This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "Key Project Information:OWASP PCI Project"
Line 1: | Line 1: | ||
− | + | =Main= | |
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | < | + | <div style="width:100%;height:160px;border:0,margin:0;overflow: hidden;">[[File:Cornucopia-header.jpg|link=]]</div> |
− | + | {| style="padding: 0;margin:0;margin-top:10px;text-align:left;" |- | |
− | + | | valign="top" style="border-right: 1px dotted gray;padding-right:25px;" | | |
− | + | ==OWASP PCI Scope Toolkit== | |
+ | OWASP PCI Scope toolkit is an Open Source Google Engine App, that will help you to scope the PCI-DSS requirements for your System Components. | ||
+ | ==Introduction== | ||
+ | The PCI toolkit is based on a decision tree assesment methodology, to help you define if the system components of your network, fall within the PCI-DSS requirements. By decomposing , one by one with the help of this Google App Engine, you will be able to create an assesment and a final report of your scope delimitation. | ||
+ | |||
+ | |||
+ | ==Licensing== | ||
+ | OWASP Corncucopia is free to use. It is licensed under the [http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one. | ||
+ | |||
+ | ==Other Security Gamification== | ||
+ | If you are interested in using gaming for security, also see [http://www.microsoft.com/security/sdl/adopt/eop.aspx Elevation of Privilege: The Threat Modeling Game] mentioned above, and the board game [http://www.controlalthack.com/ Control-Alt-Hack] ([http://media.blackhat.com/bh-us-12/Briefings/Kohno/BH_US_12_Kohno_Control_Alt_Hack_Slides.pdf presentation] for latter). | ||
+ | |||
+ | | valign="top" style="padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;" | | ||
+ | |||
+ | |||
+ | |||
+ | == Presentation == | ||
+ | Soon | ||
+ | |||
+ | |||
+ | == Project Leader == | ||
+ | |||
+ | Johanna Curiel | ||
+ | Tom Brennan | ||
+ | |||
+ | |||
+ | == Related Projects == | ||
+ | |||
+ | * [[OWASP Secure Coding Practices - Quick Reference Guide]] | ||
+ | * [[:Category:OWASP Application Security Verification Standard Project|OWASP Application Security Verification Standard]] | ||
+ | |||
+ | |||
+ | | valign="top" style="padding-left:25px;width:200px;" | | ||
+ | |||
+ | == Hyperlink to Google Engine App== | ||
+ | |||
+ | |||
+ | |||
+ | == Reference Files == | ||
+ | |||
+ | * [https://www.owasp.org/index.php/File:OWASP_SCP_Quick_Reference_Guide_v2.pdf OWASP SCP requirements] | ||
+ | * [http://www.owasp.org/images/4/4e/OWASP_ASVS_2009_Web_App_Std_Release.pdf OWASP ASVS verification IDs] | ||
+ | * [https://www.owasp.org/index.php/AppSensor_DetectionPoints OWASP AppSensor attack detection point IDs] | ||
+ | * [http://capec.mitre.org/data/archive/capec_v1.7.1.zip CAPEC IDs] | ||
+ | * [http://www.safecode.org/publications/SAFECode_Agile_Dev_Security0712.pdf SAFECode security-focused story IDs] | ||
+ | |||
+ | The OWASP SCP does not include identity values for the requirements, so please use [https://www.owasp.org/index.php/File:Owasp-requirements-numbering.zip this list]. | ||
+ | |||
+ | |||
+ | == News and Events == | ||
+ | |||
+ | |||
+ | ==PCIDSS== | ||
+ | [[File:Cornucopia-pcidss-ecommerce-guidelines-small.jpg|link=https://www.pcisecuritystandards.org/pdfs/PCI_DSS_v2_eCommerce_Guidelines.pdf]] | ||
+ | |||
+ | OWASP Cornucopia Ecommerce Website Edition is referenced in the new [https://www.pcisecuritystandards.org Payment Card Industry Security Standards Council] information supplement [https://www.pcisecuritystandards.org/pdfs/PCI_DSS_v2_eCommerce_Guidelines.pdf PCI DSS E-commerce Guidelines] v2, January 2013 | ||
+ | |||
+ | ==Classifications== | ||
+ | |||
+ | {| width="200" cellpadding="2" | ||
+ | |- | ||
+ | | align="center" valign="top" width="50%" rowspan="2"| [[File:Owasp-incubator-trans-85.png|link=:Category:OWASP_Project#tab=Terminology]] | ||
+ | | align="center" valign="top" width="50%"| [[File:Owasp-builders-small.png|link=Builders]] | ||
+ | |- | ||
+ | | align="center" valign="top" width="50%"| [[File:Owasp-defenders-small.png|link=Defenders]] | ||
+ | |- | ||
+ | | colspan="2" align="center" | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] | ||
+ | |} | ||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
|} | |} | ||
− | + | ||
− | + | = How to = | |
− | + | ||
− | + | ||
− | + | =FAQs= | |
− | + | ||
− | [[ | + | |
− | + | = Acknowledgements = | |
− | + | ==Volunteers== | |
− | + | Cornucopia is developed by a worldwide team of volunteers. The primary contributors to date have been: | |
− | + | ||
− | + | * Ken Ferris | |
− | + | * Colin Watson | |
+ | |||
+ | ==Others== | ||
+ | |||
+ | |||
+ | = Road Map and Getting Involved = | ||
+ | |||
+ | |||
+ | ==Localization== | ||
+ | |||
+ | ==Design== | ||
+ | |||
+ | ==Feedback== | ||
+ | |||
+ | |||
+ | = About Ecommerce Website Edition = | ||
+ | {{:Projects/OWASP Cornucopia Ecommerce Website Edition | Project About}} | ||
+ | |||
+ | __NOTOC__ <headertabs /> | ||
+ | |||
+ | [[Category:OWASP Project]] [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]] [[Category:OWASP_Document]] [[Category:OWASP_Download]] |
Revision as of 13:35, 28 October 2013
OWASP PCI Scope ToolkitOWASP PCI Scope toolkit is an Open Source Google Engine App, that will help you to scope the PCI-DSS requirements for your System Components. IntroductionThe PCI toolkit is based on a decision tree assesment methodology, to help you define if the system components of your network, fall within the PCI-DSS requirements. By decomposing , one by one with the help of this Google App Engine, you will be able to create an assesment and a final report of your scope delimitation.
LicensingOWASP Corncucopia is free to use. It is licensed under the Creative Commons Attribution-ShareAlike 3.0 license, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one. Other Security GamificationIf you are interested in using gaming for security, also see Elevation of Privilege: The Threat Modeling Game mentioned above, and the board game Control-Alt-Hack (presentation for latter). |
PresentationSoon
Project LeaderJohanna Curiel Tom Brennan
Related Projects
|
Hyperlink to Google Engine AppReference Files
The OWASP SCP does not include identity values for the requirements, so please use this list.
News and EventsPCIDSSOWASP Cornucopia Ecommerce Website Edition is referenced in the new Payment Card Industry Security Standards Council information supplement PCI DSS E-commerce Guidelines v2, January 2013 Classifications |
Volunteers
Cornucopia is developed by a worldwide team of volunteers. The primary contributors to date have been:
- Ken Ferris
- Colin Watson
Others
Localization
Design
Feedback
PROJECT INFO What does this OWASP project offer you? |
RELEASE(S) INFO What releases are available for this project? | |||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|