In the race to establish leadership in the fields of penetration testing and web app pen testing in particular, several organizations, companies, and councils have sprung up. Some of these organizations offer a product-neutral methodology, while others have perspectives that unabashedly drive their recommended pen testing approach or framework. This testing framework's contents and format will vary greatly, so we'll need to sort through the options and see which one makes sense.
Government supported centers and institutes such as the United States Computer Emergency Readiness Teams (US CERT), Computer Security Resource Center (CSRC) at the National Institute of Standards and Technology (NIST), and the newly established European Union Agency for Network and Information Security (https://www.enisa.europa.eu ) tend to be focused on...