This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "Category:OWASP Live CD Project - AppSecEU May2009 Release - Assessment"

From OWASP
Jump to: navigation, search
 
(12 intermediate revisions by 2 users not shown)
Line 4: Line 4:
  
 
==== Project Leader for this Release ====
 
==== Project Leader for this Release ====
 +
'''''[[User:Mtesauro|Matt Tesauro]]'s Pre-Assessment Checklist:'''''
  
'''''[[User:Mtesauro|Matt Tesauro]]'s Pre-Assessment Checklist:''''' 
+
{{ Pre-Assessment Questions - Tools
  
<!-- ###############################################################################
 
    ##                                                                          ##
 
    ##          START SECTION TO BE COMPLETED BY THE PROJECT LEAD              ##
 
    ##                                                                          ##
 
    ###############################################################################-->
 
{|style="width:100%; background:#white" align="left"
 
|style="width:100%; background:#white" align="left"|'''Alpha level''' 
 
|-
 
| style="width:100%; background:#white" align="left"|
 
<!-- ############## QUESTION BELOW ############## -->
 
''1. Is your tool licensed under an open source license?''
 
----
 
<!-- ############## ANSWER YES OR NO & PROVIDE LINKS BELOW THIS LINE ############## -->
 
Delete this text and place your answer here. 
 
<!-- ############## ANSWER YES OR NO & PROVIDE LINKS ABOVE THIS LINE ############## -->
 
|- 
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|-
 
| style="width:100%; background:#white" align="left"|
 
<!-- ############## QUESTION BELOW ############## -->
 
''2. Is the source code and any documentation available in an online project repository? (e.g. Google Code or Sourceforge site)''
 
----
 
<!-- ############## ANSWER YES OR NO & PROVIDE LINKS BELOW THIS LINE ############## -->
 
Delete this text and place your answer here. 
 
<!-- ############## ANSWER YES OR NO & PROVIDE LINKS ABOVE THIS LINE ############## -->
 
|- 
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|-
 
| style="width:100%; background:#white" align="left"|
 
<!-- ############## QUESTION BELOW ############## -->
 
''3. Is there working code?''
 
----
 
<!-- ############## ANSWER YES OR NO & PROVIDE LINKS BELOW THIS LINE ############## -->
 
Delete this text and place your answer here. 
 
<!-- ############## ANSWER YES OR NO & PROVIDE LINKS ABOVE THIS LINE ############## -->
 
|-
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|-
 
| style="width:100%; background:#white" align="left"|
 
<!-- ############## QUESTION BELOW ############## -->
 
''4. Is there a roadmap for this project release which will take it from Alpha to Stable release?''
 
----
 
<!-- ############## ANSWER YES OR NO & PROVIDE LINKS BELOW THIS LINE ############## -->
 
Delete this text and place your answer here. 
 
<!-- ############## ANSWER YES OR NO & PROVIDE LINKS ABOVE THIS LINE ############## -->
 
|- 
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|-
 
| style="width:100%; background:#white" align="left"|'''Beta Level'''
 
|-
 
| style="width:100%; background:#white" align="left"|
 
<!-- ############## QUESTION BELOW ############## -->
 
''5. Are the Alpha pre-assessment items complete?''
 
----
 
<!-- ############## ANSWER YES OR & PROVIDE LINKS NO BELOW THIS LINE ############## -->
 
Delete this text and place your answer here. 
 
<!-- ############## ANSWER YES OR NO & PROVIDE LINKS ABOVE THIS LINE ############## --> 
 
|-
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|- 
 
| style="width:100%; background:#white" align="left"|
 
<!-- ############## QUESTION BELOW ############## -->
 
''6. Is there an installer or stand-alone executable?''
 
----
 
<!-- ############## ANSWER YES OR & PROVIDE LINKS NO BELOW THIS LINE ############## -->
 
Delete this text and place your answer here. 
 
<!-- ############## ANSWER YES OR NO & PROVIDE LINKS ABOVE THIS LINE ############## --> 
 
|- 
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|-
 
| style="width:100%; background:#white" align="left"|
 
<!-- ############## QUESTION BELOW ############## -->
 
''7. Is there user documentation on the OWASP project wiki page?''
 
----
 
<!-- ############## ANSWER YES OR NO & PROVIDE LINKS BELOW THIS LINE ############## -->
 
Delete this text and place your answer here. 
 
