<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/index.php?action=history&amp;feed=atom&amp;title=Talk%3AOWASP_RFP-Criteria</id>
		<title>Talk:OWASP RFP-Criteria - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/index.php?action=history&amp;feed=atom&amp;title=Talk%3AOWASP_RFP-Criteria"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Talk:OWASP_RFP-Criteria&amp;action=history"/>
		<updated>2026-04-19T16:04:40Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Talk:OWASP_RFP-Criteria&amp;diff=84951&amp;oldid=prev</id>
		<title>Brennan: Created page with 'PURPOSE &lt;br&gt; List of questions/discussion points for the project.&lt;br&gt;  (if your wondering how to add your comments to this and get involved.. create a account its FREE and its a …'</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Talk:OWASP_RFP-Criteria&amp;diff=84951&amp;oldid=prev"/>
				<updated>2010-06-16T05:00:25Z</updated>
		
		<summary type="html">&lt;p&gt;Created page with &amp;#039;PURPOSE &amp;lt;br&amp;gt; List of questions/discussion points for the project.&amp;lt;br&amp;gt;  (if your wondering how to add your comments to this and get involved.. create a account its FREE and its a …&amp;#039;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;PURPOSE &amp;lt;br&amp;gt; List of questions/discussion points for the project.&amp;lt;br&amp;gt; &lt;br /&gt;
(if your wondering how to add your comments to this and get involved.. create a account its FREE and its a wiki)&lt;br /&gt;
&lt;br /&gt;
* Proposed discussion and feedback from the Software Assurance (SwA) Community on June 22 at 3 pm with the SwA Acquisition and Outsourcing Working Group.  We are meeting at the Booz Allen Hamilton Virginia Square Facility at 3811 N. Fairfax Drive, Suite 600, Arlington, Virginia 22203. --[[User:Walter Houser|Walter Houser]] 17:59, 22 May 2010 (UTC) &amp;lt;br&amp;gt;&lt;br /&gt;
Answer: Unable to attend this event will be at [http://www.owasp.org/index.php/OWASP_AppSec_Research_2010_-_Stockholm,_Sweden OWASP Sweden] ----&lt;br /&gt;
&lt;br /&gt;
Are these questions for use during the market survey or product evaluation steps of an acquisition? --[[User:Walter Houser|Walter Houser]] 20:00, 16 April 2010 (UTC) &lt;br /&gt;
Answer: YES --[[User:Brennan|jinxpuppy]] 02:20, 26 May 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
1. Describe the implementation process for your product/service - is software or hardware required? Vendor training? Consulting? Any additional personnel costs on customer side? How many personnel are needed? What are their skill sets and experience levels. --[[User:Walter Houser|Walter Houser]] 20:16, 16 April 2010 (UTC) The time to implement is meaningful only in the context of the amount and quality of resources and their costs. &lt;br /&gt;
&lt;br /&gt;
2. Do you have a training and support program for your product or service? Is it required? If so, what is the typical amount of time and cost associated with training/education? --[[User:Walter Houser|Walter Houser]] 20:23, 16 April 2010 (UTC) The salesman will always answer yes to &amp;quot;Can you...?&amp;quot; questions. &lt;br /&gt;
Answer: This question was focused on the service offered that what training is required to operate it and what support programs are available &lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
4. What is the most challenging element ...? Too softball a question. --[[User:Walter Houser|Walter Houser]] 20:08, 16 April 2010 (UTC) Ask instead &lt;br /&gt;
&lt;br /&gt;
4. What are the critical success factors for ... &lt;br /&gt;
&lt;br /&gt;
Answer: Good need to dive deeper here for more questions and add to the list &lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
ADDITIONAL LINKS &amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
#http://zeltser.com/security-assessments/security-assessment-rfp-cheat-sheet.html&lt;br /&gt;
&lt;br /&gt;
5. Does the product/service integrate with any IPS solutions(custom filters)? [[User:Joe Aguirre|Joe Aguirre]] 20:10, 19 April 2010 (UTC) &lt;br /&gt;
+ Web Application Firewalls&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
6. Related to question #11, asking how &amp;quot;all existing vulnerabilities&amp;quot; are discovered may need to be revisited. It may make more sense to ask how the product/solution increases its vulnerability identification rate relative to the competition. [[User:Joe Aguirre|Joe Aguirre]] 20:10, 19 April 2010 (UTC) &lt;br /&gt;
Blackbox testing of custom code on a website is finding zero-day issues in a website that was designed for a single customer hence complete coverage of the attack surface needs to be clarified. &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
7. Some additional ideas that may be useful could be: options for user administration, supported federated identity management solutions, access control granularity, and scan scheduling. [[User:Joe Aguirre|Joe Aguirre]] 15:36, 20 April 2010 (UTC)&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
8. Question #25 - Instead of listing the WASC categories, it would be cleaner to provide links to both the WASC and OWASP Top Ten lists. [[User:Joe Aguirre|Joe Aguirre]] 20:44, 21 April 2010 (UTC)&lt;br /&gt;
Answer: [http://projects.webappsec.org/Threat-Classification WASC] is classes of attack OWASP is Top 10 Risks very different from a testing perspective.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;/div&gt;</summary>
		<author><name>Brennan</name></author>	</entry>

	</feed>