This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "Industry:Citations"

From OWASP
Jump to: navigation, search
m (Important Reports and Other Resources: Punctuation)
(National and International Legislation, Standards, Guidelines, Committees and Industry Codes of Practice: ISO/IEC addition)
Line 7: Line 7:
 
* [http://www.owasp.org/index.php/ESAPI#tab=Contributors.2FUsers OWASP Enterprise Security API Users and Adopters]
 
* [http://www.owasp.org/index.php/ESAPI#tab=Contributors.2FUsers OWASP Enterprise Security API Users and Adopters]
  
=== National and International Legislation, Standards, Guidelines, Committees and Industry Codes of Practice ===
+
=== National & International Legislation, Standards, Guidelines, Committees and Industry Codes of Practice ===
  
 
Hyperlinks have not been added to citations to prevent any mis-interpretation.  Please read the source documents in full to understand the context.  Ordered by organisation name ascending, then date ascending.
 
Hyperlinks have not been added to citations to prevent any mis-interpretation.  Please read the source documents in full to understand the context.  Ordered by organisation name ascending, then date ascending.
Line 63: Line 63:
  
 
GovCertUK is the UK Government Emergency Response Team and is part of [http://www.cesg.gov.uk/ CESG].
 
GovCertUK is the UK Government Emergency Response Team and is part of [http://www.cesg.gov.uk/ CESG].
 +
|-valign="top"
 +
| [http://www.iso.org/ International Organization for Standardization (ISO)] and [http://www.iec.ch/ International Electrotechnical Commission (IEC)]
 +
| Worldwide
 +
| [http://webstore.iec.ch/Webstore/webstore.nsf/0/D2422D1EF9D89BC2C125757C0010F414 ISO/IEC TR24729-4, Information technology — Radio frequency identification for item management — Implementation guidelines — Part 4: Tag data security]
 +
| March 2009
 +
| -
 +
| In "Normative references", "Open Web Application Security Project (OWASP) http://www.owasp.org/index.php/Main_Page".  See http://www.grifs-project.eu/db/?q=node/129
 
|-valign="top"
 
|-valign="top"
 
|rowspan="2"| National Infrastructure Security Co-ordination Centre (NISCC)
 
|rowspan="2"| National Infrastructure Security Co-ordination Centre (NISCC)

Revision as of 17:35, 8 July 2009

This is a draft page containing work in progress.

OWASP Projects

Some OWASP projects maintain their own lists of citations, users and references:

National & International Legislation, Standards, Guidelines, Committees and Industry Codes of Practice

Hyperlinks have not been added to citations to prevent any mis-interpretation. Please read the source documents in full to understand the context. Ordered by organisation name ascending, then date ascending.

Organisation Scope Document Date Version Comments
Defense Information Systems Agency (DISA) USA Recommended Standard Application Security Requirements (Draft) 11 March 2003 2.0 (draft) In "Appendix B References", "B.5 Best Practices... 32. Open Web Application Security Project (OWASP): “The Ten Most Critical Web Application Security Vulnerabilities” (13 January 2003)".
Web Server Technical Implementation Guide 11 December 2006 6 Rel 1 In "1.1 Background", "Major security forums (e.g., SysAdmin, Audit, Network, Security (SANS) Institute and the Open Web Application Security Project (OWASP)) publish reports describing the most critical Internet security threats. From these reports, some threats unique to web server technology are as follows...".
Application Security and Development - Security Technical Implementation Guide 24 July 2008 2 Rel 1 In "Appendix A References", "Open Web Application Security Project http://www.owasp.org/" and "Open Web Application Security Project Threat Risk Modeling http://www.owasp.org/index.php/Threat_Risk_Modeling".
Application Security and Development Checklist 24 July 2008 2 Rel 1.1 Multiple OWASP website references providing vulnerability examples.

Superseded (see below)

