This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "OWASP Project Reviews 2017"
(Tag: Visual edit) |
(Tag: Visual edit) |
||
| Line 1: | Line 1: | ||
| − | '''<u>Overview of Project Reviews:</u>''' | + | === '''<u>Overview of Project Reviews:</u>''' === |
| − | |||
OWASP is reviewing projects who wish to graduate from [[OWASP Project Inventory|Incubator]] to [[OWASP Project Inventory|Lab]] to [[OWASP Project Inventory|Flagship]]. The purpose of this assessment is to determine whether a project meets the minimum criteria to graduate as outlined in the Project Health Assessment Criteria Document. The review process begins with an initial self-assessment done by the project leader and reviewed by Matt Tesauro. Next, the assessment enters the peer review phase where we ask volunteers in our OWASP Community to participate and finalize the results. I have included a [https://docs.google.com/document/d/1NQSHshTxK1AWTkD4WgYluxSafgO-XGDHZnwE9Qvt7TE/edit '''Sample of a Project Assessmen'''t] for your review and consideration. | OWASP is reviewing projects who wish to graduate from [[OWASP Project Inventory|Incubator]] to [[OWASP Project Inventory|Lab]] to [[OWASP Project Inventory|Flagship]]. The purpose of this assessment is to determine whether a project meets the minimum criteria to graduate as outlined in the Project Health Assessment Criteria Document. The review process begins with an initial self-assessment done by the project leader and reviewed by Matt Tesauro. Next, the assessment enters the peer review phase where we ask volunteers in our OWASP Community to participate and finalize the results. I have included a [https://docs.google.com/document/d/1NQSHshTxK1AWTkD4WgYluxSafgO-XGDHZnwE9Qvt7TE/edit '''Sample of a Project Assessmen'''t] for your review and consideration. | ||
| − | '''OWASP Project Reviews @ APPSEC Belfast 2017''' | + | === '''OWASP Project Reviews @ APPSEC Belfast 2017''' === |
* Johanna Curiel (Program Leader) | * Johanna Curiel (Program Leader) | ||
* Matt Tesauro (Sr. Project Coordinator) | * Matt Tesauro (Sr. Project Coordinator) | ||
| + | * Claudia Aviles Casanovas (Project Coordinator) | ||
* Azzeddine Ramrami | * Azzeddine Ramrami | ||
* Talal Albach | * Talal Albach | ||
| Line 11: | Line 11: | ||
* Nabin Kc | * Nabin Kc | ||
'''Description of Scope of Work: [[Project Reviews Guideline|More Information here]].''' | '''Description of Scope of Work: [[Project Reviews Guideline|More Information here]].''' | ||
| − | |||
| − | |||
'''Tool Projects''' | '''Tool Projects''' | ||
| − | [https://docs.google.com/document/d/1zO_9apf6470q9fR76F6Ms9NgGg_1HN2-DwZcRuHI7mg/edit?usp=sharing OWASP Benchmark Project] | + | [https://docs.google.com/document/d/1zO_9apf6470q9fR76F6Ms9NgGg_1HN2-DwZcRuHI7mg/edit?usp=sharing OWASP Benchmark Project] [https://docs.google.com/a/owasp.org/document/d/1X_n_70BA4cvSAoj78i30VtryiaTRvXsJaQzYLncV7nc/edit?usp=sharing OWASP Juiceshop Project] |
| − | |||
| − | [https://docs.google.com/a/owasp.org/document/d/1X_n_70BA4cvSAoj78i30VtryiaTRvXsJaQzYLncV7nc/edit?usp=sharing OWASP Juiceshop | ||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | ''' | + | '''Code Projects:''' |
| − | [https://docs.google.com/a/owasp.org/document/d/ | + | [https://docs.google.com/a/owasp.org/document/d/1w2A8OJmir2ZSYdYgcrYs578ldo74s7i3EdipkLxgXes/edit?usp=sharing OWASP DefectDojo Project] [https://docs.google.com/a/owasp.org/document/d/1lNTikC-im5oRb0Nlk0ZZcUG_FWsQeGG6mZyYcEMrQNk/edit?usp=sharing OWASP Node.js Goat Project] |
| − | + | '''Documentation Projects:''' | |
| − | + | [https://docs.google.com/a/owasp.org/document/d/1HPpSF7vaZEFhO2mRxqJT2KTmtxp7yxkFmm5jbzliuy4/edit?usp=sharing OWASP Automated Threats to Web Applications] [https://docs.google.com/a/owasp.org/document/d/1EabefBF41t6jMY4qgBOTVOQLtw4EWdtmHpAStPIwt0k/edit?usp=sharing OWASP Snakes and Ladder] | |
| − | + | === '''<u>OWASP Project Health Checks:</u>''' === | |
