OWASP
成立時間2001[1]
創始人Mark Curphey[1]
類型501(c)(3) Nonprofit organization
法律地位特拉华州法公司[*]
方法Industry standards, Conferences, Workshops
董事
Martin Knobloch, Chair; Chenxi Wang, Co-Chair; Andrew van der Stock, Treasurer; Owen Pendlebury, Secretary; Matt Konda; Greg Anderson; Sherif Mansour
重要人物
Karen Staley, Executive Director; Kelly Santalucia, Membership and Business Liaison; Laura Grau, Event Manager; Tiffany Long, Community Manager; Claudia Cassanovas, Project Coordinator; Dawn Aitken, Program Assistant
員工数8
志願者数
42,000+
目標Web Security, Application Security, Vulnerability Assessment
網站www.owasp.org

开放式Web应用程序安全项目OWASP)是一个在线社区,在Web应用安全英语Web application security领域提供免费的文章,方法,文档,工具和技术。[2][3]

历史

[编辑]

Mark Curphey于2001年9月9日创办了OWASP。[1] Jeff Williams从2003年底到2011年9月担任OWASP的志愿者主席。截至2015年 (2015-Missing required parameter 1=month!),Matt Konda担任董事会主席。[4]

OWASP基金会是一家成立于2004年的501(c)(3)非营利组织(美国),支持OWASP基础设施和项目。自2011年以来,OWASP还以OWASP Europe VZW的名义在比利时注册为非营利组织。[5]

出版物及资源

[编辑]

奖项

[编辑]

OWASP组织获得2014年SC杂志编辑选择奖。[3][19]

另请参阅

[编辑]

参考文献

[编辑]
  1. ^ 1.0 1.1 1.2 1.3 Huseby, Sverre. Innocent Code: A Security Wake-Up Call for Web Programmers. Wiley. 2004: 203. ISBN 0470857447. 
  2. ^ OWASP top 10 vulnerabilities. developerWorks. IBM. 20 April 2015 [28 November 2015]. (原始内容存档于2019-03-27). 
  3. ^ 3.0 3.1 SC Magazine Awards 2014 (PDF). Media.scmagazine.com. [3 November 2014]. (原始内容 (PDF)存档于2014-09-22). 
  4. ^ Board页面存档备份,存于互联网档案馆). OWASP. Retrieved on 2015-02-27.
  5. ^ OWASP Europe页面存档备份,存于互联网档案馆), OWASP, 2016
  6. ^ OWASP Top Ten Project on owasp.org. [2018-12-16]. (原始内容存档于2019-12-01). 
  7. ^ Trevathan, Matt. Seven Best Practices for Internet of Things. Database and Network Journal. 1 October 2015 [28 November 2015]. (原始内容存档于2015-11-28) –通过Template:Highbeam. 
  8. ^ Crosman, Penny. Leaky Bank Websites Let Clickjacking, Other Threats Seep In. American Banker. 24 July 2015 [28 November 2015]. (原始内容存档于2015-11-28) –通过Template:Highbeam. 
  9. ^ Pauli, Darren. Infosec bods rate app languages; find Java 'king', put PHP in bin. The Register. 4 December 2015 [4 December 2015]. (原始内容存档于2019-04-14). 
  10. ^ Payment Card Industry (PCI) Data Security Standard (PDF). PCI Security Standards Council: 55. November 2013 [3 December 2015]. (原始内容存档 (PDF)于2016-04-03). 
  11. ^ Open Web Application Security Project Top 10 (OWASP Top 10). Knowledge Database. Synopsys. Synopsys, Inc. 2017 [2017-07-20]. (原始内容存档于2019-04-06). Many entities including the PCI Security Standards Council, National Institute of Standards and Technology (NIST), and the Federal Trade Commission (FTC) regularly reference the OWASP Top 10 as an integral guide for mitigating Web application vulnerabilities and meeting compliance initiatives. 
  12. ^ Pauli, Darren. Comprehensive guide to obliterating web apps published. The Register. 18 September 2014 [28 November 2015]. (原始内容存档于2019-04-06). 
  13. ^ Baar, Hans; Smulters, Andre; Hintzbergen, Juls; Hintzbergen, Kees. Foundations of Information Security Based on ISO27001 and ISO27002 3. Van Haren. 2015: 144. ISBN 9789401800129. 
  14. ^ Category:OWASP XML Security Gateway Evaluation Criteria Project Latest. Owasp.org. [November 3, 2014]. (原始内容存档于2014-11-03). 
  15. ^ 存档副本. [2018-12-16]. (原始内容存档于2019-04-06). 
  16. ^ OWASP AppSec Pipeline. Open Web Application Security Project (OWASP). [26 February 2017]. (原始内容存档于2017-02-27). 
  17. ^ AUTOMATED THREATS to Web applications (PDF). OWASP. July 2015 [2018-12-16]. (原始内容存档 (PDF)于2018-07-11). 
  18. ^ The list of automated threat events. [2018-12-16]. (原始内容存档于2019-01-26). 
  19. ^ Winners | SC Magazine Awards. Awards.scmagazine.com. [2014-07-17]. (原始内容存档于2014-08-20). Editor's Choice [...] Winner: OWASP Foundation 

外部链接

[编辑]