This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "OWASP Guide Project"
(→Downloads) |
|||
Line 7: | Line 7: | ||
|- valign="top" | |- valign="top" | ||
| | | | ||
− | |||
− | + | The OWASP Developer Guide 2013 is a dramatic re-write of one of OWASP's first and most downloaded projects. The focus moves from countermeasures and weaknesses to secure software engineering. | |
+ | |||
+ | In this edition, architects, project leads, and developers can reference a massive text book covering all aspects of modern application security architecture, secure design, and detailed design patterns. This edition aligns with the syllabus outcomes of the Undergraduate Software Assurance degree and Masters of Software Assurance. | ||
+ | |||
+ | Major themes: | ||
+ | |||
+ | * Foundation Security | ||
+ | * Architecture | ||
+ | * Design | ||
+ | * Build | ||
+ | * Operate | ||
+ | * Incident Response | ||
+ | |||
+ | As this book is in a constant state of flux, it can never be said to be complete, and so the current 2005 edition is the "release" edition, and the Wiki here is the draft version until further notice. Once we have adequate coverage and quality of the SwA course matrix, we will switch over even if unfinished. | ||
| | | |
Revision as of 13:16, 29 January 2013
Home
The OWASP Developer Guide 2013 is a dramatic re-write of one of OWASP's first and most downloaded projects. The focus moves from countermeasures and weaknesses to secure software engineering. In this edition, architects, project leads, and developers can reference a massive text book covering all aspects of modern application security architecture, secure design, and detailed design patterns. This edition aligns with the syllabus outcomes of the Undergraduate Software Assurance degree and Masters of Software Assurance. Major themes:
As this book is in a constant state of flux, it can never be said to be complete, and so the current 2005 edition is the "release" edition, and the Wiki here is the draft version until further notice. Once we have adequate coverage and quality of the SwA course matrix, we will switch over even if unfinished. |
Let's talk hereFurther development of the Development Guide occurs through mailing list discussions and occasional workshops, and suggestions for improvement are welcome. For more information, please contact us. |
Got Cycles?Work has begun on the next version of the Development Guide! Read all about it, here
Got Translation Cycles?The Development Guide project is always on the lookout for volunteers who are interested in translating the Development Guide into another language.
|
Related resources |
Downloads
1. About the Development Guide
The Development Guide is aimed at architects, developers, consultants and auditors and is a comprehensive manual for designing, developing and deploying secure Web Applications and Web Services. The original OWASP Development Guide has become a staple diet for many web security professionals. Since 2002, the initial version was downloaded over 2 million times. Today, the Development Guide is referenced by many leading government, financial, and corporate standards and is the Gold standard for Web Application and Web Service security.
- Project presentation in English (Currently under development!)
- Data sheet in English (Currently under development!)
- DRAFT Development Guide 2013 - TBA
- Development Guide 2005 in English (PDF, Word, Wiki)
- Development Guide 2005 in Spanish (PDF, Word)
- Development Guide 2002 in Japanese (PDF)
- Development Guide (Earlier Versions) (file download center, CVS)
3. Learn about using the Development Guide
The Development Guide provides practical guidance and includes J2EE, ASP.NET, and PHP code samples. The Development Guide covers an extensive array of application-level security issues, from SQL injection through modern concerns such as phishing, credit card handling, session fixation, cross-site request forgeries, compliance, and privacy issues.
- Development Guide Articles (Please see below)
Glossary
- (Currently under development!)
Project About
PROJECT INFO What does this OWASP project offer you? |
RELEASE(S) INFO What releases are available for this project? | |||||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|