WebApp Sec mailing list archives

RE: Glossary of Terms


From: "Mark Curphey" <mark () curphey com>
Date: Fri, 15 Jul 2005 20:32:26 -0700

I like the second idea a lot. Thanks. I actually don't want to be web
appliction specific. I think what I will do is create a matrix, map the
current terms in existing standards (RFC 2828, NIST etc) and then I can
reference the term back to the official document in a central place. Argh,
blue skies......

-----Original Message-----
From: websec_lists () hushmail com [mailto:websec_lists () hushmail com] 
Sent: Friday, July 15, 2005 8:22 PM
To: webappsec () securityfocus com; sc-l () securecoding org
Subject: Re:Glossary of Terms

With repsect I think there are way too many slang terms for that to useful
outside of the hacker community. They are also mixed verbs and nouns and
other fundamental information modeling "feau pas's". 
I think for a glossary to be useful it has to be written to a development
community and that would be taken seriously by a CIO; not a hacker
community.

I like the idea of the NIST, RFC and other suggestions. There is no point in
re-inventing the wheel! Maybe mapping the terms from the main standards
already makes more sense?

____________________________________________________


An existing glossary containing common web application security terminology
can be found at http://www.webappsec.org/projects/glossary/. Also available
is the Threat Classifications document located at
http://www.webappsec.org/projects/threat/ which serves 
well as a taxonomy of attacks .   


Regards, 

- Robert Auger
robert () webappsec org

--------------------------------------------------------------------
-
The Web Security Mailing List
http://www.webappsec.org/lists/websecurity/
 
The Web Security Mailing List Archives
http://www.webappsec.org/lists/websecurity/archive/




Concerned about your privacy? Follow this link to get secure FREE email:
http://www.hushmail.com/?l=2

Free, ultra-private instant messaging with Hush Messenger
http://www.hushmail.com/services-messenger?l=434

Promote security and make money with the Hushmail Affiliate Program: 
http://www.hushmail.com/about-affiliate?l=427



Current thread: