This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "OWASP Security Frameworks Project"

From OWASP
Jump to: navigation, search
(removing empty FAQ, adding content)
 
(7 intermediate revisions by 2 users not shown)
Line 1: Line 1:
 
=Main=
 
=Main=
 
+
<!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE -->
<div style="width:100%;height:160px;border:0,margin:0;overflow: hidden;">[[File:OWASP_Project_Header.jpg|link=]]</div>
+
<div style="width:100%;height:100px;border:0,margin:0;overflow: hidden;">[[Image:OWASP Inactive Banner.jpg|800px| link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Inactive_Projects]] </div>
  
 
{| style="padding: 0;margin:0;margin-top:10px;text-align:left;" |-
 
{| style="padding: 0;margin:0;margin-top:10px;text-align:left;" |-
Line 23: Line 23:
  
 
| valign="top"  style="padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;" |
 
| valign="top"  style="padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;" |
 
+
<!--
 
== What is the OWASP Security Frameworks Project? ==
 
== What is the OWASP Security Frameworks Project? ==
  
Line 36: Line 36:
 
Link to presentation
 
Link to presentation
  
 
+
-->
  
  
Line 46: Line 46:
 
== Related Projects ==
 
== Related Projects ==
  
* [[OWASP_CISO_Survey]]
+
* [[Cheat Sheets]]
* [[Cheat_Sheets]]
+
* [[OWASP Framework Security Project]]
 
 
  
 
| valign="top"  style="padding-left:25px;width:200px;" |  
 
| valign="top"  style="padding-left:25px;width:200px;" |  
 
+
<!--
 
== Quick Download ==
 
== Quick Download ==
  
 
* Link to page/download when ready
 
* Link to page/download when ready
 
+
-->
  
  
 
== News and Events ==
 
== News and Events ==
* [22 Nov 2014] Project initiated
+
* [22 Feb 2014] Project initiated
  
  
Line 84: Line 83:
 
=Security Frameworks=
 
=Security Frameworks=
 
List of guides:
 
List of guides:
* [[Data access]]
+
* [[Data Access Framework]]
 
* Password Storage
 
* Password Storage
* Authentication
+
* Authentication Framework
* Session Management
+
* [[Session Management Framework]]
* Handling Output
+
* Framework for Handling Output
 
* [[Security Headers]]
 
* [[Security Headers]]
  

Latest revision as of 05:15, 13 February 2016

OWASP Inactive Banner.jpg

OWASP Security Frameworks

The OWASP Security Frameworks Project is a series of design patterns that can be used by language designers and architects to create secure frameworks for developers, thereby relieving developers of the work of implementing security themselves.

Introduction

Providing a secure environment to a developer will lead to a more secure final product. Developers need to work in an environment which is secure by default and which relieves them of the burden of implementing their own security controls. That task often falls to the developers who create languages, or enterprise architects. We aim to create a library of design patterns and instructions that should be implemented by architects to create secure languages and environments for developers.

Description

The project aims to provide language independent advice targeted at enterprise architects and people who design programming languages. The intent is to make security functionality a part of the framework that a developer builds upon, so that the developer doesn't have to implement their own security functions. The ultimate goal is to have as much security as possible built into the programming environment so that developer mistakes and omissions are less likely to lead to security vulnerabilities.

Licensing

The OWASP Security Framework is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.



Project Leader

Ari Elias-Bachrach


Related Projects


News and Events

  • [22 Feb 2014] Project initiated


In Print

This project can be purchased as a print on demand book from Lulu.com


Classifications

Owasp-incubator-trans-85.png Owasp-builders-small.png
Owasp-defenders-small.png
Cc-button-y-sa-small.png
Project Type Files DOC.jpg