This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
OWASP Assimilation Project
Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project. OWASP Assimilation Project SummaryMany people compare securing systems against attackers as a form of warfare. In The Art of War, Sun Tzu said "If you know your enemies and know yourself, you will not be imperiled in a hundred battles". The Assimilation helps you know yourself - your systems, networks, configurations in great detail, and then keeps it all that information continually up to date in a graph-based Configuration Management Database. Here are a few of the kinds of things we track for you:
This is all done in a highly scalable way which cannot set off network security alarms and requires minimal human configuration. In addition, we continually evaluate system configurations against best practices from the IT Best Practices project and compute risk scores for servers based on how they compare to security best practices. Since everything is stored in the Neo4J graph database, visualizations of things like your attack surface are natural and straightforward. The project includes event APIs and canned queries. Future plans include:
DescriptionContinuous security verification. Our community creates best practices, translates them into code, and then our software continually verifies them in near real-time. This includes verification of the status of security patches. LicensingThis program is free software: you can redistribute it and/or modify it under the terms of the GNU GPL v3 License as published by the Free Software Foundation. |
Project ResourcesProject Home Page and Documentation Project LeaderProject leader: Alan Robertson Related ProjectsThis is where you can link to other OWASP Projects that are similar to yours. Classifications |
News and EventsThis is where you can provide project updates, links to any events like conference presentations, Project Leader interviews, case studies on successful project implementations, and articles written about your project.
|
Many projects have "Frequently Asked Questions" documents or pages. However, the point of such a document is not the questions. The point of a document like this are the answers. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'
How can I participate in your project?
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key.
If I am not a programmer can I participate in your project?
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for researchers, writers, graphic designers, and a project administrator. See the Road Map and Getting Involved tab for more details.
Contributors
The success of OWASP is due to a community of enthusiasts and contributors that work to make our projects great. This is also true for the success of your project. Be sure to give credit where credit is due, no matter how small! This should be a brief list of the most amazing people involved in your project. Be sure to provide a link to a complete list of all the amazing people in your project's community as well.
The OWASP Tool Project Template is developed by a worldwide team of volunteers. A live update of project contributors is found here.
The first contributors to the project were:
- Colin Watson who created the OWASP Cornucopia project that the template was derived from
- Chuck Cooper who edited the template to convert it from a documentation project to a Tool Project Template
- YOUR NAME BELONGS HERE AND YOU SHOULD REMOVE THE PRIOR 3 NAMES
Roadmap
There are a variety of roadmap-related artifacts on the project's Trello boards. You can find them here: https://trello.com/b/KKs4rI8g/assimilation-features-current-and-desired https://trello.com/b/98QrdEK1/issues-bugs https://trello.com/b/Vn6MtFMw/user-stories https://trello.com/b/OpaED3AT/assimilation-project https://trello.com/b/CqjvMapu/best-practices
You can also read more about the project's "current thinking" in the mailing list archives: http://lists.community.tummy.com/pipermail/assim-devel/ and http://lists.community.tummy.com/pipermail/assimilation/
Getting Involved
Involvement in the development and promotion of Assimilation Project is actively encouraged! You do not have to be a security expert or a programmer to contribute. Some of the ways you can help are as follows:
Coding
Localization
Testing
Feedback
- What do like?
- What don't you like?
- What features would you like to see prioritized on the roadmap?
This page is where you should indicate what is the minimum set of functionality that is required to make this a useful product that addresses your core security concern. Defining this information helps the project leader to think about what is the critical functionality that a user needs for this project to be useful, thereby helping determine what the priorities should be on the roadmap. And it also helps reviewers who are evaluating the project to determine if the functionality sufficiently provides the critical functionality to determine if the project should be promoted to the next project category.
The Tool Project Template must specify the minimum set of tabs a project should have, provide some an example layout on each tab, provide instructional text on how a project leader should modify the tab, and give some example text that illustrates how to create an actual project.
It would also be ideal if the sample text was translated into different languages.
This page is where you need to place your legacy project template page if your project was created before October 2013. To edit this page you will need to edit your project information template. You can typically find this page by following this address and substituting your project name where it says "OWASP_Example_Project". When in doubt, ask the OWASP Projects Manager. Example template page: https://www.owasp.org/index.php/Projects/OWASP_Example_Project
PROJECT INFO What does this OWASP project offer you? |
RELEASE(S) INFO What releases are available for this project? | |||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|