[Owasp-testing] OWASP Testing Guide v4 Status?
matteo.meucci at owasp.org
Tue Jul 3 15:39:30 UTC 2012
yes I think you are right. We can not wait for Common Numbering initiative.
Yes, my fault I've to anser to Eoin for the reboot, the project was in
the list. Now I send an email to Eoin and give a feedback soon.
On 07/03/2012 05:34 PM, rick.mitchell at bell.ca wrote:
> Has anyone heard anything about this?
> I was just poking around the OWASP site again and still don't see any hint of v4 being started, though one roadmap does list Jan 2011 as the release data for v4 (https://www.owasp.org/index.php/Projects/OWASP_Testing_Project/Releases/Testing_Guide_V_4.0/Roadmap). No mention of it on the reboot project list either :(
> I do recall at one point v4 was dependant upon Common Numbering being hammered out, https://www.owasp.org/index.php/Common_OWASP_Numbering, however the common numbering initiative has also stalled in the light of workloads (mine included) and other feedback. Common numbering or requirements has had a good deal of valid feedback: CW's: https://lists.owasp.org/pipermail/owasp-common-numbering/attachments/20110707/5c2ba213/attachment-0001.pdf and SMC's: http://lists.owasp.org/pipermail/owasp-topten/2010-January/000583.html. Unfortunately it seems that common numbering/requirements will be delayed for months.
> This is just my personal opinion but I don't think drafting TG v4 content be held up waiting for another project. I'm as guilty as anyone else for not being able to deal with common-numbering being moved forward. I think TGv4 could be aligned with common numbering/requirements later (before it goes Gold), or common numbering could be adopted for v5. As things stand v4 is almost 3 years old and lots of items which are currently relevant to developers and security analysts have been identified as missing from v3 (new for v4).
> -----Original Message-----
> From: Mitchell, Rick (6030318)
> Sent: November 15, 2011 9:56 AM
> To: owasp-testing at lists.owasp.org
> Subject: OWASP Testing Guide v4 Status?
> Has there been any movement on this? I still don't see a v4 draft section on owasp.org anywhere.
> ----- Original message(s) -----
> Date: Wed, 13 Apr 2011 13:17:50 +0200
> From: Pavol Luptak <pavol.luptak at nethemba.com>
> Subject: Re: [Owasp-testing] Progress/status of v4?
> To: "owasp-testing at lists.owasp.org" <owasp-testing at lists.owasp.org>
> Message-ID: <20110413111750.GA16494 at core.nethemba.com>
> Content-Type: text/plain; charset="us-ascii"
> On Tue, Apr 12, 2011 at 08:53:06AM -0400, rick.mitchell at bell.ca wrote:
>> Is there an official plan yet for production of v4? Will all the v3 content be copied to a new heading/section of the wiki for editing and addition of new content similar to what we did for v3?
> Matteo, can you open/start the OWASP testing guide v4 wiki draft for a collaborative edit?
> Pavol Luptak, CISSP, CEH
> OWASP Slovakia chapter leader
> Owasp-testing mailing list
> Owasp-testing at lists.owasp.org
More information about the Owasp-testing