Scan against OWASP top 10 vulnerabilities
464
Views
4
Comments
New
Other

To promote secure code, on the OutSystems platform, there should be an option to run the application against The Open Web Application Security Project (OWASP) OWASP top 10 vulnerabilities.

In my opinion,

  • LifeTime is the best place to run this before we tag the application and proceed with deployment to quality or production.
  • It should be configurable in a deployment plan (to make this a manual step or automatically done each time we start with tagging)
  • It MUST not stop the regular process of promoting the application to higher environments
  • It should provide the scan result and store against each application tag

Further reading: OWASP Cheat Sheet https://github.com/OWASP/CheatSheetSeries

2015-05-05 17-20-51
João Santos

Interesting Joao, so outsystems take care of OWASP. Does the platform also has metric to generate report against these checklists?

2015-05-05 17-20-51
João Santos

No, it doesn't.

Changed the category to
Other