<!-- ############## ANSWER YES OR NO & PROVIDE LINKS ABOVE THIS LINE ############## --> 
 
|-
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|-
 
| style="width:100%; background:#white" align="left"|
 
<!-- ############## QUESTION BELOW ############## -->
 
''8. Is there an "About box" or similar help item which lists the following?''<br>
 
* ''Project Name''
 
* ''Short Description''
 
* ''Project Release Lead and contact information (e.g. email address)''
 
* ''Project Release Contributors (if any)''
 
* ''Project Release License''
 
* ''Project Release Sponsors (if any)''
 
* ''Release status and date assessed as Month-Year (e.g. March 2009)''
 
* ''Link to OWASP Project Page<br> ''
 
----
 
<!-- ############## ANSWER YES OR & PROVIDE LINKS NO BELOW THIS LINE ############## -->
 
Delete this text and place your answer here. 
 
<!-- ############## ANSWER YES OR NO & PROVIDE LINKS ABOVE THIS LINE ############## -->
 
|-
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|-
 
| style="width:100%; background:#white" align="left"|
 
<!-- ############## QUESTION BELOW ############## -->
 
''9. Is there documentation on how to build the tool from source including obtaining the source from the code repository?''
 
----
 
<!-- ############## ANSWER YES OR NO & PROVIDE LINKS BELOW THIS LINE ############## -->
 
Delete this text and place your answer here. 
 
<!-- ############## ANSWER YES OR NO & PROVIDE LINKS ABOVE THIS LINE ############## --> 
 
|-
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|-
 
| style="width:100%; background:#white" align="left"|
 
<!-- ############## QUESTION BELOW ############## -->
 
''10. Is the tool documentation stored in the same repository as the source code?''
 
----
 
<!-- ############## ANSWER YES OR NO & PROVIDE LINKS BELOW THIS LINE ############## -->
 
Delete this text and place your answer here. 
 
<!-- ############## ANSWER YES OR NO & PROVIDE LINKS ABOVE THIS LINE ############## --> 
 
|-
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|-
 
| style="width:100%; background:#white" align="left"|'''Stable Level'''
 
|-
 
| style="width:100%; background:#white" align="left"|
 
<!-- ############## QUESTION BELOW ############## -->
 
''11. Are the Alpha and Beta pre-assessment items complete?''
 
----
 
<!-- ############## ANSWER YES OR NO & PROVIDE LINKS BELOW THIS LINE ############## -->
 
Delete this text and place your answer here. 
 
<!-- ############## ANSWER YES OR NO & PROVIDE LINKS ABOVE THIS LINE ############## -->
 
|-
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|- 
 
| style="width:100%; background:#white" align="left"|
 
<!-- ############## QUESTION BELOW ############## -->
 
''12. Does the tool include documentation built into the tool?''
 
----
 
<!-- ############## ANSWER YES OR NO & PROVIDE LINKS BELOW THIS LINE ############## -->
 
Delete this text and place your answer here. 
 
<!-- ############## ANSWER YES OR NO & PROVIDE LINKS ABOVE THIS LINE ############## -->
 
|- 
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|-
 
| style="width:100%; background:#white" align="left"|
 
<!-- ############## QUESTION BELOW ############## -->
 
''13. Does the tool include build scripts to automate builds?''
 
----
 
<!-- ############## ANSWER YES OR NO & PROVIDE LINKS BELOW THIS LINE ############## -->
 
Delete this text and place your answer here. 
 
<!-- ############## ANSWER YES OR NO & PROVIDE LINKS ABOVE THIS LINE ############## -->
 
|-
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|-
 
| style="width:100%; background:#white" align="left"|
 
<!-- ############## QUESTION BELOW ############## -->
 
''14. Is there a publicly accessible bug tracking system?''
 
----
 
<!-- ############## ANSWER YES OR NO & PROVIDE LINKS BELOW THIS LINE ############## -->
 
Delete this text and place your answer here. 
 
<!-- ############## ANSWER YES OR NO & PROVIDE LINKS ABOVE THIS LINE ############## -->
 
|-
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|-
 
| style="width:100%; background:#white" align="left"|
 
<!-- ############## QUESTION BELOW ############## -->
 
''15. Have any existing limitations of the tool been documented?''
 
----
 
<!-- ############## ANSWER YES OR NO & PROVIDE LINKS BELOW THIS LINE ############## -->
 
Delete this text and place your answer here. 
 
