SlideLegend

Tray · Technology

Technology Briefings: Security Guides, White Papers and Standards

Security testing guides, industry white papers and technical standards, with notes on what has changed since publication.

3 briefings · 7 records

Card index

Records

Short entries on further documents in this tray: what each one is, who published it and where the original lives today.

  1. 001Konza TechnopolisKonza Technopolis Development AuthorityReport
  2. 002Multiagent Cooperation and Competition with Deep Reinforcement LearningPLOS ONE · 2017Study
  3. 003Oracle Exadata Database Machine X6-2 Data SheetOracle Corporation · 2016White paper
  4. 004Quantum Optimization Using Variational Algorithms on Near-Term Quantum DevicesarXiv (Cornell University) · 2017Study
  5. 005Smallsats by the Numbers 2018Bryce Space and Technology (now BryceTech) · 2018Report
  6. 006Technical Guideline: Generating Plants Connected to the Medium-Voltage NetworkBDEW (German Association of Energy and Water Industries) · 2008Standard
  7. 007What is Matrix Display?MSI (Micro-Star International)Guidance
Other trays

Law & JusticeHealth & MedicineEducationGovernment & PolicyScience & EnvironmentBusiness & MarketingSports DataCulture & Society

Fourteen trillion dollars. That was Accenture’s 2015 projection for the value the Industrial Internet of Things would add globally by 2030, built from a whitepaper’s case for connected shelves, beacons and sensors reshaping retail stores well before most of that infrastructure existed.

A white paper argues; a standard specifies

A vendor whitepaper makes a case, usually for a trend or a product category the publisher has a stake in, and its numbers are projections rather than measurements. A technical standard does the opposite: it specifies exactly how something must be built, tested or labeled, produced by a working group through a consensus process rather than a single author’s argument, and meant to be followed rather than weighed for persuasiveness. The two genres are easy to confuse when both arrive as a branded PDF, but the test is simple: does the document argue for a future, or specify a present requirement?

OWASP’s Testing Guide and the version problem

The OWASP Testing Guide, first published under that name, was later renamed the Web Security Testing Guide as OWASP continued developing past version 4, folding in new categories as attack surfaces changed, WebAssembly among the more recent additions. A security testing procedure cited from an old copy of “version 4” may not match the current guide’s category numbering or scope, which is why checking a cited test case against the guide’s current version, not just its title, matters before relying on it.

Where internet and web standards actually come from: IETF, W3C, ISO

Three bodies cover most of the standards a technology document might cite. The IETF publishes RFCs, the documents defining core internet protocols, developed through open working groups and public review, with a formal ladder from Proposed Standard up to full Internet Standard status. W3C publishes web standards as formal recommendations, HTML, CSS and related technologies, through a comparable consensus process. ISO sits apart from both: a broad international standards body spanning everything from quality management to physical units, whose standards are typically sold as paid documents rather than published freely online, unlike most IETF and W3C output.

Product documentation ages fast; check the generation, not just the date

A data sheet or buyer’s guide, like a 2016-era guide to mobile mapping systems from a UK LiDAR manufacturer, names a specific product generation, and that generation is the detail worth checking against a manufacturer’s current lineup before treating the document as current. Products get acquired, renamed and folded into larger companies’ catalogues; a standalone spec sheet with no stated revision date is the hardest kind to place in time, and worth reading as a record of one generation of a product, not a guarantee of what is sold today.

Questions

What's the difference between a white paper and a technical standard?

A white paper, like a consultancy's forecast on the Internet of Things in retail, argues a position or forecasts a trend, usually written by a vendor with a stake in the argument landing a certain way. A standard, like an OWASP or ISO document, instead specifies exactly how something should be built or tested, meant to be followed rather than debated, and produced through a working group rather than a single author.

How does OWASP's Testing Guide relate to the current Web Security Testing Guide?

OWASP renamed its Testing Guide the Web Security Testing Guide (WSTG) once it moved past version 4; the 2014-era version 4 content carries into the current guide, which has continued adding categories, including ones covering WebAssembly, as new attack surfaces emerged. Checking which version a cited testing procedure comes from matters, since categories and specific test cases get added, renamed or retired between major versions.

What do IETF and W3C actually publish, and how is that different from ISO?

IETF publishes RFCs, the documents that define how the internet's core protocols work, developed through open working groups and public comment. W3C publishes web standards as formal recommendations, covering HTML, CSS and related web technologies, through a similar consensus process. ISO, by contrast, is a broader international standards body covering everything from quality management to physical measurements, and its standards are typically paid documents rather than freely published online.

How can you tell whether a piece of hardware or software documentation is out of date?

A data sheet or buyer's guide names the specific product generation it covers, and checking whether that generation is still the manufacturer's current model, or has since been superseded, is the fastest check. A company's own product page or current-generation spec sheet is the most reliable comparison; a standalone PDF with no stated revision date is the hardest to place in time and worth treating cautiously.

What does a preprint on arXiv represent, compared to a published journal article?

A preprint is a paper posted before, or without, formal peer review, letting researchers share results quickly; some are later published in a peer-reviewed journal in a revised form, and some never are. Treating a preprint's findings with the same confidence as a peer-reviewed publication skips a real step: checking whether a peer-reviewed version exists and what, if anything, changed between the two.