This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "Application Security Program Quick Start Guide"

From OWASP
Jump to: navigation, search
(Created page with "__NOTOC__ {| width="100%" cellspacing="0" cellpadding="10" |- valign="top" | width="70%" style="background:#d9e9f9" | = Application Security Program Quick Start Guide = Pla...")
 
Line 41: Line 41:
 
== Licensing ==
 
== Licensing ==
  
The OWASP Application Security Guide For CISOs is free to use. It is licensed under the [http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license].
+
The OWASP Application Security Program Quick Start Guide is free to use. It is licensed under the [http://creativecommons.org/licenses/by-nc-sa/4.0/ Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International license].
 
You are free to:  
 
You are free to:  
 
*Share — copy and redistribute the material in any medium or format  
 
*Share — copy and redistribute the material in any medium or format  
Line 48: Line 48:
 
| width="100" style="max-height:200px;overflow:hidden;background:#fff;margin:0;padding:0;" cellpadding="0" |
 
| width="100" style="max-height:200px;overflow:hidden;background:#fff;margin:0;padding:0;" cellpadding="0" |
  
<div style="width:100px;max-height:300px;border:0;margin:0;padding-left:6px;padding-right:6px;overflow:visible;">[[File:CISO-Guide-bar.jpg|link=]]</div>
 
  
 
| width="30%" style="background:#eeeeee" |
 
| width="30%" style="background:#eeeeee" |

Revision as of 17:45, 1 December 2014


Application Security Program Quick Start Guide

Placeholder

Contents

‘’’*Day 1 **Key Activities:

      • Evaluation

*Key Questions:

      • Management
      • Security
      • IT Ops
      • Engineering Groups (inc. QA)/Development

*Day 2 **Key Activities:

      • Asset Discovery
      • Asset Risk Prioritization
      • Communication Plan

*Day 3 **Key Activities:

      • Vulnerability Assessments
      • Vulnerability delivery

*Day 4 **Key Activities:

      • Measured Metrics

*Day 5 **Key activities:

      • Compensating Controls
      • Mitigating Controls
      • Remediation Prioritization


Licensing

The OWASP Application Security Program Quick Start Guide is free to use. It is licensed under the Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International license. You are free to:

  • Share — copy and redistribute the material in any medium or format
  • Adapt — remix, transform, and build upon the material The licensor cannot revoke these freedoms as long as you follow the license terms.