This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "Category:OWASP Application Security Verification Standard Project"

From OWASP
Jump to: navigation, search
Line 1: Line 1:
[[Image:Asvs-banner-vendor.jpg|center]]
 
 
<br>
 
 
 
====About====
 
====About====
  
Line 21: Line 17:
 
;  
 
;  
 
<br>'''Latest News'''
 
<br>'''Latest News'''
* OWASP ASVS users list updated to include [http://quince.co.uk Quince Associates Limited (SeeMyData)]
+
* A "Precedents/Interpretations" tab was added to the ASVS project page.
* Updated ASVS Article: [http://www.owasp.org/index.php/Man_vs._Code Man vs. Code]
 
* New ASVS Article: [http://www.owasp.org/images/0/01/Getting_started_designing_for_a_level_of_assurance.pdf Getting started designing for a level of assurance]
 
* Updated ASVS Article: [http://www.owasp.org/index.php/Agile_Software_Development:_Don%27t_Forget_EVIL_User_Stories Agile Software Development: Don't Forget EVIL User Stories]
 
* New ASVS Article: [http://www.owasp.org/index.php/Code_Reviews_and_Other_Verification_Activities:_USELESS_Unless_Acted_Upon_IMMEDIATELY Code Reviews and Other Verification Activities: USELESS Unless Acted Upon IMMEDIATELY]
 
* OWASP ASVS and "Man vs. Code" ASVS article mentioned in [http://www.tssci-security.com/pub/2009_ToorCamp_WA-Gironda-WASTS.ppt Toorcamp 2009 presentation]
 
* New ASVS Article: [http://www.owasp.org/index.php/Agile_Software_Development:_Don%27t_Forget_EVIL_User_Stories Agile Software Development: Don't Forget EVIL User Stories]
 
* OWASP ASVS users list updated to include [http://www.mindedsecurity.com Minded Security]
 
* OWASP ASVS users list updated to include [http://www.serpro.gov.br/ CETEC/CTCSE - Divisão Processos de Segurança no Desenvolvimento SERPRO - Serviço Federal de Processamento de Dados / Sede - Brasília-DF] (CETEC / CTCSE - Division of Security in Development Processes SERPRO - Federal Service of Data Processing / Headquarters - Brasília-DF)
 
**''"Here in Serpro we have more than 2000 software developers as part of more than 10.000 employees. We have a strong need to address the webservices security issues. But as a first approach, we are working on the ASVS for web applications and we are integrating this standard to our development life cycle(including our agile process) and software acquisition process."''
 
* OWASP ASVS is discussed in the [http://iac.dtic.mil/iatac/download/cybersecurity.pdf Department of Defense (DoD) Information Assurance Technology Analysis Center (IATAC) State-of-the-Art-Report (SOAR) on "Measuring Cyber Security and Information Assurance"].
 
* OWASP ASVS rulesets are added to Casaba Security's security testing tool [http://websecuritytool.codeplex.com/ Watcher version 1.2.0]. First tool vendor to do so!
 
* OWASP ASVS users list updated to include [http://www.cgi.com/web/en/industries/governments/us_federal/services_solutions.htm CGI Federal]
 
* OWASP ASVS [[:Image:OWASP_ASVS_2009_Web_App_Std_Release.pdf|Release Version]] published! [[User:Mike.boberski|Mike Boberski]], [[User:Jeff Williams|Jeff Williams]], and [[User:Wichers|Dave Wichers]] are the primary authors.
 
* OWASP ASVS is presented by [[User:Wichers|Dave Wichers]] at [http://www.owasp.org/index.php/OWASP_AppSec_Europe_2009_-_Poland OWASP AppSec Europe 2009 - Poland].
 
* OWASP ASVS users list updated to include [http://www.fdic.gov Federal Deposit Insurance Corporation (FDIC)].
 
 
* Have you added ASVS to your software assurance tool box? [mailto:[email protected] Please let us know your stories!]
 
* Have you added ASVS to your software assurance tool box? [mailto:[email protected] Please let us know your stories!]
 
