WSTG - Latest
Suggested Reading
Whitepapers
- The Economic Impacts of Inadequate Infrastructure for Software Testing
- NIST Publications
- Fundamental Practices for Secure Software Development
- OWASP Developer Guide
Books
- The Web Application Hacker’s Handbook: Finding and Exploiting Security Flaws, 2nd Edition, by Dafydd Stuttard and Marcus Pinto, ISBN 9781118026472 (2011)
- The Tangled Web: A Guide to Securing Modern Web Applications, by Michal Zalewski, published by No Starch Press, ISBN 1593273886 (2011)
- Hacking Exposed: Web Applications 3, by Joel Scambray, Vincent Liu, and Caleb Sima, published by McGraw-Hill Osborne Media, ISBN 007222438X (2010)
- Secure Programming HOWTO, by David Wheeler (2015)
- The Art of Software Security Testing: Identifying Software Security Flaws, by Chris Wysopal, Lucas Nelson, Dino Dai Zovi, and Elfriede Dustin, published by Addison-Wesley, ISBN 0321304861 (2006)
- Software Security: Building Security In, by Gary McGraw, published by Addison-Wesley Professional, ISBN 0321356705 (2006)
- Building Secure Software: How to Avoid Security Problems the Right Way, by Gary McGraw and John Viega, published by Addison-Wesley, ISBN 020172152X (2002)
- Web Security Testing Cookbook: Systematic Techniques to Find Problems Fast, by Paco Hope and Ben Walther, published by O’Reilly, ISBN 0596514832 (2008)
- Writing Secure Code, by Mike Howard and David LeBlanc, published by Microsoft Press, ISBN 0735617228 (2004)
- Secure Coding: Principles and Practices, by Mark Graff and Kenneth R. Van Wyk, published by O’Reilly, ISBN 0596002424 (2003)
Useful Sites
- CERT Secure Coding Standards
- SANS Internet Storm Center (ISC)
- The Open Worldwide Application Security Project (OWASP)
- OWASP Cheat Sheet Series
- Pentestmonkey - Pen Testing Cheat Sheets
- Secure Coding Guidelines for .NET
- Secure Coding Guidelines for Java SE
- System Administration, Networking, and Security Institute (SANS)