However, the group is very satisfied with the results of the project.

Many industry experts and security professionals, some of whom are responsible for software security at some of the largest companies in the world, are validating the testing framework.

Until this happens, CIOs will not be able to develop an accurate return on security investment and, subsequently, assign appropriate budgets for software security.

While estimating the cost of insecure software may appear a daunting task, there has been a significant amount of work in this direction.

Most technical people will at least understand the basic issues, or they may have a deeper understanding of the vulnerabilities.

Sadly, few are able to translate that technical knowledge into monetary terms and quantify the potential cost of vulnerabilities to the application owner's business.

It was also a challenge to change the focus of web application testing from penetration testing to testing integrated in the software development life cycle.As such, hard decisions had to be made about the appropriateness of certain testing techniques and technologies.The group fully understands that not everyone will agree upon all of these decisions.Back to the OWASP Testing Guide v4 To C: https:// Back to the OWASP Testing Guide Project: https:// The OWASP Testing Project has been in development for many years.The aim of the project is to help people understand the what, why, when, where, and how of testing web applications.

