Abstracta – 7 Security Testing Tools to Try Now
csc18
https://abstracta.us/blog/security-testing/7-security-testing-tools-to-try-now/
This is a blog by abstracta that covers the pricing and features of seven penetration testing tools.
Breach Lock – Web Application Penetration Testing Checklist
csc18
https://www.breachlock.com/resources/blog/web-application-penetration-testing-checklist/
This is a checklist compiled by “testing experts” at BreachLock that can be utilized to perform a penetration test of web applications.
Forcepoint – What is DevSecOps?
csc18
https://www.forcepoint.com/cyber-edu/devsecops
This article provides a brief overview of how security is an integral part of application development operations (aka DevSecOps).
hackr.io – Top 10 Open Source Security Testing Tools for Web Applications
csc18
https://hackr.io/blog/top-10-open-source-security-testing-tools-for-web-applications
This is a blog that provides the key highlights of each of the top ten open source security testing tools for web applications.
keycdn – 11 Web Application Security Best Practices
csc18
https://www.keycdn.com/blog/web-application-security-best-practices
This is a blog by keycdn that identifies best practices to be levered with respect to web applications.
MITRE – CWE-Compatible Products and Services
csc18
https://cwe.mitre.org/compatible/compatible.html
The products and services listed here have achieved the final stage of MITRE's formal CWE Compatibility Program and are now "Officially CWE-Compatible."
Open Web Application Security Project (OWASP) – Application Security Verification Standard 4.0.2
csc18
https://raw.githubusercontent.com/OWASP/ASVS/v4.0.2/4.0/OWASP%20Application%20Security%20Verification%20Standard%204.0.2-en.pdf
This is an application security verification standard developed by OWASP that can be leveraged to test the security of web applications.
Open Web Application Security Project (OWASP) – Free for Open Source Application Security Tools
3.12 3.12.1 3.12.3 csc18 Security Assessment
https://owasp.org/www-community/Free_for_Open_Source_Application_Security_Tools
OWASP's mission is to help the world improve the security of its software.
Open Web Application Security Project (OWASP) – Secure Coding Practices: Quick Reference Guide
csc18
https://raw.githubusercontent.com/OWASP-Archives/Social-Data/master/O2_Collected_Data/owasp_org_wiki/Files/.doc/OWASP_SCP_Quick_Reference_Guide_v2.doc
This is secure coding best practices checklist put together by OWASP to ensure that web applications are developed to be secure to protect against vulnerabilities.
https://owasp.org/www-project-web-security-testing-guide/v41/6-Appendix/A-Testing_Tools_Resource
This link from OWASP provides a list of web security testing tools.