This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

OWASP ISO IEC 27034 Application Security Controls Project

From OWASP
Revision as of 16:27, 9 December 2015 by Brennan (talk | contribs) (Volunteers)

(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to: navigation, search
OWASP Inactive Banner.jpg

OWASP ISO/IEC 27034 Application Security Controls Project

OWASP ISO/IEC 27034 Application Security Controls Project is an effort to do the conversion of OWASP related documentations and best practices, such as the OWASP Top 10, in Application Security Controls (ASCs) as defined in ISO/IEC 27034. This will enable 27034 stakeholders to use formal structure of OWASP content.

Introduction to ISO/IEC 27034

ISO/IEC 27034 offers guidance on information security to those specifying, designing/programming or procuring, implementing and using application systems, in other words business and IT managers, developers and auditors, and ultimately the end-users of application systems. The aim is to ensure that computer applications deliver the desired/necessary level of security in support of the organization’s Information Security Management System.

It is aimed at architects, analysts, programmers, testers, IT Team, DBA, Admins, etc., who need to know what and when Application Security Controls should be applied, integrate Application Security Controls in their activities, meet the requirements of the Application Security Controls associated measurements, get access to tools and best practices and facilitate peer review.

It can also be used by auditors, in order to know the scope and process of verification measurements for the corresponding Application Security Controls, make audit results repeatable, identify a list of verification measurements which can generate supporting evidence to demonstrate that the application has reached the required level of trust authorized by the management and standardize the application security verification.

27034 is based upon the following key principles:

  • Security is a requirement
  • Application security is context-dependent
  • Appropriate investment for application security
  • Application security must be demonstrated

http://www.iso27001security.com/html/27034.html

Description of the OWASP project

ISO/IEC 27034 do not propose any Application Security Controls by itself, nor any coding/testing best practices. OWASP is a good match to 27034 because it is proposing many best practices and technical details that can be used to create ASCs.

At the beginning of our roadmap, the focus will be upon the conversion of the latest OWASP Top 10 into ASCs.


Licensing

OWASP ISO/IEC 27034 Application Security Controls are free to use. It is licensed under the GNU LGPL v3 License (http://www.gnu.org/licenses/lgpl.html) that is similar to GPL but modified for use with libraries that may be called by other proprietary programs.


What this project provides?

OWASP ISO/IEC 27034 Application Security Controls Project provides:

  • XML files following the schema and guidelines provided by ISO/IEC 27034-5.1
  • Ways to formally comply with OWASP best practices such as the Top 10

Presentation

Slides in English on SpeakerDeck

Presentation in French, English version will be available soon:

Introduction to ISO 27034 also in French on YouTube


Project Co-Leaders

  • Luc Poulin
  • Jonathan Marcil


Related Projects


Quick Download

Files will be available on GitHub.

News and Events

  • [6 Jan 2014] First wiki drafts
  • [17 Dec 2013] Official OWASP Project created
  • [2 Dec 2013] Kick off on the project at OWASP Montreal

Classifications

Owasp-incubator-trans-85.png Owasp-builders-small.png
Lgplv3-147x51.png
Project Type Files CODE.jpg
Is this a contribution on the ISO/IEC standard?
Not at all. It is using the standard in order to make available OWASP content in a formal format and logically compatible way with 27034.
As OWASP members, can we get access to the standard for free?
No, but the team is there to support anyone who wants to contribute by giving their insight about the standard. Note that no OWASP content will be directly refered in the standard, it's really at an implementation level that this project applies.


Volunteers

OWASP ISO/IEC 27034 Application Security Controls project is developed by a worldwide team of volunteers. The primary contributors to date have been:

  • Bruno Guay
  • Daniel Sinnig
  • Luc Poulin
  • Jonathan Marcil
  • Tom Brennan
  • _________________

Supporting organizations

  • Cogentas
  • Desjardins
  • Nurun
  • OWASP Montreal

1. Kick-start at OWASP Montreal in order to find contributors (already in progress).

2. Starts with the OWASP Top 10 2013 and chose some number of the Top 10 and work on them.

3. Provide a platform and a review team in order to support various contributions.

4. Release work in progress conversion of Top 10.

5. Have French, English and Spanish versions of the ASCs.

6. Finish the Top 10 2013 conversion to 27034 and final release.

7. Look for others projects that could be converted.


Involvement in the development and promotion of OWASP ISO/IEC 27034 Application Security Controls Project is actively encouraged!

Some of the ways you can help:

  • Give your opinion on how we should implement controls
  • Use the ASCs in order to implements OWASP best practices and give feedback
  • Participate in the elaboration of ASCs

You can use our official mailing list to reach us or to be in touch with updates: https://lists.owasp.org/mailman/listinfo/owasp_iso_iec_27034_application_security_controls_project


PROJECT INFO
What does this OWASP project offer you?
RELEASE(S) INFO
What releases are available for this project?
what is this project?
Name: OWASP ISO/IEC 27034 Application Security Controls Project
Purpose: Conversion of OWASP related documentations and best practices, such as the OWASP Top 10, in Application Security Controls (ASCs) as defined in ISO/IEC 27034. This will enable 27034 stakeholders to use formal structure of OWASP content.
License: GNU LGPL v3 License (similar to GPL but modified for use with libraries that may be called by other proprietary programs)
who is working on this project?
Project Leader(s):
  • Jonathan Marcil @
  • Luc Poulin @
how can you learn more?
Project Pamphlet: Not Yet Created
Project Presentation:
Mailing list: Mailing List Archives
Project Roadmap: View
Key Contacts
  • Contact Jonathan Marcil @ to contribute to this project
  • Contact Jonathan Marcil @ to review or sponsor this project
current release
Not Yet Published
last reviewed release
Not Yet Reviewed


other releases