|
|
Line 3: |
Line 3: |
| back to the [[http://www.owasp.org/index.php/Category:OWASP_Education_Project Education Project]] | | back to the [[http://www.owasp.org/index.php/Category:OWASP_Education_Project Education Project]] |
| | | |
− | ==== Profession / Interest ====
| + | {{:OWASP Education Material Categorized/Profession & Interest}} |
− | Below you find the education material categorized by profession and interest.
| |
− | {{Template:Education Info | |
− | | title = '''Management'''
| |
− | | beginner = * training material
| |
− | | experienced = * training material
| |
− | | expert = * training material
| |
− | }}
| |
− | {{Template:Education Info
| |
− | | title = '''Student'''
| |
− | | beginner = * training material
| |
− | | experienced = * training material
| |
− | | expert = * training material
| |
− | }}
| |
− | {{Template:Education Info
| |
− | | title = '''Developer'''
| |
− | | beginner = * training material
| |
− | | experienced = * training material
| |
− | | expert = * training material
| |
− | }}
| |
− | {{Template:Education Info
| |
− | | title = '''Tester'''
| |
− | | beginner = * training material
| |
− | | experienced = * training material
| |
− | | expert = * training material
| |
− | }} | |
− | <br>
| |
| | | |
− | ==== OWASP Top Ten ====
| + | {{:OWASP Education Material Categorized/OWASP Top Ten}} |
− | The [[:Category:OWASP_Top_Ten_Project |'''OWASP Top Ten''']] represents a broad consensus about what the most critical web application security flaws are. Project members include a variety of security experts from around the world who have shared their expertise to produce this list. There are currently versions in English, French, Japanese, Korean and Turkish. A Spanish version is in the works. We urge all companies to adopt this awareness document within their organization and start the process of ensuring that their web applications do not contain these flaws. Adopting the OWASP Top Ten is perhaps the most effective first step towards changing the software development culture within your organization into one that produces secure code.
| |
− | {| style="width:100%" border="0" align="center"
| |
− | ! colspan="4" align="center" style="background:#FFFFFF; color:white"|<font color="white">
| |
− | '''[[Top_10_2007-A1|A1 - Cross Site Scripting (XSS)]]'''
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Presentation'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Video's '''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training video
| |
− | |}
| |
− | {| style="width:100%" border="0" align="center"
| |
− | ! colspan="4" align="center" style="background:#FFFFFF; color:white"|<font color="white">
| |
− | '''[[Top_10_2007-A2|A2 - Injection Flaws]]'''
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Presentation'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Video's '''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training video
| |
− | |}
| |
− | {| style="width:100%" border="0" align="center"
| |
− | ! colspan="4" align="center" style="background:#FFFFFF; color:white"|<font color="white">
| |
− | '''[[Top_10_2007-A3|A3 - Malicious File Execution]]'''
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Presentation'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Video's '''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training video
| |
− | |}
| |
− | {| style="width:100%" border="0" align="center"
| |
− | ! colspan="4" align="center" style="background:#FFFFFF; color:white"|<font color="white">
| |
− | '''[[Top_10_2007-A4|A4 - Insecure Direct Object Reference]]'''
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Presentation'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Video's '''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training video
| |
− | |}
| |
− | {| style="width:100%" border="0" align="center"
| |
− | ! colspan="4" align="center" style="background:#FFFFFF; color:white"|<font color="white">
| |
− | '''[[Top_10_2007-A5|A5 - Cross Site Request Forgery (CSRF)]]'''
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Presentation'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Video's '''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training video
| |
− | |}
| |
− | {| style="width:100%" border="0" align="center"
| |
− | ! colspan="4" align="center" style="background:#FFFFFF; color:white"|<font color="white">
| |
− | '''[[Top_10_2007-A6|A6 - Information Leakage and Improper Error Handling]]'''
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Presentation'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Video's '''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training video
| |
− | |}
| |
− | {| style="width:100%" border="0" align="center"
| |
− | ! colspan="4" align="center" style="background:#FFFFFF; color:white"|<font color="white">
| |
− | '''[[Top_10_2007-A7|A7 - Broken Authentication and Session Management]]'''
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Presentation'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Video's '''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training video
| |
− | |}
| |
− | {| style="width:100%" border="0" align="center"
| |
− | ! colspan="4" align="center" style="background:#FFFFFF; color:white"|<font color="white">
| |
− | '''[[Top_10_2007-A8|A8 - Insecure Cryptographic Storage]]'''
