This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "Category:OWASP Application Security Verification Standard Project"
Deleted user (talk | contribs) |
Deleted user (talk | contribs) |
||
| Line 2: | Line 2: | ||
Proj_About= | Proj_About= | ||
[[Image:Asvs-bannerbug.JPG|200px|right]] | [[Image:Asvs-bannerbug.JPG|200px|right]] | ||
| − | Whereas the [[OWASP Top Ten Project]] is a tool that provides web application security awareness, the OWASP "Application Security Verification Standard" (also known as "ASVS") is a commercially-workable open standard that defines ranges in coverage and levels of rigor that can be used to perform application security verifications. It is the very first standard that OWASP has published! There are currently versions in English. | + | Whereas the [[OWASP Top Ten Project]] is a tool that provides web application security awareness, the '''OWASP "Application Security Verification Standard" (also known as "ASVS")''' is a commercially-workable open standard that defines ranges in coverage and levels of rigor that can be used to perform application security verifications. It is the very first standard that OWASP has published! There are currently versions in English. |
<br> | <br> | ||
<br> | <br> | ||
| − | |||
| − | |||
What becomes quickly apparent during procurement when attempting to capture contractual terms and conditions related to the security of web applications and web services is that specifying security analysis and testing requirements is very hard. It also becomes quickly apparent when reviewing web application and web service security verification reports that there is no way to tell the difference between someone running a grep tool, and someone doing painstaking code review and manual testing. | What becomes quickly apparent during procurement when attempting to capture contractual terms and conditions related to the security of web applications and web services is that specifying security analysis and testing requirements is very hard. It also becomes quickly apparent when reviewing web application and web service security verification reports that there is no way to tell the difference between someone running a grep tool, and someone doing painstaking code review and manual testing. | ||
| Line 109: | Line 107: | ||
* 04/16/2008 - [https://www.owasp.org/index.php/OWASP_Summer_of_Code_2008_Applications#OWASP_Application_Security_Verification_Standard OWASP ASVS Summer of Code 2008 proposal] submitted by [[User:Mike.boberski|Mike Boberski]] wins! | * 04/16/2008 - [https://www.owasp.org/index.php/OWASP_Summer_of_Code_2008_Applications#OWASP_Application_Security_Verification_Standard OWASP ASVS Summer of Code 2008 proposal] submitted by [[User:Mike.boberski|Mike Boberski]] wins! | ||
| − | + | <br>'''Project Mail List:'''<br>[http://lists.owasp.org/mailman/listinfo/owasp-application-security-verification-standard Subscribe here]<br>[mailto:[email protected] Use here] | | |
| − | |||
| − | |||
Proj_Related= [[Top Ten|OWASP Top Ten]] | | Proj_Related= [[Top Ten|OWASP Top Ten]] | | ||
Revision as of 00:42, 9 March 2009
About
Whereas the OWASP Top Ten Project is a tool that provides web application security awareness, the OWASP "Application Security Verification Standard" (also known as "ASVS") is a commercially-workable open standard that defines ranges in coverage and levels of rigor that can be used to perform application security verifications. It is the very first standard that OWASP has published! There are currently versions in English.
What becomes quickly apparent during procurement when attempting to capture contractual terms and conditions related to the security of web applications and web services is that specifying security analysis and testing requirements is very hard. It also becomes quickly apparent when reviewing web application and web service security verification reports that there is no way to tell the difference between someone running a grep tool, and someone doing painstaking code review and manual testing.
Both of these problems have a single root cause: the lack of a standard for performing application-level security verification that is web application and web service independent, Software Development Life Cycle (SDLC) independent, and that can be used for any application without special interpretation. The OWASP ASVS was designed to normalize the range in coverage and level of rigor available in the market when it comes to performing application security verification.
Where did ASVS come from?
The OWASP ASVS project is led by Mike Boberski (Booz Allen Hamilton). The primary authors are Mike Boberski, Jeff Williams (Aspect Security), and Dave Wichers (Aspect Security). The ASVS is the result of the collection and consolidation of decades of collective subject matter expertise in application security. If you’d like to volunteer to help on the project, you can contact Mike Boberski.
FAQ
| |
This project has produced a book that can be downloaded or purchased. Feel free to browse the full catalog of available OWASP books. |
More About OWASP ASVS
- Project Presentation (PowerPoint)
- Executive-Level Presentation (PowerPoint)
- Presentation Abstract (Word)
- One Page Conference Handout (PDF, Word)
Related projects:
Web Application Edition
OWASP ASVS - Beta (This is the current official release version)
Download free:
OWASP ASVS - Beta (This is the current official release version)
OWASP ASVS Alpha Downloads
Download free:
OWASP ASVS - Alpha
Web Service Edition
The OWASP ASVS Web Service Edition can be used to establish a level of confidence in the security of web services. It is currently under development and is not yet available for release.
News
Project News:
- 01/22/2009 - OWASP ASVS has been integrated into the OWASP Secure Software Contract Annex in the OWASP Legal Project.
- 01/08/2009 - OWASP ASVS is presented by Mike Boberski at the OWASP Washington VA Local Chapter meeting.
- 12/29/2008 - OWASP ASVS is the subject of an article by DarkReading.
- 12/08/2008 - OWASP ASVS Final assistance required! Please join the mailing list for more information and assignments.
- 12/05/2008 - OWASP ASVS exits the Summer of Code 2008! The Beta draft of the Web Application Edition is released! Mike Boberski, Jeff Williams, and Dave Wichers are the primary authors.
- 11/03/2008 - OWASP ASVS is presented by Jeff Williams at OWASP EU Summit 2008.
- 10/03/2008 - OWASP ASVS Alpha draft is released! Mike Boberski is the primary author.
- 04/16/2008 - OWASP ASVS Summer of Code 2008 proposal submitted by Mike Boberski wins!
Project Mail List:
Subscribe here
Use here
Contributors/Users
Project Leader
Mike Boberski
Project Contributors
Jeff Williams
Dave Wichers
The OWASP ASVS project is co-sponsored by:
This project licensed under the Licensed under Creative Commons Attribution ShareAlike 3.0.
Pages in category "OWASP Application Security Verification Standard Project"
The following 21 pages are in this category, out of 21 total.
H
- How to bootstrap the NIST risk management framework with verification activities
- How to bootstrap your SDLC with verification activities
- How to create verification project schedules
- How to perform a security architecture review at Level 1
- How to perform a security architecture review at Level 2
- How to specify verification requirements in contracts
- How to write verifier job requisitions
