OWASP Flashcards

1
Q

OWASP stands for

A

Open Web Application Security Project

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

OWASP is what type of bussiness

A

Non-profit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

OWASP supports

A

o Secure software development
o Risk Decision Making
o Free resources to developer teams – publications, articles, standards

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Examples of OWASP publicationa

A

*Top 10 …
*“Guide to building secure web applications”
*Legal Project

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

OWASPP is used in our unit, what list is used

A

“Top 10 Cloud Security Risks”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Top 10 Cloud Security Risks according to OWASP

A
  • Accountability & Data Ownership
  • User Identity Federation
  • Regulatory Compliance
  • Bussiness Continuity & Resiliency
  • User Privacy & Secondary Usage of Data
  • Service & Data Integration
  • Multi-Tennacy & Physical Security
  • Incidence Analysis & FOrensics
  • Infrastructure Security
  • Non Production Enviroment Exposure
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Handy Mnemonic to remember Top 10 CLoud Security Risks

A

A Dynamic
Fireman
Creatively
Calms
People
In
Intimidating
Incidents
Near
Manchester

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

OWASP: Accountability & Data Ownership

A

 GDPR
 Policies
 RACI model
 Mitigation – Delete data, keys

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

OWASP: User Identity FEderation

A

 OWASP supports using SAML (Security Assertion Market Lanaguage)
 Google eco system, other options (WSO2, 0Auth)
 Takes control of user lifecycle out of administrators hand
 “one right to rule them all”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

OWASP: Regulatory Compliance

A
  • Geographic
  • Use understanding cloud vendor / parnters
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

OWASP: Business Continuity & Resiliency

A
  • AWS went down – 2.6 million @ 13 mins
  • Pre-contracts: SLA’s, MTTR, Objectives etc
  • ISO22301
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

OWASP: User Privacy & Secondary Usage of Data

A
  • GDPR
  • Policies – Terms of Use
  • User v Provider
  • Encrypted storage
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

OWASP: Service & Data Integration

A
  • Use secure protocols – TLS
  • Data at use / data at rest
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

OWASP: Multi-tenancy & Physical Security

A

Multi tennancy shiz

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

OWASP: Infrastrucutre Security

A
  • Network Security
  • Previously this was where the battles were faught
  • Progressive - Zero-Trust
How well did you know this?
1
Not at all
2
3
4
5
Perfectly