<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Common Criteria Web Application Security Scoring (CCWAPSS) Released</title>
	<atom:link href="http://www.darknet.org.uk/2007/10/common-criteria-web-application-security-scoring-ccwapss-released/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk/2007/10/common-criteria-web-application-security-scoring-ccwapss-released/</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<pubDate>Fri, 21 Nov 2008 01:18:27 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.3</generator>
		<item>
		<title>By: dre</title>
		<link>http://www.darknet.org.uk/2007/10/common-criteria-web-application-security-scoring-ccwapss-released/#comment-68791</link>
		<dc:creator>dre</dc:creator>
		<pubDate>Thu, 25 Oct 2007 01:20:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2007/10/common-criteria-web-application-security-scoring-ccwapss-released/#comment-68791</guid>
		<description>for similar work look at the fortifysoftware metricon 2.0 talk by fred lee, &lt;a href="https://securitymetrics.org/content/attach/Metricon2.0/Lee_metricon20070807.ppt" rel="nofollow"&gt;Security Metrics in Practice: Development of a Security Metric System to Rate Enterprise Software&lt;/a&gt;.  i wasn't able to see it at metricon 2.0, but he gave the talk along with me at the &lt;a href="https://www.owasp.org/index.php/Minneapolis_St_Paul" rel="nofollow"&gt;owasp msp event&lt;/a&gt; last week.

mark cuphey and the owasp team (including chris wysopal and myself) have also been working on another set of metrics.  darkreading did an article on it called &lt;a&gt;OWASP Preps Framework for Website Security Certification&lt;/a&gt;.  wysopal is also working on a more generic vulnerability rating system using CVSS from CWE data as described in &lt;a href="https://securitymetrics.org/content/attach/Metricon2.0/Wysopal-metricon2.0-software-weakness-scoring.ppt" rel="nofollow"&gt;Software Security Weakness Scoring&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>for similar work look at the fortifysoftware metricon 2.0 talk by fred lee, <a href="https://securitymetrics.org/content/attach/Metricon2.0/Lee_metricon20070807.ppt" rel="nofollow">Security Metrics in Practice: Development of a Security Metric System to Rate Enterprise Software</a>.  i wasn&#8217;t able to see it at metricon 2.0, but he gave the talk along with me at the <a href="https://www.owasp.org/index.php/Minneapolis_St_Paul" rel="nofollow">owasp msp event</a> last week.</p>
<p>mark cuphey and the owasp team (including chris wysopal and myself) have also been working on another set of metrics.  darkreading did an article on it called <a>OWASP Preps Framework for Website Security Certification</a>.  wysopal is also working on a more generic vulnerability rating system using CVSS from CWE data as described in <a href="https://securitymetrics.org/content/attach/Metricon2.0/Wysopal-metricon2.0-software-weakness-scoring.ppt" rel="nofollow">Software Security Weakness Scoring</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>
