what
|
is this project?
|
Name: OWASP Secure Web Application Framework Manifesto (home page)
|
Purpose: The Secure Web Application Framework Manifesto is a document detailing a specific set of security requirements for developers of web application frameworks to adhere to. The goal is to help develop more secure applications from the start. The manifesto centers around the following beliefs:
- Frameworks that are ‘secure by default’ will yield a dramatic reduction in the number of common web application security vulnerabilities.
- Application security experts should provide, on a regularly basis, updated guidance to framework developers on how to incorporate mechanisms to avoid newly discovered vulnerabilities.
|
License: Creative Commons Attribution ShareAlike 3.0 license
|
who
|
is working on this project?
|
Project Leader(s):
|
Project Contributor(s):
|
how
|
can you learn more?
|
Project Pamphlet: Not Yet Created
|
Project Presentation:
|
Mailing list: N/A
|
Project Roadmap: Not Yet Created
|
Main links:
|
Key Contacts
|
|
|
|
current release
|
|
SWAF Manifesto v0.08 - 01/10/2010 - (download)
|
Release description: Developers are increasingly relying on scaffolding-based systems like Rails and Django to build applications. The number of web application frameworks, scaffolding or otherwise, is constantly growing and it's becoming increasingly clear that securing these frameworks will be a major boon for the future of secure web applications.
Recognizing that many developers are gravitating to leveraging web application frameworks, we decided it was time to provide a list of positive features that these frameworks should include.
This "Secure Web Application Framework Manifesto" must, of course, be a living document. At any given point, it should provide a minimum baseline of what a web application framework should include to appeal to security-conscious developers. We contend that if such a web application framework is broadly adopted, it will have far reaching effects into web application security.
|
Rating: Not Reviewed - Assessment Details
|
|
|
last reviewed release
|
Not Yet Reviewed
|
|
|