?
Name: The OWASP "Green Book" (home page)
Purpose: This effort envisages to create and maintain The OWASP Application Security Code of Conduct for Government Bodies/The OWASP "Green Book".
License: Creative Commons Attribution ShareAlike 3.0 license
who is working on this project?
Project Leader(s):
Project Contributor(s):
how can you learn more?
Project Pamphlet: View
Project Presentation: View
Mailing list: Mailing List Archives
Project Roadmap: View
Main links:
Key Contacts
  • Contact the GPC to report a problem or concern about this project or to update information.
current release
The OWASP "Green Book" v1.1 - March 27, 2013 - (download)
Release description: This effort publishes a release version of The OWASP Application Security Code of Conduct for Government Bodies/The OWASP "Green Book", version v1.1
Rating: Greenlight.pngGreenlight.pngGreenlight.png Stable Release - Assessment Details
last reviewed release
The OWASP "Green Book" v1.1 - March 27, 2013 - (download)
Release description: This effort publishes a release version of The OWASP Application Security Code of Conduct for Government Bodies/The OWASP "Green Book", version v1.1

This release includes the following significant changes:

  • Formal review
Rating: Greenlight.pngGreenlight.pngGreenlight.png Stable Release - Assessment Details


other releases

PROJECT INFO
What does this OWASP project offer you?
RELEASE(S) INFO
What releases are available for this project?
what is this project?
Name: The OWASP "Blue Book" (home page)
Purpose: This effort envisages to create and maintain The OWASP Application Security Code of Conduct for Educational Institutions/The OWASP "Blue Book".
License: Creative Commons Attribution ShareAlike 3.0 license
who is working on this project?
Project Leader(s):
Project Contributor(s):
how can you learn more?
Project Pamphlet: View
Project Presentation: View
Mailing list: Mailing List Archives
Project Roadmap: View
Main links:
Key Contacts
  • Contact the GPC to report a problem or concern about this project or to update information.
current release
The OWASP "Blue Book" v1.1 - March 27, 2013 - (download)
Release description: This effort publishes a release version of The OWASP Application Security Code of Conduct for Educational Institutions/The OWASP "Blue Book", version v1.1.
Rating: Greenlight.pngGreenlight.pngGreenlight.png Stable Release - Assessment Details
last reviewed release
The OWASP "Blue Book" v1.1 - March 27, 2013 - (download)
Release description: This effort publishes a release version of The OWASP Application Security Code of Conduct for Government Bodies/The OWASP "Green Book", version v1.1

This release includes the following significant changes:

  • Formal review
Rating: Greenlight.pngGreenlight.pngGreenlight.png Stable Release - Assessment Details


other releases

PROJECT INFO
What does this OWASP project offer you?
RELEASE(S) INFO
What releases are available for this project?
what is this project?
Name: The OWASP "Yellow Book" (home page)
Purpose: This effort envisages to create and maintain The OWASP Application Security Code of Conduct for Standards Groups/The OWASP "Yellow Book".
License: Creative Commons Attribution ShareAlike 3.0 license
who is working on this project?
Project Leader(s):
Project Contributor(s):
how can you learn more?
Project Pamphlet: View
Project Presentation: View
Mailing list: Mailing List Archives
Project Roadmap: View
Main links:
Key Contacts
  • Contact the GPC to report a problem or concern about this project or to update information.
current release
The OWASP "Yellow Book" v1.1 - March 27, 2013 - (download)
Release description: This effort publishes a release version of The OWASP Application Security Code of Conduct for Standards Groups/The OWASP "Yellow Book", version v1.1.
Rating: Greenlight.pngGreenlight.pngGreenlight.png Stable Release - Assessment Details
last reviewed release
The OWASP "Yellow Book" v1.1 - March 27, 2013 - (download)
Release description: This effort publishes a release version of The OWASP Application Security Code of Conduct for Government Bodies/The OWASP "Green Book", version v1.1

This release includes the following significant changes:

