Re: [SC-L] SANS/CWE Top 25: "The New Standard" for Webappsec

2009-01-19 Thread Stephen Craig Evans
Hi Arian, " SANS has spoken and I think that is a pretty clear indication what is going on)" Have you been watching Wizard of Oz re-reruns again? This sentence sounds too much like "The Mighty Oz has spoken" :-) Cheers, Stephen On Sat, Jan 17, 2009 at 11:39 AM, Arian J. Evans wrote: > Hel

Re: [SC-L] SANS/CWE Top 25: "The New Standard" for Webappsec

2009-01-19 Thread Arian J. Evans
On Mon, Jan 19, 2009 at 9:45 AM, Stephen Craig Evans wrote: > > Hi Arian, > > " SANS has spoken and I think that is a pretty clear indication what is > going on)" > > Have you been watching Wizard of Oz re-reruns again? This sentence sounds > too much like "The Mighty Oz has spoken" :-) I am

[SC-L] SANS/CWE Top 25: "The New Standard" for Webappsec

2009-01-17 Thread Arian J. Evans
Hello all. Xposting to SCL and WASC: Following-up to my commentary on the WASC list about the SANS/CWE "Top 25" I have repeatedly confirmed that the SANS/CWE Top 25 is being actively used, and growing in use, as a "Standard". I understand the spirit of intent and that the makers are not acco