Application Security and Development Checklist 26 June 2009 2 Rel 1.5 OWASP referenced in "APP3020 Threat model not established or updated... Detailed information on threat modeling can be found at the OWASP website. http://www.owasp.org/index.php/Threat_Risk_Modeling", "APP3550 Application is vulnerable to integer overflows... Examples of Integer Overflow vulnerabilities can be obtained from the OWASP website. http://www.owasp.org/index.php/Integer_overflow", "APP3560 Application contains format string vulnerabilities... Examples of Format String vulnerabilities can be obtained from the OWASP website. http://www.owasp.org/index.php/Format_string_problem", "APP3570 Application vulnerable to Command Injection... Examples of Command Injection vulnerabilities can be obtained from the OWASP website. http://www.owasp.org/index.php/Command_Injection", "APP3580 Application vulnerable to Cross Site Scripting... Examples of Cross Site Scripting vulnerabilities can be obtained from the OWASP website. http://www.owasp.org/index.php/Cross_Site_Scripting", "APP3600 Vulnerable to canonical representation attacks... Examples of Canonical Representation vulnerabilities can be obtained from the OWASP website. http://www.owasp.org/index.php/Canonicalization,_locale_and_Unicode", "APP3630 Application vulnerable to race conditions... Examples of Race Conditions vulnerabilities can be obtained from the OWASP website. https://www.owasp.org/index.php/Reviewing_Code_for_Race_Conditions", and "APP5100 Fuzz testing is not performed... The following website provides an overview of fuzz testing and examples: http://www.owasp.org/index.php/Fuzzing"
GovCertUK UK SQL Injection 16 January 2009 1.0 In "3.2 SQL Injection", "The OWASP Foundation has produced two tools that can be used to learn about and analyse attacks. The WebGoat application has been developed to demonstrate web application security errors, including SQL injection, and educate developers in how to avoid them. A web proxy, such as OWASP’s WebScarab, is needed to complete some of the WebGoat activities. Such a proxy is used to intercept communications between the browser and application, providing a means of changing the data in each message. Where appropriate examples have been taken (with permission) from the WebGoat application and WebScarab proxy output.", extensive use of screen captures from WebGoat and WebScarab, in "6.4 Education", "The key contributors in SQL injection protection are usually the application and web developers and system administrators... There are free resources on the Internet to encourage a better awareness of SQL injection techniques and guides on how to avoid it. Two examples of such free resources are OWASP Foundation’s WebGoat and ...", in "7 Acknowledgements", "Thanks to the OWASP Foundation’s WebGoat Project and WebScarab Project for their permission to use examples from these tools in this paper. They are published under the Creative Commons Licence" and in "8 References", "[i] OWASP WebGoat Project, OWASP Foundation, 15 January 2009, http://www.owasp.org/index.php/Category:OWASP_WebGoat_Project [j] OWASP WebScarab Project, OWASP Foundation, 17 November 2008, [ttp://www.owasp.org/index.php/Category:OWASP_WebScarab_Project http://www.owasp.org/index.php/Category:OWASP_WebScarab_Project]".

GovCertUK is the UK Government Emergency Response Team and is part of CESG.

International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC) Worldwide ISO/IEC TR24729-4, Information technology — Radio frequency identification for item management — Implementation guidelines — Part 4: Tag data security March 2009 - In "Normative references", "Open Web Application Security Project (OWASP) http://www.owasp.org/index.php/Main_Page". See http://www.grifs-project.eu/db/?q=node/129
National Infrastructure Security Co-ordination Centre (NISCC) UK Secure web applications - Development, installation and security testing (NISCC Briefing 10/2006) 27 April 2006 - In References "OWASP Secure Web Application Guide http://www.owasp.org/documentation/guide/guide_about.html".

NISCC is now part of the UK Centre for the Protection of National Infrastructure.

Commercially Available Penetration Testing - Best Practice Guide 8 May 2006 - In "Methodologies", "There are a number of open source penetration testing methodologies that can be used as a reference when examining provider methodologies. Examples include... OWASP - Open Web Application Security Project (http://www.owasp.org)".

NISCC is now part of the UK Centre for the Protection of National Infrastructure.

Payment Card Industry Security Standards Council (PCI SSC) Worldwide Data Security Standard September 2006 1.1 In Requirement 6: Develop and maintain secure systems and applications, "6.5 Develop all web applications based on secure coding guidelines such as the Open Web Application Security Project guidelines...".

Superseded by PCI DSS 1.2 (see below).

Data Security Standard October 2008 1.2 In Requirement 6: Develop and maintain secure systems and applications, "6.3.7 Review of custom code..." mention in "6.3.7b ...Code reviews ensure code is developed according to secure coding guidelines such as the Open Web Security Project Guide...". And "6.5 Develop all web applications (internal and external, and including web administrative access to application) based on secure coding guidelines such as the Open Web Application Security Project Guide. Cover prevention of common coding vulnerabilities in software development processes, to include the following: Note: The vulnerabilities listed at 6.5.1 through 6.5.10 were current in the OWASP guide when PCI DSS v1.2 was published. However, if and when the OWASP guide is updated, the current version must be used for these requirements." and specifically "6.5.a Obtain and review software development processes for any web-based applications. Verify that processes require training in secure coding techniques for developers, and are based on guidance such as the OWASP guide (http://www.owasp.org)."
SAFECode Worldwide Fundamental Practices for Secure Software Development: A Guide to the Most Effective Secure Development Practices in Use Today 8 October 2008 - Links to "OWASP Top Ten", "OWASP PHP AntiXSS Library", "OWASP Canonicalization, Locale and Unicode", "OWASP Reviewing Code for Logging Issues", and "OWASP Error Handling, Auditing and Logging".

Important Reports and Other Resources

Organisation Scope Document Date Version Comments
Combined Security Incident Response Team (CSIRTUK) UK CSIRTUK advisories Ongoing - OWASP Designation used in advisory categorisation.

CSIRTUK is part of the UK Centre for the Protection of National Infrastructure.

Information Assurance Technology Analysis Center (IATAC) and Data and Analysis Center for Software (DACS) USA Software Security Assurance State-of-the-Art Report (SOAR) 31 July 2007 - In Section 6: Software Assurance Initiatives, Activities, and Organizations, "6.2 Private Sector Initiatives", 6.2.1 OWASP... 6.2.1.1 Tools... WebGoat... WebScarab... 6.2.1.2 Documents and Knowledge Bases... AppSec FAQ... Guide to Building Secure Web Applications... Legal knowledge base... Top Ten Web Application Security Vulnerabilities...".
National Cyber Security Division Worldwide Common Weakness Enumeration Ongoing - OWASP Top Ten (2007) view, OWASP Top Ten (2004) view and OWASP in Taxonomies.

The National Cyber Security Division is part of the U.S. Department of Homeland Security.