<!-- ############## ANSWER YES OR NO & PROVIDE LINKS ABOVE THIS LINE ############## -->
 
|-
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|}
 
<br />
 
  
<!-- ###############################################################################
+
| 1. Is this release associated with a project containing at least the [[Assessing_Project_Health#Project_Wiki_Page_Minimal_Content|Project Wiki Page Minimum Content]]  information?
    ##                                                                          ##
+
= answer 1
    ##          END OF SECTION TO BE COMPLETED BY THE PROJECT LEAD              ##
+
 
    ##                                                                          ##
+
| 2. Is your tool licensed under an open source license?
    ###############################################################################-->
+
= answer 2
 +
 
 +
| 3. Is the source code and any documentation available in an online project repository?
 +
= answer 3
 +
 
 +
| 4. Is there working code?
 +
= answer 4
 +
 
 +
| 5. Is there a roadmap for this project release which will take it from Alpha to Stable release?
 +
= answer 5
 +
 
 +
| 6. Are the Alpha pre-assessment items complete?
 +
= answer 6
 +
 
 +
| 7. Is there an installer or stand-alone executable?
 +
= answer 7
 +
 +
| 8. Is there user documentation on the OWASP project wiki page?
 +
= answer 8
 +
 
 +
| 9. Is there an "About box" or similar help item which lists the following?
 +
= answer 9
 +
 
 +
| 10. Is there documentation on how to build the tool from source including obtaining the source from the code repository?
 +
= answer 10
 +
 
 +
| 11. Is the tool documentation stored in the same repository as the source code?
 +
= answer 11
 +
 
 +
| 12. Are the Alpha and Beta pre-assessment items complete?
 +
= answer 12
 +
 
 +
| 13. Does the tool include documentation built into the tool?
 +
= answer 13
 +
 
 +
| 14. Does the tool include build scripts to automate builds?
 +
= answer 14
 +
 
 +
| 15. Is there a publicly accessible bug tracking system?
 +
= answer 15
 +
 
 +
| 16. Have any existing limitations of the tool been documented?
 +
= answer 16
 +
}}
  
 
==== First Reviewer ====
 
==== First Reviewer ====
 
'''''[[User:name|First Reviewer]]'s Review:'''''<br />
 
'''''[[User:name|First Reviewer]]'s Review:'''''<br />
 
<small>Ideally, reviewers should be an existing OWASP project leader or chapter leader.</small>
 
<small>Ideally, reviewers should be an existing OWASP project leader or chapter leader.</small>
<!-- ###############################################################################
 
    ##                                                                          ##
 
    ##          START SECTION TO BE COMPLETED BY THE FIRST REVIEWER              ##
 
    ##                                                                          ##
 
    ###############################################################################-->
 
  
{|style="width:100%; background:#white" align="left"
+
{{ Assessment Questions - Tools
|style="width:100%; background:#white" align="left"|'''Beta Release Level Questions'''
+
 
|-
+
| 1. Is an installer for the tool available and easy to use? How close does it reach the goal of a fully automated installer?     = (answer #1) Delete this text and place your answer here. The same for the questions below.
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
+
 
|-
+
| 2. Is the end user documentation complete, relevant and presented on the OWASP wiki page?
| style="width:100%; background:#white" align="left"|
+
= (answer #2)
<!-- ############## QUESTION BELOW ############## -->
+
 
''1. Is an installer for the tool available and easy to use? How close does it reach the goal of a fully automated installer?''
+
|3. Does the tool have an “About box” or similar help item which allows the end user to get an overview of the state of this tool? Is this information readily available and easy to find?
----
+
= (answer #3)  
<!-- ############## RESPOND BELOW THIS LINE ############## -->
 
Delete this text and place your answer here.
 
<!-- ############## RESPOND ABOVE THIS LINE ############## -->
 
|- 
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|-
 
| style="width:100%; background:#white" align="left"|
 
<!-- ############## QUESTION BELOW ############## -->
 
''2. Is the end user documentation complete, relevant and presented on the OWASP wiki page?''
 
----
 
<!-- ############## RESPOND BELOW THIS LINE ############## -->
 
Delete this text and place your answer here.
 
<!-- ############## RESPOND ABOVE THIS LINE ############## -->
 
|- 
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|-
 
| style="width:100%; background:#white" align="left"|
 
<!-- ############## QUESTION BELOW ############## -->
 
''3. Does the tool have an “About box” or similar help item which allows the end user to get an overview of the state of this tool? Is this information readily available and easy to find?''
 
