This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "OWASP Security Integration System"
From OWASP
MB netblue4 (talk | contribs) |
MB netblue4 (talk | contribs) |
||
Line 39: | Line 39: | ||
<h1><b>Problems the tool address</b></h1> | <h1><b>Problems the tool address</b></h1> | ||
+ | ==Low levels of compliance== | ||
<ul> | <ul> | ||
− | <li | + | <li Development teams don’t have the time to study and understand the complex security requirements and don’t know how to write code or test code that implements it</li> |
− | < | + | </ul> |
− | < | + | ==Compliance and assurance seen as blockers== |
+ | <ul> | ||
+ | <li>Approvers and assurance teams delay release while development teams do a post development, blind scramble for evidence to prove they have met security requirements</li> | ||
+ | </ul> | ||
+ | ==Duplication of effort and inconsistent implementation== | ||
+ | <ul> | ||
+ | <li>Complex application landscapes with multiple dev teams, application and technologies make it difficult to control and coordinate development and testing effort</li> | ||
</ul> | </ul> | ||
Revision as of 11:27, 30 September 2019
|