<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; web-testing-criteria</title>
	<atom:link href="http://www.darknet.org.uk/tag/web-testing-criteria/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Fri, 12 Mar 2010 08:12:36 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Common Criteria Web Application Security Scoring (CCWAPSS) Released</title>
		<link>http://www.darknet.org.uk/2007/10/common-criteria-web-application-security-scoring-ccwapss-released/</link>
		<comments>http://www.darknet.org.uk/2007/10/common-criteria-web-application-security-scoring-ccwapss-released/#comments</comments>
		<pubDate>Tue, 02 Oct 2007 20:24:53 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[ccwapss]]></category>
		<category><![CDATA[hacking-web-sites]]></category>
		<category><![CDATA[Information-Security]]></category>
		<category><![CDATA[web-application-security]]></category>
		<category><![CDATA[web-application-testing]]></category>
		<category><![CDATA[web-security]]></category>
		<category><![CDATA[web-testing-criteria]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2007/10/common-criteria-web-application-security-scoring-ccwapss-released/</guid>
		<description><![CDATA[The purpose of the scoring scale CCWAPSS is to share a common evaluation method for web application security assessments/pentests between security auditors and final customers.
This scale does not aim at replacing other evaluation standards but suggests a simple way of evaluating the security level of a web application.
CCWAPSS is focused on rating the security level [...]]]></description>
			<content:encoded><![CDATA[<p>The purpose of the scoring scale CCWAPSS is to share a common evaluation method for web application security assessments/pentests between security auditors and final customers.</p>
<p>This scale does not aim at replacing other evaluation standards but suggests a simple way of evaluating the security level of a web application.</p>
<p>CCWAPSS is focused on rating the security level of a distinct web application, web services or e-business platform. CCWAPSS does not aim at scoring a whole heterogenic perimeter.</p>
<p><div align="center">
<script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
google_alternate_ad_url = "http://www.darknet.org.uk/google_adsense_script.html";
google_ad_width = 336;
google_ad_height = 280;
google_ad_format = "336x280_as";
google_ad_type = "text";
google_ad_channel ="4027562844";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "df6f0b";
google_color_url = "df6f0b";
google_color_text = "000000";
//--></script>
<script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>
</div></p>
<p><strong>Key benefits of CCWAPSS</strong></p>
<ul>
<li>Fighting against the inclination of using a restricted granularity that forces the auditor to clear-cut score (there is no medium choice).</li>
<li>Offering a solution to interpretation problems between different auditors by providing clear and 11 well documented criteria.</li>
<li>The maximum score (10/10) means “compliant with Best Practices”. This score could be exceeded in case of excellence (like a medical vision evaluation such as 12/10).</li>
<li>Each criteria is relative to section of the OWASP Guide 3.0.</li>
</ul>
<p><div align="center">
<script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
google_alternate_ad_url = "http://www.darknet.org.uk/google_adsense_script.html";
google_ad_width = 336;
google_ad_height = 280;
google_ad_format = "336x280_as";
google_ad_type = "text";
google_ad_channel ="4027562844";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "df6f0b";
google_color_url = "df6f0b";
google_color_text = "000000";
//--></script>
<script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>
</div></p>
<p><strong>The 11 scoring criteria</strong></p>
<p>   1. Authentication<br />
   2. Authorization<br />
   3. User’s Input Sanitization<br />
   4. Error Handling and Information leakage<br />
   5. Passwords/PIN Complexity<br />
   6. User’s data confidentiality<br />
   7. Session mechanism<br />
   8. Patch management<br />
   9. Administration interfaces<br />
  10. Communication security<br />
  11. Third-Party services exposure</p>
<p>You can get the CCWAPSS whitepaper here:</p>
<p><a href="http://www.xmcopartners.com/whitepapers/ccwapss_1.0.pdf">CCWAPSS release 1.0 [PDF]</a></p>
<p>Or read more <a href="http://ccwapss.blogspot.com/">here</a>.</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Common+Criteria+Web+Application+Security+Scoring+%28CCWAPSS%29+Released+http://bit.ly/LF1s8+from+@THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2007/10/common-criteria-web-application-security-scoring-ccwapss-released/&amp;title=Common+Criteria+Web+Application+Security+Scoring+%28CCWAPSS%29+Released" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2007/10/common-criteria-web-application-security-scoring-ccwapss-released/&amp;title=Common+Criteria+Web+Application+Security+Scoring+%28CCWAPSS%29+Released" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2007/10/common-criteria-web-application-security-scoring-ccwapss-released/&amp;t=Common+Criteria+Web+Application+Security+Scoring+%28CCWAPSS%29+Released" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2007/10/common-criteria-web-application-security-scoring-ccwapss-released/&amp;title=Common+Criteria+Web+Application+Security+Scoring+%28CCWAPSS%29+Released" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2007/10/common-criteria-web-application-security-scoring-ccwapss-released/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
