This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "Projects/OWASP Embedded Application Security/Roadmap"

From OWASP
Jump to: navigation, search
(Created page with "1. Reach out to embedded developers and build a community to start talking about security challenges in embedded development. 2. Create a list of the top risks in embedded ha...")
 
Line 1: Line 1:
1. Reach out to embedded developers and build a community to start talking about security challenges in embedded development.
+
'''Year 1'''
  
2. Create a list of the top risks in embedded hardware. (Similar to the mobile risks lists.)
+
Reach out to embedded developers and embedded security experts to start discussing security challenges in embedded development lifecycle.
  
3. Create cheat sheets or best practice guides.
+
Create a list of the top risks and known security downfalls in embedded development.  
  
4. Guide for testing embedded applications.
+
Create an Embedded Security Tool resource list for testing
 +
 
 +
'''Year 2'''
 +
 
 +
Create a development cheat sheet for embedded developers to reference
 +
 
 +
Create a Secure development guide for embedded applications
 +
-Will need developers who are comfortable with C/C++ for code snippets
 +
-Will be in detail
 +
 
 +
Create a guide for testing embedded applications
 +
 
 +
'''Year 3'''
 +
 
 +
Create platform specific risk lists for embedded industries like Routers, IoT, etc
 +
Create an embedded application threat model describing its differences from normal software development
 +
 
 +
'''Year 4'''
 +
 
 +
Create security tool chains  that can be used for embedded development

Revision as of 22:43, 17 February 2015

Year 1

Reach out to embedded developers and embedded security experts to start discussing security challenges in embedded development lifecycle.

Create a list of the top risks and known security downfalls in embedded development.

Create an Embedded Security Tool resource list for testing

Year 2

Create a development cheat sheet for embedded developers to reference

Create a Secure development guide for embedded applications -Will need developers who are comfortable with C/C++ for code snippets -Will be in detail

Create a guide for testing embedded applications

Year 3

Create platform specific risk lists for embedded industries like Routers, IoT, etc Create an embedded application threat model describing its differences from normal software development

Year 4

Create security tool chains that can be used for embedded development