wasc-wafec@lists.webappsec.org

WASC Web Application Firewall Evaluation Criteria Project Mailing List

View all threads

WAFEC v2 Step 1

WT
Wujek Thorsten [STEIN-IT GmbH]
Wed, Mar 16, 2011 1:25 PM

Hi guys,

after a while I would like to bring us back to the initial question, which we have to answer to proceed.

    I.            "Should we review WAFEC v1 and how should WAFEC v2 be structured"

  II.            "Sharpen the profile by defining What is a WAF ?"

III.            "What way should use Cases be developed, so that a customer or user can evaluate his environment"

To I.
I would like to say, that I think it is necessary to review it , otherwise we have to redo it, which is also possible. Nobody has said anything "positive" about V1 yet. I have used it several times, and I found it useful but mentioned my critique as well.
Regarding the idea to move away from the spreadsheet form, I find the idea good and it will be more usable and user-friendly for end users, but the question is how much work is it to develop such "kind of software". And should it be in the scope of this project.
We should really come to a point where we decide how V2 should look like and if we want to start from scratch, with V1 in mind, or if we want to extend V1 or build something on top of it.

I am awaiting a lively discussion

Regards.

Thorsten Wujek

Mit freundlichen Grüßen
STEIN-IT GmbH
Thorsten Wujek
technischer Geschäftsführer
technical CEO

MCT,MCA,MASE,CITA-P

Neckarstraße 4. 45768 Marl
Fon +49 23 65 . 92 44 - 31
Fax +49 23 65 . 92 44 - 44

www.stein-edv.dehttp://www.stein-edv.de/
www.sony-repair.dehttp://www.sony-repair.de/
Thorsten.Wujek@stein-edv.demailto:thorsten.wujek@stein-edv.de

Ust.-Idnr.:  DE 814703466
Steuer-Nr.: 359 5786 0059

Amtsgericht Gelsenkirchen, HRB 8639
Sitz und Gerichtsstand Marl

Geschäftsführer:
Joachim Matzek, Thorsten Wujek

Hi guys, after a while I would like to bring us back to the initial question, which we have to answer to proceed. I. "Should we review WAFEC v1 and how should WAFEC v2 be structured" II. "Sharpen the profile by defining What is a WAF ?" III. "What way should use Cases be developed, so that a customer or user can evaluate his environment" To I. I would like to say, that I think it is necessary to review it , otherwise we have to redo it, which is also possible. Nobody has said anything "positive" about V1 yet. I have used it several times, and I found it useful but mentioned my critique as well. Regarding the idea to move away from the spreadsheet form, I find the idea good and it will be more usable and user-friendly for end users, but the question is how much work is it to develop such "kind of software". And should it be in the scope of this project. We should really come to a point where we decide how V2 should look like and if we want to start from scratch, with V1 in mind, or if we want to extend V1 or build something on top of it. I am awaiting a lively discussion Regards. Thorsten Wujek Mit freundlichen Grüßen STEIN-IT GmbH Thorsten Wujek technischer Geschäftsführer technical CEO MCT,MCA,MASE,CITA-P Neckarstraße 4. 45768 Marl Fon +49 23 65 . 92 44 - 31 Fax +49 23 65 . 92 44 - 44 www.stein-edv.de<http://www.stein-edv.de/> www.sony-repair.de<http://www.sony-repair.de/> Thorsten.Wujek@stein-edv.de<mailto:thorsten.wujek@stein-edv.de> Ust.-Idnr.: DE 814703466 Steuer-Nr.: 359 5786 0059 Amtsgericht Gelsenkirchen, HRB 8639 Sitz und Gerichtsstand Marl Geschäftsführer: Joachim Matzek, Thorsten Wujek