←back to thread

205 points bsoles | 1 comments | | HN request time: 0.207s | source
Show context
tptacek ◴[] No.41908836[source]
SWEBOK 4 adds a dedicated section for security, but it's painfully 2012 (testing, for instance, centers on the old industry-driven "SAST" vs. "DAST" distinction). It also promotes stuff like Common Criteria and CVSS. The "domain-specific" security section could have been pulled out of the OWASP wiki from 2012 as well: "cloud", "IOT", "machine learning".
replies(3): >>41910272 #>>41911429 #>>41930898 #
1. glwtta ◴[] No.41930898[source]
Apparently I am also stuck in 2012 - are we not doing cloud and machine learning anymore?