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Presentation'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Video's '''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training video
| |
− | |}
| |
− | {| style="width:100%" border="0" align="center"
| |
− | ! colspan="4" align="center" style="background:#FFFFFF; color:white"|<font color="white">
| |
− | '''[[Top_10_2007-A9|A9 - Insecure Communications]]'''
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Presentation'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Video's '''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training video
| |
− | |}
| |
− | {| style="width:100%" border="0" align="center"
| |
− | ! colspan="4" align="center" style="background:#FFFFFF; color:white"|<font color="white">
| |
− | '''[[Top_10_2007-A10|A10 - Failure to Restrict URL Access]]'''
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Presentation'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Video's '''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training video
| |
− | |}
| |
| | | |
− | <br>
| + | {{:OWASP Education Material Categorized/OWASP Tooling}} |
| | | |
− | ==== OWASP Tooling ====
| + | {{:OWASP Education Material Categorized/OWASP Documentation}} |
− | An [[:Category:OWASP_Project |'''OWASP Project''']] is a collection of related tasks that have a defined roadmap and team members. OWASP project leaders are responsible for defining the vision, roadmap, and tasks for the project. The project leader also promotes the project and builds the team. Tools and documents are organized into the following categories:
| |
− | PROTECT - These are tools and documents that can be used to guard against security-related design and implementation flaws.
| |
− | DETECT - These are tools and documents that can be used to find security-related design and implementation flaws.
| |
− | LIFE CYCLE - These are tools and documents that can be used to add security-related activities into the Software Development Life Cycle (SDLC).
| |
| | | |
− | <hr><br>''' Protect:'''
| + | {{:OWASP Education Material Categorized/CLASP Roles}} |
| | | |
− | {| style="width:100%" border="0" align="center" | + | {{:OWASP Education Material Categorized/SAMM Disciplines & Functions}} |
− | ! colspan="4" align="center" style="background:#FFFFFF; color:white"|<font color="white">
| |
− | '''[[:Category:OWASP_AntiSamy_Project|OWASP AntiSamy Java Project]] '''
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Beginner'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Experienced'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Expert'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Video's '''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training video
| |
− | |}
| |
− | {| style="width:100%" border="0" align="center" | |
− | ! colspan="4" align="center" style="background:#FFFFFF; color:white"|<font color="white">
| |
− | '''[[:Category:OWASP_Enterprise_Security_API|OWASP Enterprise Security API (ESAPI) Project]] '''
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Beginner'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Experienced'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Expert'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |}
| |
− | | |
− | <br>''' Detect:'''
| |
− | | |
− | {| style="width:100%" border="0" align="center"
| |
− | ! colspan="4" align="center" style="background:#FFFFFF color:white"|<font color="white">
| |
− | '''[[:Category:OWASP_Live_CD_Project|OWASP Live CD Project]]'''
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Beginner'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Experienced'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Expert'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |}
| |
− | {| style="width:100%" border="0" align="center"
| |
− | ! colspan="4" align="center" style="background:#FFFFFF color:white"|<font color="white">
| |
− | '''[[:Category:OWASP_WebScarab_Project|OWASP WebScarab Project]]'''
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Beginner'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Experienced'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Expert'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |}
| |
− | | |
− | <br>''' Life Cycle:'''
| |
− | | |
− | {| style="width:100%" border="0" align="center"
| |
− | ! colspan="4" align="center" style="background:#FFFFFF color:white"|<font color="white">
| |
− | '''[[:Category:OWASP_WebGoat_Project|OWASP WebGoat Project]]'''
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Beginner'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Experienced'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Expert'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |}
| |
− | <br>
| |
− | ==== OWASP Documentation ====
| |
− | An [[:Category:OWASP_Project |'''OWASP Project''']] is a collection of related tasks that have a defined roadmap and team members. OWASP project leaders are responsible for defining the vision, roadmap, and tasks for the project. The project leader also promotes the project and builds the team. Tools and documents are organized into the following categories:
| |
− | PROTECT - These are tools and documents that can be used to guard against security-related design and implementation flaws.
