This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Category:WASS Security Frame
From OWASP
[hide]
Introduction Text
Add suggested approach of how to audit against/use the requirements
Requirements
Architecture
Deployment and Configuration
Authentication
- Deploy mechanisms to enhance the security of authentication credentials used.
- Establish a new session identifier upon user authentication.
Authorization
Session and User Management
- Deploy mechanisms to securely perform tasks related to user management.
- Take measures to securely manage user identification.
- Take measures to securely manage cookies.
Auditing and Logging
Data Validation
Injections
Privacy
- Do not transmit sensitive information in GET requests.
- Disable caching of sensitive pages.
- Do not store sensitive information in Hidden fields.
Cryptography
File system
Canonicalization and Unicode
This category currently contains no pages or media.