Web Security and the OWASP Top Ten
Security in the Software Development Life Cycle (SDLC)
Security Integration: Security must be integrated across building, verifying, and hosting phases.
Key Activities: Includes threat modeling, security training, SAST, DAST, IAST, vulnerability scanning, and manual penetration testing.
Operational Security: Infrastructure involves Patch Management, OS Hardening, File integrity monitoring, and the use of Web Application Firewalls (WAF).
Economic Impact: Approximate estimated cost for building and securing applications can reach .
OWASP Frameworks and Standards
Application Security Verification Standard (ASVS): A basis for testing technical security controls and providing developers with list of requirements for secure development.
Software Assurance Maturity Model (SAMM): Provides a measurable way for organizations to analyze and improve their software security posture.
OWASP WAF Projects: Includes ModSecurity, Coraza, and the OWASP Core Rule Set (CRS).
Specialized Guidance: Includes the OWASP AI Exchange and GenAI Security resources for securing AI and Generative AI systems.
The OWASP Top 10 (2025)
Broken Access Control: Unauthorized access to data or functions.
Security Misconfiguration: Incorrectly configured systems, applications, or cloud services.
Software Supply Chain Failures: Use of insecure libraries or components.
Cryptographic Failures: Inadequate encryption of sensitive data.
Injection: Failure to prevent users from executing malicious code (e.g., SQL injection).
Insecure Design: Fundamental security flaws in architectural design.
Authentication Failures: Weaknesses in user login and identity management.
Software or Data Integrity Failures: Lack of validation for code and data validity.
Security Logging & Alerting Failures: Inability to identify or respond to active threats.
Mishandling of Exceptional Conditions: Insecure handling of errors and exceptions.
Security Professional Skills and Community
Foundational Disciplines: Requires knowledge in Web Dev (HTTP, Javascript, CSS, Same Origin Policy), Database/NoSQL, and Networking (Protocols, Zero Trust).
Cloud Security: Understanding core concepts in AWS, Azure, and Google Cloud.
NZ Ecosystem: Key local resources include OWASP Wellington, OWASP NZ Conference (Auckland), and the CyberTech NZ ecosystem map.
Career Resources: "Getting Started as a Penetration Tester in NZ" by Simon Howard from Bastion Security Group.