| |
− | DETECT - These are tools and documents that can be used to find security-related design and implementation flaws.
| |
− | LIFE CYCLE - These are tools and documents that can be used to add security-related activities into the Software Development Life Cycle (SDLC).
| |
− | | |
− | <hr><br> '''Protect: '''
| |
− | | |
− | {| style="width:100%" border="0" align="center"
| |
− | ! colspan="4" align="center" style="background:#FFFFFF color:white"|<font color="white">
| |
− | '''[[:Category:OWASP_Guide_Project|OWASP Development Guide]]'''
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Beginner'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Experienced'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Expert'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |}
| |
− | {| style="width:100%" border="0" align="center"
| |
− | ! colspan="4" align="center" style="background:#FFFFFF color:white"|<font color="white">
| |
− | '''[[:Category:OWASP_Ruby_on_Rails_Security_Guide_V2|OWASP Ruby on Rails Security Guide V2]]'''
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Beginner'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Experienced'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Expert'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |}
| |
− | | |
− | | |
− | <br>''' Detect:'''
| |
− | | |
− | {| style="width:100%" border="0" align="center"
| |
− | ! colspan="4" align="center" style="background:#FFFFFF color:white"|<font color="white">
| |
− | '''[[:Category:OWASP_Code_Review_Project|OWASP Code Review Guide]]'''
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Beginner'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Experienced'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Expert'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |}
| |
− | {| style="width:100%" border="0" align="center"
| |
− | ! colspan="4" align="center" style="background:#FFFFFF color:white"|<font color="white">
| |
− | '''[[:Category:OWASP_Testing_Project|OWASP Testing Guide]]'''
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Beginner'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Experienced'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Expert'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |}
| |
− | {| style="width:100%" border="0" align="center"
| |
− | ! colspan="4" align="center" style="background:#FFFFFF color:white"|<font color="white">
| |
− | '''[[:Category:OWASP_Top_Ten_Project|OOWASP Top Ten Project]]'''
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Beginner'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Experienced'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Expert'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |}
| |
− | | |
− | <br>''' Life Cycle:'''
| |
− | | |
− | {| style="width:100%" border="0" align="center"
| |
− | ! colspan="4" align="center" style="background:#FFFFFF color:white"|<font color="white">
| |
− | '''[[:Category:OWASP_AppSec_FAQ_Project|OWASP AppSec FAQ Project]]'''
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Beginner'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Experienced'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Expert'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |}
| |
− | {| style="width:100%" border="0" align="center"
| |
− | ! colspan="4" align="center" style="background:#FFFFFF color:white"|<font color="white">
| |
− | '''[[:Category:OWASP_Legal_Project|OWASP Legal Project]]'''
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Beginner'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Experienced'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Expert'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |}
| |
− | {| style="width:100%" border="0" align="center"
| |
− | ! colspan="4" align="center" style="background:#FFFFFF color:white"|<font color="white">
| |
− | '''[[:Category:OWASP_Source_Code_Review_OWASP_Projects_Project|OWASP Source Code Review for OWASP-Projects]]'''
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Beginner'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Experienced'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Expert'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |}
| |
− | <br>
| |
− | | |
− | ==== CLASP roles ====
| |
− | [http://www.owasp.org/index.php/Category:OWASP_CLASP_Project '''CLASP'''] (Comprehensive, Lightweight Application Security Process) provides a well-organized and structured approach for moving security concerns into the early stages of the software development lifecycle, whenever possible.