----
 
<!-- ############## RESPOND BELOW THIS LINE ############## -->
 
Delete this text and place your answer here. 
 
<!-- ############## RESPOND ABOVE THIS LINE ############## -->
 
|-
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|-
 
| style="width:100%; background:#white" align="left"|
 
<!-- ############## QUESTION BELOW ############## -->
 
''4. Does the documentation on building the source provide the necessary information and detail to allow someone to build the tool? Is there sufficient detail and information for the target user? Is there any domain specific knowledge that is assumed and not provided?''
 
----
 
<!-- ############## RESPOND BELOW THIS LINE ############## -->
 
Delete this text and place your answer here. 
 
<!-- ############## RESPOND ABOVE THIS LINE ############## -->
 
|-
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|-
 
| style="width:100%; background:#white" align="left"|
 
<!-- ############## QUESTION BELOW ############## -->
 
''5. Is the tool's documentation available with the source code and would it readily discoverable by a new user of the tool?''
 
----
 
<!-- ############## RESPOND BELOW THIS LINE ############## -->
 
Delete this text and place your answer here. 
 
<!-- ############## RESPOND ABOVE THIS LINE ############## -->
 
|-
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|-
 
| style="width:100%; background:#white" align="left"|
 
<!-- ############## QUESTION BELOW ############## -->
 
''6. Is there anything missing that is critical enough to keep the release at a alpha quality?''
 
----
 
<!-- ############## RESPOND BELOW THIS LINE ############## -->
 
Delete this text and place your answer here. 
 
<!-- ############## RESPOND ABOVE THIS LINE ############## -->
 
|-
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|-
 
| style="width:100%; background:#white" align="left"|'''Stable Release Level Questions'''
 
|-
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|-
 
| style="width:100%; background:#white" align="left"|
 
''7. Does the tool substantially address the application security issues it was created to solve?''
 
----
 
<!-- ############## RESPOND BELOW THIS LINE ############## -->
 
Delete this text and place your answer here. 
 
<!-- ############## RESPOND ABOVE THIS LINE ############## -->
 
|- 
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|-
 
| style="width:100%; background:#white" align="left"|
 
<!-- ############## QUESTION BELOW ############## -->
 
''8. Is the tool reasonably easy to use?''
 
----
 
<!-- ############## RESPOND BELOW THIS LINE ############## -->
 
Delete this text and place your answer here. 
 
<!-- ############## RESPOND ABOVE THIS LINE ############## -->
 
|-
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|-
 
| style="width:100%; background:#white" align="left"|
 
<!-- ############## QUESTION BELOW ############## -->
 
''9. Does the documentation meet the needs of the tool users and is easily found?'' 
 
----
 
<!-- ############## RESPOND BELOW THIS LINE ############## -->
 
Delete this text and place your answer here. 
 
<!-- ############## RESPOND ABOVE THIS LINE ############## -->
 
|-
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|-
 
| style="width:100%; background:#white" align="left"|
 
<!-- ############## QUESTION BELOW ############## -->
 
''10. Do the build scripts work as expected? Can you build the tool? The goal is a “One-click” build.''
 
----
 
<!-- ############## RESPOND BELOW THIS LINE ############## -->
 
Delete this text and place your answer here. 
 
<!-- ############## RESPOND ABOVE THIS LINE ############## -->
 
|-
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|-
 
| style="width:100%; background:#white" align="left"|
 
<!-- ############## QUESTION BELOW ############## -->
 
''11. Is the bug tracking system usable? Is it hosted at the same place as the source code? (e.g. Google Code, Sourceforge)''
 
----
 
<!-- ############## RESPOND BELOW THIS LINE ############## -->
 
Delete this text and place your answer here. 
 
<!-- ############## RESPOND ABOVE THIS LINE ############## -->
 
|-
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|-
 
| style="width:100%; background:#white" align="left"|
 
<!-- ############## QUESTION BELOW ############## -->
 
''12. Have you noted any limitations of the tool that are not already documented by the project lead.''
 
----
 
<!-- ############## RESPOND BELOW THIS LINE ############## -->
 
Delete this text and place your answer here. 
 
<!-- ############## RESPOND ABOVE THIS LINE ############## -->
 
|-
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|-
 
| style="width:100%; background:#white" align="left"|
 
<!-- ############## QUESTION BELOW ############## -->
 
''13. Would you consider using this tool in your day to day work assuming your professional work includes a reason to use this tool? Why or why not?''
 
