Thanks again to all those who took the time to fill out the survey. I got a lot of informative comments in addition to the answers. It would be insightful for readers to know the names/organizations of those polled, including what their comments were. But I promised not to release their personal information. However, they themselves are more than welcome to re-post their thoughts and comments.
1) How many web application security assessment
![](http://photos1.blogger.com/blogger/4263/1222/200/webappsec_professionals_survey_1.png)
a) None (0%)
b) 1 - 10 (0%)
c) 10 - 25 (57%)
d) 25 - 50 (29%)
e) 50+ (14%)
2) What vulnerability reporting standard do you utilize most
![](http://photos1.blogger.com/blogger/4263/1222/200/webappsec_professionals_survey_2.png)
a) Web Security Threat Classification (WASC) (14%)
b) OWASP Top Ten (0%)
c) Common Vulnerabilities and Exposures (CVE) (10%)
d) Proprietary (57%)
e) Other (19%)
3) Do you use commercial web application vulnerability scanners during security assessments?
![](http://photos1.blogger.com/blogger/4263/1222/200/webappsec_professionals_survey_3.0.png)
(SPI Dynamic's WebInspect, Cenzic's Hailstorm, Watchfire's AppScan, Acunetix Web Vulnerability Scanner)
a) Never (71%)
b) Sometimes (24%)
c) 50/50 (0%)
d) Most of the time (0%)
e) Religiously (5%)
4) Average number of man-hours required to perform a thorough web application vulnerability assessment on the average commerce website?
![](http://photos1.blogger.com/blogger/4263/1222/200/webappsec_professionals_survey_4.png)
a) None (0%)
b) 0 - 10 (5%)
c) 10 - 25 (10%)
d) 25 - 40 (0%)
e) 40+ (86%)
5) Do you recommend Web Application Firewalls?
![](http://photos1.blogger.com/blogger/4263/1222/200/webappsec_professionals_survey_5.6.png)
(ModSecurity, Imperva's SecureSphere, NetContinuum's NC-1100, Citrix Application Firewall, etc.)
a) Yes (14%)
b) No (10%)
c) Sometimes (76%)
6) What do you think about the updated PCI Data Security Standard v1.1?
![](http://photos1.blogger.com/blogger/4263/1222/200/webappsec_professionals_survey_6.3.png)
a) Huh? (0%)
b) It's stupid and means nothing to me (0%)
c) Step in the right direction (57%)
d) Great for the web application security industry! (0%)
e) Other (43%)
7) Checking for XSS on public websites without permission?
![](http://photos1.blogger.com/blogger/4263/1222/200/webappsec_professionals_survey_7.1.png)
a) Legal (24%)
b) Legal, but unethical (19%)
c) Illegal (10%)
d) Don't know (Grey area) (48%)
4 comments:
Jeremiah,
I've posted up my response to your survey:
http://www.greebo.net/?p=374
thanks,
Andrew
My survey results are available on my blog.
Thanks for the Poll,
sv
Thanks Sylvan! The more data the better. And there is more than 1 person now following your blog. :)
hi there!
Very nice survey and interesting results, specially when it comes to "do you use commercial web application testing software" and "what vulnerability reporting standard do you utilize"!
thanks for publishing this!
Post a Comment