<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/index.php?action=history&amp;feed=atom&amp;title=Baseline_Assessor_Qual_and_Eval_Criteria</id>
		<title>Baseline Assessor Qual and Eval Criteria - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/index.php?action=history&amp;feed=atom&amp;title=Baseline_Assessor_Qual_and_Eval_Criteria"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Baseline_Assessor_Qual_and_Eval_Criteria&amp;action=history"/>
		<updated>2026-04-05T10:38:38Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Baseline_Assessor_Qual_and_Eval_Criteria&amp;diff=219745&amp;oldid=prev</id>
		<title>Johanna Curiel at 21:50, 30 July 2016</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Baseline_Assessor_Qual_and_Eval_Criteria&amp;diff=219745&amp;oldid=prev"/>
				<updated>2016-07-30T21:50:03Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;tr style='vertical-align: top;' lang='en'&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 21:50, 30 July 2016&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot; &gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;{{taggedDocument&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;| type=old&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;| lastRevision=2016-06-31&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;| comment=The page should be updated.&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;}}&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;This project article’s focus is to establish common set of assessor qualifications and evaluation criteria to facilitate end service user ability to determine competence per assessment type.&amp;#160; Agreement and establishment of these qualifications and criteria are foundational to establishing the Assessment Levels later within this project.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;This project article’s focus is to establish common set of assessor qualifications and evaluation criteria to facilitate end service user ability to determine competence per assessment type.&amp;#160; Agreement and establishment of these qualifications and criteria are foundational to establishing the Assessment Levels later within this project.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Johanna Curiel</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Baseline_Assessor_Qual_and_Eval_Criteria&amp;diff=9665&amp;oldid=prev</id>
		<title>Cbarlow at 17:30, 13 September 2006</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Baseline_Assessor_Qual_and_Eval_Criteria&amp;diff=9665&amp;oldid=prev"/>
				<updated>2006-09-13T17:30:54Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;This project article’s focus is to establish common set of assessor qualifications and evaluation criteria to facilitate end service user ability to determine competence per assessment type.  Agreement and establishment of these qualifications and criteria are foundational to establishing the Assessment Levels later within this project.&lt;br /&gt;
&lt;br /&gt;
== Baseline Assessor Qualifications for Expert Testing ==&lt;br /&gt;
&lt;br /&gt;
Prior to hiring a firm or before hiring internally, verify and ensure on individual basis each Assessor has the following skills:&lt;br /&gt;
* 4+ years of technical security experience with multiple computer platforms, operating systems, software products, network protocols and system architecture.  &lt;br /&gt;
* Knowledge of security architecture methodologies, industry best practices and generally accepted information security principles. &lt;br /&gt;
* Demonstrated ability to secure (lock-down/harden) underlying operating systems and web services such as IIS or Apache – Thus inverse ability to break into insecure systems.&lt;br /&gt;
* Demonstrated experience in designing and integrating security services (authentication, authorization, encryption, integrity, and non-repudiation) into systems and/or applications. &lt;br /&gt;
** Demonstrated ability to recognize MD5 from Base64 from an encrypted value visually.  (Example to demonstrate depth of knowledge in encryption)&lt;br /&gt;
* Demonstrated experience in conducting vulnerability assessments and penetration testing – Seen as foundational skills to application level testing.&lt;br /&gt;
** Demonstrated evidence of vulnerability discoveries (new undiscovered vulnerability).&lt;br /&gt;
** Demonstrated ability to interpret a generated report from vulnerability scanners and quickly recognize potential false positives.&lt;br /&gt;
** Able to demonstrate any exploit used during a test if requested by a client.&lt;br /&gt;
* Solid understanding and experience in Web application and Internet security.&lt;br /&gt;
* Solid, in-depth understanding of all Internet and Web protocols.&lt;br /&gt;
* Full understanding of major HTML directives and code.&lt;br /&gt;
* Knowledge of Service Oriented Architectures (SOA) and SOAP if applicable to environment.&lt;br /&gt;
* Demonstrated ability to reverse engineer a transactional web application.&lt;br /&gt;
* Produces own security tools known in reputable security circles.  Ability to shell code to automate custom tests.&lt;br /&gt;
* Demonstrated use of testing methodologies defined in OWASP Testing Project – Ask for specific testing process used for three or more testing areas.&lt;br /&gt;
* Demonstrated ability to create and follow a project specific well documented test plan.&lt;br /&gt;
* Programming / web services development experience a benefit.  However, not all programmers make good security testers (it’s a mindset thing).&lt;br /&gt;
* Demonstrated ability to formulate written technical material in a clear and effective manner – Ask for writing sample.&lt;br /&gt;
&lt;br /&gt;
Assessors identify and exploit security weaknesses, evaluate counter-measures and conduct analysis to determine potential security impacts to business.  More so, the assessor must demonstrate ability to take assessment data and formulate security technical solutions.  &lt;br /&gt;
&lt;br /&gt;
The following education and/or certifications are helpful and increase the viability of the Assessor (establishes their business foundation skills thus ability to link technical results to business impact) but should not be taken as sole means for evaluating.&lt;br /&gt;
* Undergraduate degree in Computer Science, Information Systems, Engineering, or related discipline&lt;br /&gt;
* CISSP or CCNA or GIAC certifications &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Evaluation Criteria'''&lt;br /&gt;
&lt;br /&gt;
The following matrix is intended to summarize the skills required per assessment level. &lt;br /&gt;
&lt;br /&gt;
''…[To Be Developed After Assessment Levels Established]''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Application Security Assessment Standards Project]]&lt;br /&gt;
{{Template:Stub}}&lt;/div&gt;</summary>
		<author><name>Cbarlow</name></author>	</entry>

	</feed>