----
 
<!-- ############## RESPOND BELOW THIS LINE ############## -->
 
Delete this text and place your answer here. 
 
<!-- ############## RESPOND ABOVE THIS LINE ############## -->
 
|-
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|-
 
| style="width:100%; background:#white" align="left"|
 
<!-- ############## QUESTION BELOW ############## -->
 
''14. What, if anything, is missing which would make this a more useful tool? Is what is missing critical enough to keep the release at a beta quality?''
 
----
 
<!-- ############## RESPOND BELOW THIS LINE ############## -->
 
Delete this text and place your answer here. 
 
<!-- ############## RESPOND ABOVE THIS LINE ############## -->
 
|-
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|}
 
  
<!-- ###############################################################################
+
| 4. Does the documentation on building the source provide the necessary information and detail to allow someone to build the tool? Is there sufficient detail and information for the target user? Is there any domain specific knowledge that is assumed and not provided?
    ##                                                                          ##
+
= (answer #4)
    ##        END OF SECTION TO BE COMPLETED BY THE FIRST REVIEWER              ##
+
 
    ##                                                                          ##
+
| 5. Is the tool's documentation available with the source code and would it readily discoverable by a new user of the tool?
    ###############################################################################-->
+
= (answer #5)
 +
 
 +
| 6. Is there anything missing that is critical enough to keep the release at a alpha quality?
 +
= (answer #6)
 +
 
 +
| 7. Does the tool substantially address the application security issues it was created to solve?
 +
= (answer #7)
 +
 
 +
| 8. Is the tool reasonably easy to use?
 +
= (answer #8)
 +
 
 +
| 9. Does the documentation meet the needs of the tool users and is easily found?
 +
= (answer #9)
 +
 
 +
| 10. Do the build scripts work as expected? Can you build the tool? The goal is a “One-click” build.
 +
= (answer #10)
 +
 
 +
| 11. Is the bug tracking system usable? Is it hosted at the same place as the source code? (e.g. Google Code, Sourceforge)
 +
= (answer #11)
 +
 
 +
| 12. Have you noted any limitations of the tool that are not already documented by the project lead.
 +
= (answer #12)
 +
 
 +
| 13. Would you consider using this tool in your day to day work assuming your professional work includes a reason to use this tool? Why or why not?
 +
= (answer #13)
 +
 
 +
| 14. What, if anything, is missing which would make this a more useful tool? Is what is missing critical enough to keep the release at a beta quality?
 +
= (answer #14)
 +
 
 +
}}
  
 
==== Second Reviewer ====
 
==== Second Reviewer ====
 
'''''[[User:name|Second Reviewer]]'s Review:'''''<br />
 
'''''[[User:name|Second Reviewer]]'s Review:'''''<br />
 
<small>It is recommended that an OWASP board member or Global Projects Committee member be the second reviewer on Quality releases. The board has the initial option to review the project, followed by the Global Projects Committee.</small>
 
<small>It is recommended that an OWASP board member or Global Projects Committee member be the second reviewer on Quality releases. The board has the initial option to review the project, followed by the Global Projects Committee.</small>
<!-- ###############################################################################
 
    ##                                                                          ##
 
    ##        START SECTION TO BE COMPLETED BY THE SECOND REVIEWER              ##
 
    ##                                                                          ##
 
    ###############################################################################-->
 
  
{|style="width:100%; background:#white" align="left"
+
{{ Assessment Questions - Tools
|style="width:100%; background:#white" align="left"|'''Beta Release Level Questions'''
+
 
|-
+
| 1. Is an installer for the tool available and easy to use? How close does it reach the goal of a fully automated installer?     = (answer #1) Delete this text and place your answer here. The same for the questions below.
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
+
 
|-
+
| 2. Is the end user documentation complete, relevant and presented on the OWASP wiki page?
| style="width:100%; background:#white" align="left"|
+
= (answer #2)
<!-- ############## QUESTION BELOW ############## -->
+
 
''1. Is an installer for the tool available and easy to use? How close does it reach the goal of a fully automated installer?''
+
|3. Does the tool have an “About box” or similar help item which allows the end user to get an overview of the state of this tool? Is this information readily available and easy to find?
----
+
= (answer #3)
<!-- ############## RESPOND BELOW THIS LINE ############## -->
+
 
