This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "Risk Assessment Framework"
From OWASP
(24 intermediate revisions by 2 users not shown) | |||
Line 4: | Line 4: | ||
| valign="top" style="border-right: 1px dotted gray;padding-right:25px;" | | | valign="top" style="border-right: 1px dotted gray;padding-right:25px;" | | ||
− | + | =Home= | |
− | OWASP Risk Asessement Framework is | + | The OWASP Risk Asessement Framework is SAS(Source Code Analysis) and Risk Assesment tool. |
− | + | ||
==Project About== | ==Project About== | ||
+ | https://github.com/OWASP/RiskAssessmentFramework | ||
<span style="color:#ff0000"> | <span style="color:#ff0000"> | ||
− | |||
− | ==OWASP | + | |
− | <span style="color: | + | ==OWASP Risk Assessment Framework Project / RAF == |
− | + | <span style="color:> | |
+ | The OWASP Risk Asessement Framework is SAS(Source Code Analysis) and Risk Assesment tool. | ||
+ | features<br> | ||
+ | Web Deface Detection<br> | ||
+ | Scanning Tools based on OWASP Top 10<br> | ||
+ | Risk Assesment Tools<br> | ||
+ | Static Application security Testing<br> | ||
</span> | </span> | ||
− | |||
− | |||
==Description== | ==Description== | ||
− | <span style="color: | + | <span style="color:"> |
− | + | Introduction to Problem: <br> | |
− | + | There are hundreds of SAST tools available for a penetration tester to use from and there | |
− | + | are frameworks to assess the risk of a security flaw. But in the OWASP Risk Assessment to testers | |
− | + | have to manually input the the test results from each and every tool to get a relative | |
− | + | approximation. This makes the assessment part as a separate component from all other tools. | |
− | |||
− | |||
− | |||
==Licensing== | ==Licensing== | ||
− | <span style="color: | + | <span style="color:"> |
A project must be licensed under a community friendly or open source license. For more information on OWASP recommended licenses, please see [https://www.owasp.org/index.php/OWASP_Licenses OWASP Licenses]. While OWASP does not promote any particular license over another, the vast majority of projects have chosen a Creative Commons license variant for documentation projects, or a GNU General Public License variant for tools and code projects. This example assumes that you want to use the AGPL 3.0 license. | A project must be licensed under a community friendly or open source license. For more information on OWASP recommended licenses, please see [https://www.owasp.org/index.php/OWASP_Licenses OWASP Licenses]. While OWASP does not promote any particular license over another, the vast majority of projects have chosen a Creative Commons license variant for documentation projects, or a GNU General Public License variant for tools and code projects. This example assumes that you want to use the AGPL 3.0 license. | ||
</span> | </span> | ||
− | This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version. OWASP XXX and any contributions are Copyright © by {the Project Leader(s) or OWASP} {Year(s)}. | + | This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version. OWASP XXX and any contributions are Copyright © by {the Project Leader(s) or OWASP} {Year(s)}. |
− | + | =Roadmap= | |
− | <span style="color: | + | <span style="color:"> |
− | + | https://github.com/OWASP/RiskAssessmentFramework/blob/master/readme.md | |
− | |||
− | |||
− | |||
− | |||
− | |||
</strong> | </strong> | ||
− | + | ||
− | |||
− | |||
− | |||
− | |||
</strong> | </strong> | ||
==Getting Involved== | ==Getting Involved== | ||
− | < | + | <br> |
− | Involvement in the development and promotion of | + | Involvement in the development and promotion of his project is actively encouraged! |
You do not have to be a security expert or a programmer to contribute. | You do not have to be a security expert or a programmer to contribute. | ||
Some of the ways you can help are as follows: | Some of the ways you can help are as follows: | ||
− | + | Contact me at ade.putra@owasp.org | |
| valign="top" style="padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;" | | | valign="top" style="padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;" | | ||
== Project Resources == | == Project Resources == | ||
− | |||
− | |||
− | |||
− | [ https://github.com/OWASP/RiskAssessmentFramework | + | [https://github.com/OWASP/RiskAssessmentFramework |
− | Installation Package] | + | Installation Package] <br> |
− | [https://github.com/OWASP/RiskAssessmentFramework] | + | [https://github.com/OWASP/RiskAssessmentFramework Source Code] |
== Project Leader == | == Project Leader == | ||
Ade Yoseman Putra | Ade Yoseman Putra | ||
+ | Rejah Rehim | ||
+ | ==News== | ||
+ | * [23 May 2019] Published in ToolsWatch.org, [https://www.toolswatch.org/2019/05/amazing-black-hat-arsenal-usa-2019-lineup-announced/ Amazing Black Hat Arsenal USA 2019 Lineup Announced] | ||
== Related Projects == | == Related Projects == | ||
− | + | ||
− | + | * [[OWASP Testing Guide v4 Table of Contents]] | |
− | + | * [[OWASP SonarQube Project]] | |
− | * [[ | ||
− | * [[ | ||
==Classifications== | ==Classifications== |
Latest revision as of 03:49, 24 May 2019
Project Resources[https://github.com/OWASP/RiskAssessmentFramework
Installation Package] Project LeaderAde Yoseman Putra Rejah Rehim News
Related ProjectsClassifications
|