| + | '''Review Forms:''' [https://docs.google.com/a/owasp.org/document/d/1jUXt9M9u9Kq1JLaDSdbh6s0p5G_EqFSoaKpzDRures4/edit?usp=sharing Code Health Check] [https://docs.google.com/a/owasp.org/document/d/1aDdcBm3v-DMraVKmsBiNA4YzBmlGFLvOddj5nvPd--Q/edit?usp=sharing Tool Health Check] [https://docs.google.com/a/owasp.org/document/d/17kJlpupi2nmKKRMMBpxgyj1JWxvt23iT8fWULm4SW6k/edit?usp=sharing Documentation Health Check] | ||
| − | '''Lab | + | '''Lab Projects:''' |
| − | [[OWASP Hackademic Challenges Project]] | + | [[OWASP Hackademic Challenges Project|OWASP Hackademic Challenges Project]] |
| − | [[OWASP Mantra - Security Framework|OWASP Mantra Security Framwork]] | + | [[OWASP Mantra - Security Framework|OWASP Mantra Security Framwork]] |
[[:Category:OWASP Security Ninjas AppSec Training Program|OWASP Security Ninjas AppSec Training Program]] | [[:Category:OWASP Security Ninjas AppSec Training Program|OWASP Security Ninjas AppSec Training Program]] | ||
| − | '''Lab Documentation''' | + | '''Lab Documentation Projects:''' |
[[OWASP Application Security Guide For CISOs Project|OWASP Application Security Guide for Cisos Project]] | [[OWASP Application Security Guide For CISOs Project|OWASP Application Security Guide for Cisos Project]] | ||
Revision as of 23:05, 6 April 2017
Overview of Project Reviews:
OWASP is reviewing projects who wish to graduate from Incubator to Lab to Flagship. The purpose of this assessment is to determine whether a project meets the minimum criteria to graduate as outlined in the Project Health Assessment Criteria Document. The review process begins with an initial self-assessment done by the project leader and reviewed by Matt Tesauro. Next, the assessment enters the peer review phase where we ask volunteers in our OWASP Community to participate and finalize the results. I have included a Sample of a Project Assessment for your review and consideration.
OWASP Project Reviews @ APPSEC Belfast 2017
- Johanna Curiel (Program Leader)
- Matt Tesauro (Sr. Project Coordinator)
- Claudia Aviles Casanovas (Project Coordinator)
- Azzeddine Ramrami
- Talal Albach
- Kuai Hinojosa
- Nabin Kc
Description of Scope of Work: More Information here.
Tool Projects
OWASP Benchmark Project OWASP Juiceshop Project
Code Projects:
OWASP DefectDojo Project OWASP Node.js Goat Project
Documentation Projects:
OWASP Automated Threats to Web Applications OWASP Snakes and Ladder
OWASP Project Health Checks:
Review Forms: Code Health Check Tool Health Check Documentation Health Check
Lab Projects:
OWASP Hackademic Challenges Project
OWASP Mantra Security Framwork
OWASP Security Ninjas AppSec Training Program
Lab Documentation Projects:
OWASP Application Security Guide for Cisos Project
Incubator Projects
https://www.owasp.org/index.php/OWASP_Secure_Headers_Project - Response on needed on request to get an external hosthttps://www.owasp.org/index.php/OWASP_WASC_Distributed_Web_Honeypots_Project - No updates since 2015
https://www.owasp.org/index.php/OWASP_Faux_Bank_Project - No updates since 2015
https://www.owasp.org/index.php/OWASP_Droid10_Project - No updates since March 15
https://www.owasp.org/index.php/OWASP_WAP-Web_Application_Protection - no updates since 2015 and no repository still in salesforge
https://www.owasp.org/index.php/OWASP_Mutillidae_2_Project - No updates since 2015 still using salesforge
https://www.owasp.org/index.php/OWASP_WebSpa_Project - no updates since March 2015 last update in salesforge 2/21/2016
https://www.owasp.org/index.php/OWASP_Rainbow_Maker_Project - Last release 12/11/2015 and no updates since May 2015
https://www.owasp.org/index.php/Category:OWASP_.NET_Project - No updates March 23, 2016
https://www.owasp.org/index.php/OWASP_WASC_Web_Hacking_Incidents_Database_Project - no updated since March 12, 2015
https://www.owasp.org/index.php/OWASP_Application_Security_Program_Quick_Start_Guide_Project - no updates since january 2015
https://www.owasp.org/index.php/OWASP_Secure_Configuration_Guide#tab=Main - No updates since April 2016 - no updates to guide
https://www.owasp.org/index.php/OWASP_RFP-Criteria - no updates since March 2016
https://www.owasp.org/index.php/Category:OWASP_Top_10_fuer_Entwickler - no real updates on news since 2013 some updates to the wiki