Delete this text and place your answer here.
+
| 4. Does the documentation on building the source provide the necessary information and detail to allow someone to build the tool? Is there sufficient detail and information for the target user? Is there any domain specific knowledge that is assumed and not provided?
<!-- ############## RESPOND ABOVE THIS LINE ############## -->
+
= (answer #4)
|- 
+
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
+
| 5. Is the tool's documentation available with the source code and would it readily discoverable by a new user of the tool?
|-
+
= (answer #5)
| style="width:100%; background:#white" align="left"|
+
 
<!-- ############## QUESTION BELOW ############## -->
+
| 6. Is there anything missing that is critical enough to keep the release at a alpha quality?
''2. Is the end user documentation complete, relevant and presented on the OWASP wiki page?''
+
= (answer #6)
----
+
 
<!-- ############## RESPOND BELOW THIS LINE ############## -->
+
| 7. Does the tool substantially address the application security issues it was created to solve?
Delete this text and place your answer here.
+
= (answer #7)
<!-- ############## RESPOND ABOVE THIS LINE ############## -->
+
 
|- 
+
| 8. Is the tool reasonably easy to use?
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
+
= (answer #8)
|-
+
 
| style="width:100%; background:#white" align="left"|
+
| 9. Does the documentation meet the needs of the tool users and is easily found?
<!-- ############## QUESTION BELOW ############## -->
+
= (answer #9)
''3. Does the tool have an “About box” or similar help item which allows the end user to get an overview of the state of this tool? Is this information readily available and easy to find?''
+
 
----
+
| 10. Do the build scripts work as expected? Can you build the tool? The goal is a “One-click” build.
<!-- ############## RESPOND BELOW THIS LINE ############## -->
+
= (answer #10)
Delete this text and place your answer here. 
+
 
<!-- ############## RESPOND ABOVE THIS LINE ############## -->
+
| 11. Is the bug tracking system usable? Is it hosted at the same place as the source code? (e.g. Google Code, Sourceforge)
|-
+
= (answer #11)
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
+
 
|-
+
| 12. Have you noted any limitations of the tool that are not already documented by the project lead.
| style="width:100%; background:#white" align="left"|
+
= (answer #12)
<!-- ############## QUESTION BELOW ############## -->
+
 
''4. Does the documentation on building the source provide the necessary information and detail to allow someone to build the tool? Is there sufficient detail and information for the target user? Is there any domain specific knowledge that is assumed and not provided?''
+
| 13. Would you consider using this tool in your day to day work assuming your professional work includes a reason to use this tool? Why or why not?
----
+
= (answer #13)
<!-- ############## RESPOND BELOW THIS LINE ############## -->
 
Delete this text and place your answer here. 
 
<!-- ############## RESPOND ABOVE THIS LINE ############## -->
 
|-
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|-
 
| style="width:100%; background:#white" align="left"|
 
<!-- ############## QUESTION BELOW ############## -->
 
''5. Is the tool's documentation available with the source code and would it readily discoverable by a new user of the tool?''
 
----
 
<!-- ############## RESPOND BELOW THIS LINE ############## -->
 
Delete this text and place your answer here. 
 
<!-- ############## RESPOND ABOVE THIS LINE ############## -->
 
|-
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|-
 
| style="width:100%; background:#white" align="left"|'''Stable Release Level Questions'''
 
|-
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|-
 
| style="width:100%; background:#white" align="left"|
 
''6. Does the tool substantially address the application security issues it was created to solve?''
 
----
 
<!-- ############## RESPOND BELOW THIS LINE ############## -->
 
Delete this text and place your answer here. 
 
<!-- ############## RESPOND ABOVE THIS LINE ############## -->
 
|- 
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|-
 
| style="width:100%; background:#white" align="left"|
 
<!-- ############## QUESTION BELOW ############## -->
 
''7. Is the tool reasonably easy to use?''
 
----
 
<!-- ############## RESPOND BELOW THIS LINE ############## -->
 
Delete this text and place your answer here. 
 
<!-- ############## RESPOND ABOVE THIS LINE ############## -->
 
|-
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|-
 
| style="width:100%; background:#white" align="left"|
 
<!-- ############## QUESTION BELOW ############## -->
 
''8. Does the documentation meet the needs of the tool users and is easily found?'' 
 
