Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Pen-Test
[Top] [All Lists]

Announcement : CCWAPSS methodology release 1.1

Subject: Announcement : CCWAPSS methodology release 1.1
Date: Wed, 7 Nov 2007 21:50:16 +0100
Greetings,

I'm pleased to announce the release of the latest version of the Common Criteria Web Application Security Scoring : CCWAPSS v1.1.

This update clarifies the rating process when rating multiple flaws associated to the same criteria.

CCWAPSS
=========

CCWAPSS is a comprehensive security scoring methodolody dedicated to web application pentests.
This scale aims at sharing a common, open and documented evaluation methodology between security auditors and final customers.


Key benefits of CCWAPSS
=====================
- Offering a solution to interpretation problems between different auditors by providing clear and 11 well documented criteria.
- Fighting against the "gaussienne" inclination using a restricted granularity that forces the auditor to clear-cut score (there is no medium choice).
- The maximum score (10/10) means "compliant with Best Practices". This score could be exceeded in case of excellence (like a medical vision evaluation such as 12/10).
- Each criteria is relative to section of the OWASP Guide 3.0.


The CCWAPSS v1.1 whitepaper is available in PDF format at http://ccwapss.blogspot.com/ .

Comments and suggestions are always welcome

Regards, Fred.


------------------------------------------------------------------------ This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------

<Prev in Thread] Current Thread [Next in Thread>
  • Announcement : CCWAPSS methodology release 1.1, Frederic Charpentier <=