110 likes | 121 Views
OWASP RFP Criteria. For Web Application Security Projects. 1. Introduction. Table of Contents. 2. Recommended Information the Client should provide to Service Providers/Vendors. 3. Recommended RFP Questions. 1. Introduction. Introduction:.
E N D
OWASP RFP Criteria. For Web Application Security Projects.
1. Introduction Table of Contents. 2. Recommended Information the Client should provide to Service Providers/Vendors. 3. Recommended RFP Questions
Introduction: A Request For Proposal, (RFP) is a call made by an organization soliciting for bids by service providers or vendors to meet a need and it is often done by documents. The information provided in RFPs are important and when you create an RFP for an Application Security Verification project , emphasis should be on providing clear information about the scope of verification activities and evaluation criteria so prospective service providers and vendors can submit proposals that are comparable.
2. Recommended Information the Client should provide to Service Providers/Vendors.
Provide details about: • Lines of Code • Number of Dynamic Pages. • An Inventory of user roles and role descriptions. • Brief Application Summary and Application Architecture. • Degree of Verification Required. • The frequency or duration for performing verification.
Ask Service Providers/Vendors to Provide details on: • Lines of Code • Number of Dynamic Pages. • An Inventory of user roles and role descriptions. • Brief Application Summary and Application Architecture. • Degree of Verification Required. • The frequency or duration for performing verification.
Ask Service Providers/Vendors to Provide details on: • Company Background. • Application Security Verification Methodology. • Security Coverage. • Application Coverage. • Risk Evaluation. • Differentiators. • Scope. • Security.
Ask Service Providers/Vendors to Provide details on: • Burden. • Reporting Interface. • Innovation. • Integration. • Benefits. • Supporting Services. . • Client Support Details. • Pricing/Licensing Information.