Re: [Full-disclosure] Fw: [WEB SECURITY] Application Security Program



Google "STRIDE" and "DREAD" in terms of computer security; http://wiki.okopipi.org/wiki/Security_concerns

-- c0redump

----- Original Message ----- From: huan chen
To: full-disclosure@xxxxxxxxxxxxxxxxx
Sent: Friday, June 30, 2006 3:40 AM
Subject: [Full-disclosure] Fw: [WEB SECURITY] Application Security Program


forwarding to this list for opinion...

----- Original Message ----- From: "huan chen" <ktriv3di@xxxxxxx>
To: "Web Security" <websecurity@xxxxxxxxxxxxx>
Sent: Thursday, June 29, 2006 3:51 PM
Subject: [WEB SECURITY] Application Security Program


List,

We are trying to design a big picture information security program for out organization. The goal is to concentrate on application security. Sub tasks should include stuff like policy gap analysis, pen test balc box and white box, etc. The goal is to do all the activities and measure progress on an yearly basis/

Are thier any existing frameworks? Anything that has worked / not worked for you guys?

Thanks



_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • Re: [Full-disclosure] Ganging up on n3td3v
    ... doesnt stand for Fat Douches it stands for Full Disclosure. ... I see that you are an A-list blogger for the web2.o security industry ... > Full-Disclosure - We believe in it. ... Charter: http://lists.grok.org.uk/full-disclosure-charter.html ...
    (Full-Disclosure)
  • Re: [Full-disclosure] [Dailydave] Hacking software is lame -- try medical research...
    ... What did I do I just said I was gonna eat CORNdogs. ... >> What have you done for the security community ... > Full-Disclosure - We believe in it. ... Charter: http://lists.grok.org.uk/full-disclosure-charter.html ...
    (Full-Disclosure)
  • Re: [Full-disclosure] Another 0day to sell.
    ... Any good CISSP will tell you there is more to security than ... Full-Disclosure - We believe in it. ... Charter: http://lists.grok.org.uk/full-disclosure-charter.html ... Hosted and sponsored by Secunia - http://secunia.com/ ...
    (Full-Disclosure)
  • Re: [Full-disclosure] Ganging up on n3td3v
    ... I see that you are an A-list blogger for the web2.o security industry ... > Full-Disclosure - We believe in it. ... > Charter: http://lists.grok.org.uk/full-disclosure-charter.html ... Hosted and sponsored by Secunia - http://secunia.com/ ...
    (Full-Disclosure)
  • RE: [Full-Disclosure] Trojan Horse for Mac OS X
    ... [Full-Disclosure] Trojan Horse for Mac OS X ... Check out Tools, Options, Security, Do not allow executable attachments... ... Outlook Express and Outlook will strip all executable ... Charter: http://lists.netsys.com/full-disclosure-charter.html ...
    (Full-Disclosure)