  • Formal review
Rating: Greenlight.pngGreenlight.pngGreenlight.png Stable Release - Assessment Details


other releases

PROJECT INFO
What does this OWASP project offer you?
RELEASE(S) INFO
What releases are available for this project?
what is this project?
Name: The OWASP "Purple Book" (home page)
Purpose: This effort envisages to create and maintain The OWASP Application Security Code of Conduct for Trade Organizations/The OWASP "Purple Book".
License: Creative Commons Attribution ShareAlike 3.0 license
who is working on this project?
Project Leader(s):
how can you learn more?
Project Pamphlet: View
Project Presentation: View
Mailing list: Mailing List Archives
Project Roadmap: View
Key Contacts
  • Contact the GPC to report a problem or concern about this project or to update information.
current release
The OWASP "Purple Book" v1.1 - March 27, 2013 - (download)
Release description: This effort publishes a release version of The OWASP Application Security Code of Conduct for Trade Organizations/The OWASP "Purple Book", version v1.1.
Rating: Greenlight.pngGreenlight.pngGreenlight.png Stable Release - Assessment Details
last reviewed release
The OWASP "Purple Book" v1.1 - March 27, 2013 - (download)
Release description: This effort publishes a release version of The OWASP Application Security Code of Conduct for Government Bodies/The OWASP "Green Book", version v1.1

This release includes the following significant changes:

  • Formal review
Rating: Greenlight.pngGreenlight.pngGreenlight.png Stable Release - Assessment Details


other releases

PROJECT INFO
What does this OWASP project offer you?
RELEASE(S) INFO
What releases are available for this project?
what is this project?
Name: The OWASP "Red Book" (home page)
Purpose: This effort envisages to create and maintain The OWASP Application Security Code of Conduct for Certifying Bodies/The OWASP "Red Book".
License: Creative Commons Attribution ShareAlike 3.0 license
who is working on this project?
Project Leader(s):
Project Contributor(s):
how can you learn more?
Project Pamphlet: View
Project Presentation: View
Mailing list: Mailing List Archives
Project Roadmap: View
Main links:
Key Contacts
  • Contact the GPC to report a problem or concern about this project or to update information.
current release
The OWASP "Red Book" v1.1 - March 27, 2013 - (download)
Release description: This effort publishes a release version of The OWASP Application Security Code of Conduct for Certifying Bodies/The OWASP "Red Book", Version v1.1.
Rating: Greenlight.pngGreenlight.pngGreenlight.png Stable Release - Assessment Details
last reviewed release
The OWASP "Red Book" v1.1 - March 27, 2013 - (download)
Release description: This effort publishes a release version of The OWASP Application Security Code of Conduct for Government Bodies/The OWASP "Green Book", version v1.1

This release includes the following significant changes:

  • Formal review
Rating: Greenlight.pngGreenlight.pngGreenlight.png Stable Release - Assessment Details


other releases

PROJECT INFO
What does this OWASP project offer you?
RELEASE(S) INFO
What releases are available for this project?
what is this project?
Name: The OWASP "Gray Book" (home page)
Purpose: This effort envisages to create and maintain The OWASP Application Security Code of Conduct for Development Organizations/The OWASP "Gray Book".
License: Creative Commons Attribution ShareAlike 3.0 license
who is working on this project?
Project Leader(s):
Project Contributor(s):
how can you learn more?
Project Pamphlet: View
Project Presentation: View
Mailing list: Mailing List Archives
Project Roadmap: View
Key Contacts
  • Contact the GPC to report a problem or concern about this project or to update information.
current release
The OWASP "Gray Book" v1.1 - March 27, 2013 - (download)
Release description: This effort publishes a release version of The OWASP Application Security Code of Conduct for Development Organizations/The OWASP "Gray Book", version v1.1
Rating: Greenlight.pngGreenlight.pngGreenlight.png Stable Release - Assessment Details
last reviewed release
The OWASP "Gray Book" v1.1 - March 27, 2013 - (download)
Release description: This effort publishes a release version of The OWASP Application Security Code of Conduct for Government Bodies/The OWASP "Green Book", version v1.1

This release includes the following significant changes:

  • Formal review
Rating: Greenlight.pngGreenlight.pngGreenlight.png Stable Release - Assessment Details


other releases