<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-7784275687535954642</id><updated>2012-01-22T17:59:05.576-08:00</updated><title type='text'>Common Criteria Web Application Security Scoring</title><subtitle type='html'>A comprehensive security scoring method for web applications</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://ccwapss.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7784275687535954642/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://ccwapss.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Fred</name><uri>http://www.blogger.com/profile/09157392358166457109</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-rMt5x-wPzWo/Tj0Z9LyyXvI/AAAAAAAAAnE/cvDEPyYM4fw/s220/screenshot_01.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>4</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7784275687535954642.post-3700556316022058165</id><published>2007-08-24T04:33:00.000-07:00</published><updated>2007-08-27T01:06:54.973-07:00</updated><title type='text'>CCWAPSS : Pentest and score the security level of a webapps</title><content type='html'>The purpose of the scoring scale CCWAPSS  is to share a &lt;span style="font-weight:bold;"&gt;common evaluation method&lt;/span&gt; for web application security assessments/pentests between security auditors and final customers.&lt;br /&gt;&lt;br /&gt;This scale does not aim at replacing other evaluation standards but suggests a simple way of evaluating the &lt;span style="font-weight:bold;"&gt;security level of a web application&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;CCWAPSS is focused on rating the security level of a distinct web application, web services or e-business platform. CCWAPSS does not aim at scoring a whole heterogenic perimeter.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7784275687535954642-3700556316022058165?l=ccwapss.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ccwapss.blogspot.com/feeds/3700556316022058165/comments/default' title='Publier les commentaires'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7784275687535954642&amp;postID=3700556316022058165' title='11 commentaires'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7784275687535954642/posts/default/3700556316022058165'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7784275687535954642/posts/default/3700556316022058165'/><link rel='alternate' type='text/html' href='http://ccwapss.blogspot.com/2007/08/ccwapss-assess-and-score-security-level.html' title='CCWAPSS : Pentest and score the security level of a webapps'/><author><name>Fred</name><uri>http://www.blogger.com/profile/09157392358166457109</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-rMt5x-wPzWo/Tj0Z9LyyXvI/AAAAAAAAAnE/cvDEPyYM4fw/s220/screenshot_01.jpg'/></author><thr:total>11</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7784275687535954642.post-4692806353342849241</id><published>2007-08-23T05:09:00.000-07:00</published><updated>2007-08-26T02:32:14.487-07:00</updated><title type='text'>Key benefits of CCWAPSS scoring</title><content type='html'>• Fighting against the « gaussienne » inclination using a restricted granularity that forces the auditor to &lt;span style="font-weight:bold;"&gt;clear-cut&lt;/span&gt; score (there is no medium choice).&lt;br /&gt;&lt;br /&gt;• Offering a solution to interpretation problems between different auditors by providing clear and well &lt;span style="font-weight:bold;"&gt;documented criteria&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;• The maximum score (10/10) means “compliant with &lt;span style="font-weight:bold;"&gt;Best Practices&lt;/span&gt;”. This score could be exceeded in case of excellence (like a medical vision evaluation such as 12/10).&lt;br /&gt;&lt;br /&gt;• Each criteria is relative to section of the &lt;span style="font-weight:bold;"&gt;&lt;a href="http://www.owasp.org/index.php/OWASP_Guide_Project"&gt;OWASP Guide 3.0&lt;/a&gt;&lt;/span&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7784275687535954642-4692806353342849241?l=ccwapss.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ccwapss.blogspot.com/feeds/4692806353342849241/comments/default' title='Publier les commentaires'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7784275687535954642&amp;postID=4692806353342849241' title='1 commentaires'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7784275687535954642/posts/default/4692806353342849241'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7784275687535954642/posts/default/4692806353342849241'/><link rel='alternate' type='text/html' href='http://ccwapss.blogspot.com/2007/08/test.html' title='Key benefits of CCWAPSS scoring'/><author><name>Fred</name><uri>http://www.blogger.com/profile/09157392358166457109</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-rMt5x-wPzWo/Tj0Z9LyyXvI/AAAAAAAAAnE/cvDEPyYM4fw/s220/screenshot_01.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7784275687535954642.post-8007635944140197572</id><published>2007-08-22T05:13:00.000-07:00</published><updated>2007-08-24T05:17:35.693-07:00</updated><title type='text'>The 11 scoring criteria</title><content type='html'>1 - Authentication&lt;br /&gt;2 - Authorization&lt;br /&gt;3 - User’s Input Sanitization&lt;br /&gt;4 - Error Handling and Information leakage&lt;br /&gt;5 - Passwords/PIN Complexity&lt;br /&gt;6 - User’s data confidentiality&lt;br /&gt;7 - Session mechanism&lt;br /&gt;8 - Patch management&lt;br /&gt;9 - Administration interfaces&lt;br /&gt;10 - Communication security&lt;br /&gt;11 - Third-Party services exposure&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7784275687535954642-8007635944140197572?l=ccwapss.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ccwapss.blogspot.com/feeds/8007635944140197572/comments/default' title='Publier les commentaires'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7784275687535954642&amp;postID=8007635944140197572' title='3 commentaires'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7784275687535954642/posts/default/8007635944140197572'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7784275687535954642/posts/default/8007635944140197572'/><link rel='alternate' type='text/html' href='http://ccwapss.blogspot.com/2007/08/11-scoring-criteria.html' title='The 11 scoring criteria'/><author><name>Fred</name><uri>http://www.blogger.com/profile/09157392358166457109</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-rMt5x-wPzWo/Tj0Z9LyyXvI/AAAAAAAAAnE/cvDEPyYM4fw/s220/screenshot_01.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7784275687535954642.post-8884399209656396496</id><published>2007-01-06T10:55:00.000-08:00</published><updated>2007-11-06T11:40:36.050-08:00</updated><title type='text'>Risk factor : Difficulty of Exploit  vs Business Impact</title><content type='html'>The Risk Factor concept used by the CCWAPPSS is the answer to the question : &lt;i&gt;Could this vulnerability lead to major issues&lt;/i&gt; ?&lt;br /&gt;&lt;br /&gt;To figure out the Risk Factor of a vulnerability, the auditor has to answer the following questions :&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Is the exploitation of this vulnerability trivial or sophiticated ?&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Could the exploitation of this vulnerability have an impact on the business activity ?&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7784275687535954642-8884399209656396496?l=ccwapss.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ccwapss.blogspot.com/feeds/8884399209656396496/comments/default' title='Publier les commentaires'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7784275687535954642&amp;postID=8884399209656396496' title='2 commentaires'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7784275687535954642/posts/default/8884399209656396496'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7784275687535954642/posts/default/8884399209656396496'/><link rel='alternate' type='text/html' href='http://ccwapss.blogspot.com/2007/11/risk-factor-difficulty-of-exploit-vs.html' title='Risk factor : Difficulty of Exploit  vs Business Impact'/><author><name>Fred</name><uri>http://www.blogger.com/profile/09157392358166457109</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-rMt5x-wPzWo/Tj0Z9LyyXvI/AAAAAAAAAnE/cvDEPyYM4fw/s220/screenshot_01.jpg'/></author><thr:total>2</thr:total></entry></feed>
