Support OWASP's mission to provide support for education activities to foster collaborations and support relationships with the Application Security, Developer, and Training communities, both academic and industry-based, and to advise the Foundation & Board of an educational strategy for OWASP.
Part of OWASP’s main purpose is to “Be the thriving global community that drives visibility and evolution in the safety and security of the world’s software”. A key part of that mission is to educate not just the current generation of developers and information security professionals, but also the next generation, particularly given the acknowledged skills shortage in the security sector. A common problem with many security education programs (whether cyber or InfoSec) and even traditional computer science programs is that they do not adequately address application security, if at all.
To provide a support mechanism for OWASP education activities to foster collaborations and support relationships with the Application Security, Developer, and Training communities, both academic and industry-based.
To advise the Foundation & Board on an educational strategy for OWASP.
Encourage chapters to foster and document relationships with training providers and educational institutions (at all levels) to broaden application security education across all communities.
Encourage projects that foster and document relationships with training providers and educational establishments (at all levels) to broaden application security education across all communities.
The committee will establish and strengthen relationships with professional bodies, standards organizations, and academic organizations to advance application security education within the broader security and developer community.
The OWASP Education and Training Committee will respond to training requests received from the public at large. The mechanisms to respond to these requests is to collaborate with the Events Committee to conduct the training.
Design and develop a certification program with multiple levels (Foundational and Advanced) for developers. The certificate would validate developers' knowledge and also provide an avenue to meet the requirements of standards like PCI-DSS, where training developers in secure coding is required.
Establish a core set of Learning Objectives for an application security curriculum that defines the educational requirements necessitated by industry (from an established Application Security Body of Knowledge)
Undertake a gap analysis of existing and missing curricula to meet the requirements outlined by industry;
This will be achieved through liaison with industry, professional bodies, and existing state-of-the-art literature.
Design, develop, and implement a certificate for developers - OWASP Certified Secure Developer. The initial set of aims/goals for achieving this project is:
To design a body of knowledge
Design a process for creating an exam question bank
Foundational certification levels shall be programming language neutral