This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "Category:OWASP Top Ten Project"

From OWASP
Jump to: navigation, search
m (Highlighted the date of the final release in yellow.)
(Preparing for 2017 release...)
Line 4: Line 4:
 
| valign="top"  style="border-right: 1px dotted gray;padding-right:25px;" |
 
| valign="top"  style="border-right: 1px dotted gray;padding-right:25px;" |
  
== OWASP Top 10 2017 GM Released==
+
== OWASP Top 10 2017 Released==
The 'Golden Master' is now [[Media:OWASP_Top_10_2017_GM_(en).pdf | available for download]]. The final comes out <span style="background:yellow;"><b>20  November, 2017</b></span>. This is the last chance to review carefully and log issues at [https://github.com/OWASP/Top10/issues GitHub].
+
The OWASP Top 10 - 2017 will be available for download on <span style="background:yellow;"><b>20  November, 2017</b></span>. We are asking for comments to be submitted on the project's [https://github.com/OWASP/Top10/issues GitHub issues].
  
== OWASP Top 10 2017 RC2 Released==
 
RC2 is now [https://github.com/OWASP/Top10/raw/master/2017/drafts/OWASP%20Top%2010%202017%20RC2%20Final.pdf available for download]. In an ongoing effort to be transparent, we are asking for all comments to be made on the project's [https://github.com/OWASP/Top10/issues GitHub issues list].
 
 
== OWASP Top 10 2017 - Industry survey open and data call completed==
 
 
* A big thank you to all industry professionals who completed this [https://goo.gl/forms/ltbKrdYrp4Qdl7Df2 <u>survey for new vulnerability categories</u>] to help determine up to two items in the 2017 Top 10. The deadline for the survey was 18 September, 2017.
 
* The data call for the 2017 Top 10 had been reopened, a bit thank you to all the contributors. The  [https://goo.gl/forms/tLgyvK9O74r7wMkt2 <u>call for data</u>] is now closed. The deadline for the extended data call was 18 September, 2017.
 
This [https://owasp.blogspot.com/2017/08/owasp-top-10-2017-project-update.html <u>OWASP blog posting</u>] describes the process in detail.
 
 
==OWASP Top 10 2017 – RC1 rejected==
 
 
During the [https://owaspsummit.org/website/ <u>OWASP Summit 2017</u>], several sessions took place discussing many different aspects of the OWASP Top 10, for example, governance and validation, the data collection process, data assessment and review of the new suggested A7 and A10.
 
Main [https://owaspsummit.org/Outcomes/Owasp-Top-10-2017/Owasp-Top-10-2017.html <u>outcomes of the OWASP Summit</u>] include:
 
* RC1 of the OWASP Top 10 2017 has been rejected
 
* A1, A2, A3, A4, A5, A6, A8, A9 have been left untouched by consensus view
 
* Requirement to choose two additional items (-> see OWASP Top 10 2017 - Industry survey open and data call reopened)
 
* Feedback on the mailing list has been moved to the [https://github.com/OWASP/Top10/issues <u>issues list</u>] in GitHub, please continue to contribute feedback there.
 
* The new OWASP Top 10 2017 is to be released in late November 2017.
 
* New project leadership put in place.
 
 
<!-- I think it makes sense just to delete this text - Neil Smithline
 
==OWASP Top 10 - 2017 Release Candidate ==
 
 
The release candidate for public comment was published 10 April 2017 and can be [https://github.com/OWASP/Top10/raw/master/2017/drafts/OWASP%20Top%2010%20-%202017%20RC1-English.pdf downloaded here]. OWASP plans to release the final OWASP Top 10 - 2017 in July or August 2017 after a public comment period ending June 30, 2017.
 
 
Constructive comments on this [https://github.com/OWASP/Top10/raw/master/2017/drafts/OWASP%20Top%2010%20-%202017%20RC1-English.pdf OWASP Top 10 - 2017 Release Candidate] should be forwarded via email to the [https://lists.owasp.org/mailman/listinfo/Owasp-topten OWASP Top 10 Project Email List]. Private comments may be sent to [mailto:vanderaj@owasp.org Andrew van der Stock]. Anonymous comments are welcome. All non-private comments will be catalogued and published at the same time as the final public release. Comments recommending changes to the Top 10 should include a complete suggested list of changes, along with a rationale for each change. All comments should indicate the specific relevant page and section.
 
 
-->
 
 
==OWASP Top 10 Most Critical Web Application Security Risks==
 
==OWASP Top 10 Most Critical Web Application Security Risks==
  
Line 52: Line 24:
 
The OWASP Top 10 is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.
 
The OWASP Top 10 is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.
  
 +
<!-- Do we really need this - Neil Smithline - 19 November 2017
 
{{Social Media Links}}
 
{{Social Media Links}}
 
| valign="top"  style="padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;" |
 
| valign="top"  style="padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;" |
 
+
-->
 
== What is the OWASP Top 10? ==
 
== What is the OWASP Top 10? ==
  
Line 67: Line 40:
 
* Guidance on how to avoid
 
* Guidance on how to avoid
 
* References to OWASP and other related resources
 
* References to OWASP and other related resources
 
== Project Leaders ==
 
 
* [[User:vanderaj | Andrew van der Stock]]
 
* [[User:Neil_Smithline | Neil Smithline]]
 
* [[User:T.Gigler | Torsten Gigler]]
 
* [[User:Brianglas | Brian Glas]]
 
  
 
== Related Projects ==
 
== Related Projects ==
Line 85: Line 51:
 
* [[OWASP_Top_10/Mapping_to_WHID | OWASP Top 10 Mapped to the Web Hacking Incident Database]]
 
* [[OWASP_Top_10/Mapping_to_WHID | OWASP Top 10 Mapped to the Web Hacking Incident Database]]
  
== Ohloh ==
+
== Project Sponsors ==
  
*https://www.ohloh.net/p/OWASP-Top-10
+
The OWASP Top 10 - 2017 project is sponsored by
 +
 
 +
{{MemberLinks|link=https://www.autodesk.com|logo=Autodesk-logo.png}}
 +
 
 +
Thanks to [https://www.aspectsecurity.com Aspect Security] for sponsoring earlier versions.
  
 
| valign="top"  style="padding-left:25px;width:200px;" |
 
| valign="top"  style="padding-left:25px;width:200px;" |
Line 110: Line 80:
 
* [12 Jun 2013] OWASP Top 10 - 2013 Final Released
 
* [12 Jun 2013] OWASP Top 10 - 2013 Final Released
 
* [Feb 2013] OWASP Top 10 - 2013 - Release Candidate Published
 
* [Feb 2013] OWASP Top 10 - 2013 - Release Candidate Published
 +
 +
== Project Leaders ==
 +
 +
* [[User:vanderaj | Andrew van der Stock]]
 +
* [[User:Brianglas | Brian Glas]]
 +
* [[User:Neil_Smithline | Neil Smithline]]
 +
* [[User:T.Gigler | Torsten Gigler]]
  
 
==Classifications==
 
==Classifications==

Revision as of 22:36, 19 November 2017

Flagship big.jpg

OWASP Top 10 2017 Released

The OWASP Top 10 - 2017 will be available for download on 20 November, 2017. We are asking for comments to be submitted on the project's GitHub issues.

OWASP Top 10 Most Critical Web Application Security Risks

The OWASP Top 10 is a powerful awareness document for web application security. It represents a broad consensus about the most critical security risks to web applications. Project members include a variety of security experts from around the world who have shared their expertise to produce this list.

We urge all companies to adopt this awareness document within their organization and start the process of ensuring that their web applications minimize these risks. Adopting the OWASP Top 10 is perhaps the most effective first step towards changing the software development culture within your organization into one that produces secure code.

Translation Efforts

The OWASP Top 10 has been translated to many different languages by numerous volunteers. These translations are available as follows:

Licensing

The OWASP Top 10 is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.

What is the OWASP Top 10?

The OWASP Top 10 provides:

  • A list of the 10 Most Critical Web Application Security Risks

For each Risk it provides:

  • A description
  • Example vulnerabilities
  • Example attacks
  • Guidance on how to avoid
  • References to OWASP and other related resources

Related Projects

Project Sponsors

The OWASP Top 10 - 2017 project is sponsored by

Autodesk-logo.png       

Thanks to Aspect Security for sponsoring earlier versions.

Quick Download

Get Involved

News and Events

  • [20 Oct 2017] OWASP Top 10 2017 RC2 Published
  • [11 Jul 2017] OWASP Top 10 2017 – The appeal for data and opinions is still open
  • [10 Apr 2017] OWAP Top 10 - 2017 Release Candidate Published
  • [17 Dec 2016] OWASP Top 10 - 2017 Data Call Data Published
  • [20 May 2016] OWASP Top 10 - 2017 Data Call Announced
  • [12 Jun 2013] OWASP Top 10 - 2013 Final Released
  • [Feb 2013] OWASP Top 10 - 2013 - Release Candidate Published

Project Leaders

Classifications

Owasp-flagship-trans-85.png Owasp-builders-small.png
Owasp-defenders-small.png
Cc-button-y-sa-small.png
Project Type Files DOC.jpg

Subcategories

This category has the following 2 subcategories, out of 2 total.

O

Pages in category "OWASP Top Ten Project"

The following 107 pages are in this category, out of 107 total.

T

Media in category "OWASP Top Ten Project"

The following 2 files are in this category, out of 2 total.