| |
− | | |
− | {| style="width:100%" border="0" align="center"
| |
− | ! colspan="4" align="center" style="background:#FFFFFF color:white"|<font color="white">'''[[Architect]]'''
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Beginner'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Experienced'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Expert'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |}
| |
− | {| style="width:100%" border="0" align="center"
| |
− | ! colspan="4" align="center" style="background:#FFFFFF color:white"|<font color="white">'''[[Designer]]'''
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Beginner'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Experienced'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Expert'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |}
| |
− | {| style="width:100%" border="0" align="center"
| |
− | ! colspan="4" align="center" style="background:#FFFFFF color:white"|<font color="white">'''[[Implementer]]'''
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Beginner'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Experienced'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Expert'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |}
| |
− | {| style="width:100%" border="0" align="center"
| |
− | ! colspan="4" align="center" style="background:#FFFFFF color:white"|<font color="white">'''[[Project Manager]]'''
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Beginner'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Experienced'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Expert'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |}
| |
− | {| style="width:100%" border="0" align="center"
| |
− | ! colspan="4" align="center" style="background:#FFFFFF color:white"|<font color="white">'''[[Requirements Specifier]]'''
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Beginner'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Experienced'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Expert'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |}
| |
− | {| style="width:100%" border="0" align="center"
| |
− | ! colspan="4" align="center" style="background:#FFFFFF color:white"|<font color="white">'''[[Security Auditor]]'''
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Beginner'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Experienced'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Expert'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |}
| |
− | {| style="width:100%" border="0" align="center"
| |
− | ! colspan="4" align="center" style="background:#FFFFFF color:white"|<font color="white">'''[[Test Analyst]]'''
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Beginner'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Experienced'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |-
| |
− | | style="width:25%; background:#7B8ABD" align="left"| '''Expert'''
| |
− | | colspan="3" style="width:75%; background:#cccccc" align="left"|
| |
− | * training material
| |
− | |}
| |
− | | |
− | ==== SAMM Disciplines & Functions ====
| |
− | {| {{Template:Education Table Header | title = '''Alignment & Governance'''}}
| |
− | {{Template:Education Table Row | title = Education & Guidance | text = * training material}}
| |
− | {{Template:Education Table Row | title = Standards & Compliance | text = * training material}}
| |
− | {{Template:Education Table Row | title = Strategic Planning | text = * training material}}
| |
− | |}
| |
− | {| {{Template:Education Table Header | title = '''Requirements & Design'''}}
| |
− | {{Template:Education Table Row | title = Threat Modeling | text = * training material}}
| |
− | {{Template:Education Table Row | title = Security Requirements | text = * training material}}
| |
− | {{Template:Education Table Row | title = Defensive Design | text = * training material}}
| |
− | |}
| |
− | {| {{Template:Education Table Header | title = '''Verification & Assessment'''}}
| |
− | {{Template:Education Table Row | title = Architecture Review | text = * training material}}
| |
− | {{Template:Education Table Row | title = Code Review | text = * training material}}
| |
− | {{Template:Education Table Row | title = Security Testing | text = * training material}}
| |
− | |}
| |
− | {| {{Template:Education Table Header | title = '''Deployment & Operations'''}}
| |
− | {{Template:Education Table Row | title = Vulnerability Management | text = * training material}}
| |
− | {{Template:Education Table Row | title = Infrastructure Hardening | text = * training material}}
| |
− | {{Template:Education Table Row | title = Operational Enablement
| |
− | * beginner
| |
− | * intermediate
| |
− | * expert | text = * training material}}
| |
− | |}
| |
| | | |
| __NOTOC__ | | __NOTOC__ |
Below you find the education material categorized by profession and interest.