Forum archive
OWASP Top-10
{I made this post before, but it dissapeared into the Æether}
Considering the sheer number of (frikkin' awesome) web-apps, little (or at leat too little) consideration has been given to the InfoSec (wheras that really should be the first concern).
Would there be some way to validate appliances agains the OWASP Top-10?
I'm not suggesting it's the be-all & end-all of security concerns, but it sure as hell is a very good starting-point. I'm aware that much of the issues actually reside withthe indivitual application, but TKL systems can go a very long way towards addressing any possible shortcomings & so mitigate the risks.
Once the Top-10 has been covered, it will also inherently address some of the requirements for PCI DSS.
Much of this may seem common-sense, but it's not
Ideas?
- J
OTOH, this isn't really a TurnKey specific thing. We just package these web applications. If there are security issues we should be reporting them to upstream .
So I'm somewhat unsure if this fits well with the scope of TurnKey but I'd be delighted if community members that know their way around this stuff picked up the guantlet. Come to think of it, you sound like you know what you're talking about. If you want it the job is yours... :)