----
 
<!-- ############## RESPOND BELOW THIS LINE ############## -->
 
Delete this text and place your answer here. 
 
<!-- ############## RESPOND ABOVE THIS LINE ############## -->
 
|-
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|-
 
| style="width:100%; background:#white" align="left"|
 
<!-- ############## QUESTION BELOW ############## -->
 
''9. Do the build scripts work as expected? Can you build the tool? The goal is a “One-click” build.''
 
----
 
<!-- ############## RESPOND BELOW THIS LINE ############## -->
 
Delete this text and place your answer here. 
 
<!-- ############## RESPOND ABOVE THIS LINE ############## -->
 
|-
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|-
 
| style="width:100%; background:#white" align="left"|
 
<!-- ############## QUESTION BELOW ############## -->
 
''10. Is the bug tracking system usable? Is it hosted at the same place as the source code? (e.g. Google Code, Sourceforge)''
 
----
 
<!-- ############## RESPOND BELOW THIS LINE ############## -->
 
Delete this text and place your answer here. 
 
<!-- ############## RESPOND ABOVE THIS LINE ############## -->
 
|-
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|-
 
| style="width:100%; background:#white" align="left"|
 
<!-- ############## QUESTION BELOW ############## -->
 
''11. Have you noted any limitations of the tool that are not already documented by the project lead.''
 
----
 
<!-- ############## RESPOND BELOW THIS LINE ############## -->
 
Delete this text and place your answer here. 
 
<!-- ############## RESPOND ABOVE THIS LINE ############## -->
 
|-
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|-
 
| style="width:100%; background:#white" align="left"|
 
<!-- ############## QUESTION BELOW ############## -->
 
''12. Would you consider using this tool in your day to day work assuming your professional work includes a reason to use this tool? Why or why not?''
 
----
 
<!-- ############## RESPOND BELOW THIS LINE ############## -->
 
Delete this text and place your answer here. 
 
<!-- ############## RESPOND ABOVE THIS LINE ############## -->
 
|-
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|-
 
| style="width:100%; background:#white" align="left"|
 
<!-- ############## QUESTION BELOW ############## -->
 
''13. What, if anything, is missing which would make this a more useful tool? Is what is missing critical enough to keep the release at a beta quality?''
 
----
 
<!-- ############## RESPOND BELOW THIS LINE ############## -->
 
Delete this text and place your answer here. 
 
<!-- ############## RESPOND ABOVE THIS LINE ############## -->
 
|-
 
| style="width:100%; background:#C2C2C2" align="left"|<!-- Provides a spacer -->
 
|}
 
  
<!-- ###############################################################################
+
| 14. What, if anything, is missing which would make this a more useful tool? Is what is missing critical enough to keep the release at a beta quality?
    ##                                                                          ##
+
= (answer #14)
    ##        END OF SECTION TO BE COMPLETED BY THE SECOND REVIEWER              ##
 
    ##                                                                          ##
 
    ###############################################################################-->
 
  
 +
}}
  
 
__NOTOC__
 
__NOTOC__
 
<headertabs/>
 
<headertabs/>

Latest revision as of 18:24, 10 July 2009

Click here to return to project's main page

Stable Release Review of the OWASP Live CD AppSecEU May2009 Release

Project Leader for this Release

Matt Tesauro's Pre-Assessment Checklist:

(This FORM is EDITED via a template)

Alpha level

1. Is this release associated with a project containing at least the Project Wiki Page Minimum Content information?


answer 1

2. Is your tool licensed under an open source license? Please point out the link(s).


answer 2

3. Is the source code and any documentation available in an online project repository? (e.g. Google Code or Sourceforge site) Please point out the link(s).


answer 3

4. Is there working code? Please point out the link(s).


answer 4

5. Is there a roadmap for this project release which will take it from Alpha to Stable release? Please point out the link(s).


answer 5

Beta Level

6. Are the Alpha pre-assessment items complete?


answer 6

7. Is there an installer or stand-alone executable? Please point out the link(s).


answer 7

8. Is there user documentation on the OWASP project wiki page? Please point out the link(s).


answer 8

9. Is there an "About box" or similar help item which lists the following? Please point out the link(s).

  • Project Name
  • Short Description
  • Project Release Lead and contact information (e.g. email address)
  • Project Release Contributors (if any)
  • Project Release License
  • Project Release Sponsors (if any)
  • Release status and date assessed as Month-Year (e.g. March 2009)
  • Link to OWASP Project Page

answer 9

10. Is there documentation on how to build the tool from source including obtaining the source from the code repository? Please point out the link(s).


