Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



WebApp Sec: RE: OWASP Top Ten - The certification and blame problem

RE: OWASP Top Ten - The certification and blame problem

From: Steven M. Christey <coley_at_mitre.org>
Date: Thu, 14 Jul 2005 00:24:28 -0400 (EDT)

I think the continued notion of a "Top Ten" is a great one, especially
with respect to visibility and with at least identifying the most
frequent and glaring errors. Maybe it could be called the "Bare
Minimum Ten" or something like that. That's what the current Top Ten
is really talking about, right? The low-hanging fruit?

By its name, a "Minimum Ten" implies that if that's all you're
covering, it's not enough.

- Steve
Received on Jul 13 2005

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]