Daily using/supporting

Get Firefox browser!
Get Thunderbird!
Get Opera browser!
Get The Gimp!
Get Inkscape!
Get LibreOffice!
Get Videolan!
Get Linux!
Get Mandriva!
Get Joomla!
Hacker Emblem

Archives

Which topics would you like us to cover more?

Latest comments

Latest tweets

about 1 day ago Using REDIPS.drag to add drag and drop to your .Net webapplication #li #dib0 http://t.co/n8zY3s7d
about 7 days ago http://t.co/cknQcDbo #Kindle
about 15 days ago Freedom isn't the ability to choose what to do or say, but the ability to choose what not to do or say #freedom
about 29 days ago http://t.co/61KTQknI #Kindle
12 Apr 2012 Force the use of a networking adapter using C# #li #dib0 http://t.co/ZTJOPzOz
9 Apr 2012 Mandriva 2010.2 and USB devices in Virtualbox http://t.co/fwq9gbHB
9 Apr 2012 Execute a http request to you own site with PHP http://t.co/DIvWPrpd
Home Architecture, security and coding How to verify the security of your application: the OWASP standard
How to verify the security of your application: the OWASP standard
Written by Division by Zero   
Thursday, 21 October 2010 13:00

You're thinking about security. That's a good thing! Maybe you are looking at using a secure development process like SDL or CLASP, but still wondering how you are able to verify the security status of your software?

OWASP gives you the Application Security Verification Standard (ASVS). This standard provides guidelines on how to test and verify the security of your software. There are 4 levels of verification which you reach if you fulfill the requirements for that level (page 16) and handle or mitigate threat signaled by the verification process.

How do you use this standard? At first you'll have to determine an configure the right tools that fit your needs and environment. If you have these set up you can use the levels described in the standard as a non-functional requirement for the application you are building. Know the tools and use them to verify the 'secure state' of your application.

 

Add comment


Security code
Refresh

If the human brain was simple enough for us to understand we'd be so simple we couldn't understand. - Unknown


© 2009 - 2012, Division by Zero

Template based on the empire template by joomlashack 

Valid XHTML 1.0 Strict  Valid CSS!  Creative Commons License
This work by Division by Zero is licensed under a Creative Commons Attribution-Noncommercial-Share Alike 3.0 Netherlands License.