answer 10

11. Is the tool documentation stored in the same repository as the source code? Please point out the link(s).


answer 11

Stable Level

12. Are the Alpha and Beta pre-assessment items complete?


answer 12

13. Does the tool include documentation built into the tool? Please point out the link(s).


answer 13

14. Does the tool include build scripts to automate builds? Please point out the link(s)


answer 14

15. Is there a publicly accessible bug tracking system? Please point out the link(s).


answer 15

16. Have any existing limitations of the tool been documented? Please point out the link(s).


answer 16


First Reviewer

First Reviewer's Review:
Ideally, reviewers should be an existing OWASP project leader or chapter leader.

(This FORM is EDITED via a template)

Beta Release Level Questions

1. Is an installer for the tool available and easy to use? How close does it reach the goal of a fully automated installer?


(answer #1) Delete this text and place your answer here. The same for the questions below.

2. Is the end user documentation complete, relevant and presented on the OWASP wiki page?


(answer #2)

3. Does the tool have an “About box” or similar help item which allows the end user to get an overview of the state of this tool? Is this information readily available and easy to find?


(answer #3)

4. Does the documentation on building the source provide the necessary information and detail to allow someone to build the tool? Is there sufficient detail and information for the target user? Is there any domain specific knowledge that is assumed and not provided?


(answer #4)

5. Is the tool's documentation available with the source code and would it readily discoverable by a new user of the tool?


(answer #5)

6. Is there anything missing that is critical enough to keep the release at a alpha quality?


(answer #6)

Stable Release Level Questions

7. Does the tool substantially address the application security issues it was created to solve?


(answer #7)

8. Is the tool reasonably easy to use?


(answer #8)

9. Does the documentation meet the needs of the tool users and is easily found?


(answer #9)

10. Do the build scripts work as expected? Can you build the tool? The goal is a “One-click” build.


(answer #10)

11. Is the bug tracking system usable? Is it hosted at the same place as the source code? (e.g. Google Code, Sourceforge)


(answer #11)

12. Have you noted any limitations of the tool that are not already documented by the project lead.


(answer #12)

13. Would you consider using this tool in your day to day work assuming your professional work includes a reason to use this tool? Why or why not?


(answer #13)

14. What, if anything, is missing which would make this a more useful tool? Is what is missing critical enough to keep the release at a beta quality?


(answer #14)

Second Reviewer

Second Reviewer's Review:
It is recommended that an OWASP board member or Global Projects Committee member be the second reviewer on Quality releases. The board has the initial option to review the project, followed by the Global Projects Committee.

(This FORM is EDITED via a template)

Beta Release Level Questions

1. Is an installer for the tool available and easy to use? How close does it reach the goal of a fully automated installer?


(answer #1) Delete this text and place your answer here. The same for the questions below.

2. Is the end user documentation complete, relevant and presented on the OWASP wiki page?


(answer #2)

3. Does the tool have an “About box” or similar help item which allows the end user to get an overview of the state of this tool? Is this information readily available and easy to find?


(answer #3)

4. Does the documentation on building the source provide the necessary information and detail to allow someone to build the tool? Is there sufficient detail and information for the target user? Is there any domain specific knowledge that is assumed and not provided?


(answer #4)

5. Is the tool's documentation available with the source code and would it readily discoverable by a new user of the tool?


(answer #5)

6. Is there anything missing that is critical enough to keep the release at a alpha quality?


(answer #6)

Stable Release Level Questions

7. Does the tool substantially address the application security issues it was created to solve?


(answer #7)

8. Is the tool reasonably easy to use?


(answer #8)

9. Does the documentation meet the needs of the tool users and is easily found?


(answer #9)

10. Do the build scripts work as expected? Can you build the tool? The goal is a “One-click” build.


(answer #10)

11. Is the bug tracking system usable? Is it hosted at the same place as the source code? (e.g. Google Code, Sourceforge)


(answer #11)

12. Have you noted any limitations of the tool that are not already documented by the project lead.


(answer #12)

13. Would you consider using this tool in your day to day work assuming your professional work includes a reason to use this tool? Why or why not?


(answer #13)

14. What, if anything, is missing which would make this a more useful tool? Is what is missing critical enough to keep the release at a beta quality?


(answer #14)


This category currently contains no pages or media.