Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Review to ensure coverage to Secure Code Warrior survey knowledge #70

Open
david-a-wheeler opened this issue Jun 24, 2022 · 0 comments
Open

Comments

@david-a-wheeler
Copy link
Contributor

The "The State of Developer-Driven Security Survey REPORT 2022" survey by Secure Code Warrior asked about various knowledge topics, make sure we cover them.

Software vulnerabilities (page 19)

  • Unencrypted data (yes)
  • Privilege escalation vulnerabilities (I think so, double-check)
  • Backdoor credentials
  • Vulnerability to injection (yes)
  • Buffer overflows (yes)
  • Inherent security flaws in libraries or frameworks I use (yes)

And maybe these compliance frameworks / best practices:

  • CIS Security Framework
  • ISO/IEC 27034:2011
  • NIST Security Framework
  • OWASP Top 10 (iknown yes)
  • PCI DSS
  • HIPAA Security and Privacy Rules
  • MISRA C
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant