This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "OWASP Security Ninja Project"
From OWASP
(→OWASP Green Belt, OWASP Brown Belt, OWASP Black Belt (October 2017 - September 2018)) |
(→OWASP Security Ninja) |
||
(2 intermediate revisions by the same user not shown) | |||
Line 8: | Line 8: | ||
The world of application security has a gaping hole when it comes to interesting and engaging security learning. Builders, breakers, and defenders lack a solid foundation of application security knowledge and an appreciation for the evolving threat landscape. These same folks also lack experience with secure development practices and tools. Finally, they lack the motivation to volunteer to improve application security. | The world of application security has a gaping hole when it comes to interesting and engaging security learning. Builders, breakers, and defenders lack a solid foundation of application security knowledge and an appreciation for the evolving threat landscape. These same folks also lack experience with secure development practices and tools. Finally, they lack the motivation to volunteer to improve application security. | ||
− | Enter the OWASP Security Ninja program, a content and action based application security learning adventure. The project recognizes the learning and activity achievements of OWASP application security practitioners using a system of security belts. The OWASP security belts are white, yellow, green, brown, and black. Similar to belts in the world of martial arts, a student in our "virtual dojo" must train and test to earn a belt. | + | Enter the OWASP Security Ninja program, a content and action based application security learning adventure using the latest advancements in the world of gamification to enhance the learner experience and keep them coming back. The project recognizes the learning and activity achievements of OWASP application security practitioners using a system of security belts. The OWASP security belts are white, yellow, green, brown, and black. Similar to belts in the world of martial arts, a student in our "virtual dojo" must train and test to earn a belt. |
* '''White Belt''' -- The journey begins with the student reviewing video learning modules and taking an assessment per module. When the learner achieves passing status on all the white belt modules, they earn the OWASP Security White Belt and are eligible to continue to Yellow Belt. | * '''White Belt''' -- The journey begins with the student reviewing video learning modules and taking an assessment per module. When the learner achieves passing status on all the white belt modules, they earn the OWASP Security White Belt and are eligible to continue to Yellow Belt. | ||
− | * '''Yellow Belt''' -- focuses on applying the knowledge, and splits the content into builder and breaker specific roles. | + | * '''Yellow Belt''' -- The yellow belt focuses on applying the security knowledge, and splits the content into builder and breaker specific roles, each with a separate set of learning modules to be completed. |
* '''Green, Brown, Black Belts''' -- After yellow, the student must put their new found knowledge into action by completing activities that improve some facet of application security. For each activity, the student earns points towards the next belt in the series (green, brown, and black). OWASP Security Black belt is the highest honor, and signifies that the student has become the teacher, and has taken a leadership stake in learning and doing application security. | * '''Green, Brown, Black Belts''' -- After yellow, the student must put their new found knowledge into action by completing activities that improve some facet of application security. For each activity, the student earns points towards the next belt in the series (green, brown, and black). OWASP Security Black belt is the highest honor, and signifies that the student has become the teacher, and has taken a leadership stake in learning and doing application security. | ||
Line 106: | Line 106: | ||
* Launch of concept and completion of initial scope (September 2018) | * Launch of concept and completion of initial scope (September 2018) | ||
===Content Refresh=== | ===Content Refresh=== | ||
− | + | The challenge with security learning modules is that they become stale after roughly one year of release. The content refresh process ensures that once per year content is reviewed and select pieces of content are updated. At the conclusion of the green, brown, and black belt deployment, the project will begin an aggressive content refresh process. | |
= White Belt = | = White Belt = |
Latest revision as of 01:10, 7 December 2015