* [http://www.owasp.org/index.php/ASVS#tab=News ASVS News Archives]
 
* [http://www.owasp.org/index.php/ASVS#tab=News ASVS News Archives]
Line 101: Line 82:
 
====Precedents/Interpretations====
 
====Precedents/Interpretations====
  
* <We'll add and maintain Precedents/Interpretations here>
+
PI-0001: Are there levels between the levels?
 +
* Issue: Are there levels between the levels for the cases where "The specification for an application may require OWASP ASVS Level N, but it could also include other additional detailed requirements such as from a higher ASVS level"?
 +
* Resolution: No. Use of alternate level definitions or notations such as "ASVS Level 1B+" is discouraged.
 +
* References: ASVS section "Application Security Verification Levels"
 +
 
  
 
====News====
 
====News====

Revision as of 12:50, 26 October 2009

About

OWASP Documentation Project

Application Security Verification Standards (ASVS)

Application Security Verification Standards are specifications produced by OWASP in cooperation with secure applications developers and verifiers worldwide for the purpose of accelerating the deployment of secure Web applications. First published in 2008 as a result of an OWASP Summer of Code grant and meetings with a small group of early adopters, the ASVS documents have become widely referenced and implemented. Further development of ASVS occurs through mailing list discussions and occasional workshops, and suggestions for improvement are welcome. For more information, please contact us. You can download it here. Need help getting started? ASVS is brand new after all! Read this. Use this and this! Frequently asked questions can be found here.

How ASVS Works

ASVS defines four levels of Web application security verification. Each level includes a set of requirements for verifying the effectiveness of security controls that are being used.

Asvs-levels.jpg


Latest News


FAQ

More About OWASP ASVS

  • ASVS Datasheet: (PDF, Word)
  • ASVS Article: Getting Started Using ASVS (PDF)
  • ASVS Article: Code Reviews and Other Verification Activities: USELESS Unless Acted Upon IMMEDIATELY (Wiki)
  • ASVS Article: Agile Software Development: Don't Forget EVIL User Stories (Wiki)
  • ASVS Article: Man vs. Code (Wiki)
  • ASVS Article: Getting started designing for a level of assurance (PDF)
  • ASVS Template: Sample verification fee schedule template (Excel)
  • ASVS Template: Sample verification report template (Word)
  • ASVS Presentation: Project Presentation (PowerPoint)
  • ASVS Training: An ASVS training presentation (PowerPoint)
  • ASVS Presentation: Executive-Level Presentation (PowerPoint)
  • ASVS Presentation: Presentation Abstract (Word)
  • Articles (More About ASVS and Using It)


Related projects

Did You Know...

  • Businesses are under no obligation to seek inclusion in any sort of a registry or a program in order to perform application security verifications according to OWASP ASVS. Download the latest version and start using ASVS today!
  • More complex applications typically take more time to analyze resulting in longer and more costly verifications. Lines of code are not the only factors that determine the complexity of an application – different technologies will typically require different amounts of analysis. Simple applications may include for example libraries and frameworks. Applications of moderate complexity may include simple Web 1.0 applications. Complex applications may include Web 2.0 applications and new/unique Web technologies.
  • One way to introduce verification as an activity into your SDLC is depicted in the figure below.
ASVS-SDLC.JPG

Download

Web Application Standard

Download ASVS now, for free, here.

Other Versions

  • Web Application Verification Standard 2008 (Release Version) (Word)

Earlier Versions

  • Web Application Verification Standard 2008 (Beta Version) (PDF, Word)
  • Web Application Verification Standard 2008 (Alpha Version) (PDF, Word)


OWASP Books logo.png This project has produced a book that can be downloaded or purchased.
Feel free to browse the full catalog of available OWASP books.

Precedents/Interpretations

PI-0001: Are there levels between the levels?

  • Issue: Are there levels between the levels for the cases where "The specification for an application may require OWASP ASVS Level N, but it could also include other additional detailed requirements such as from a higher ASVS level"?
  • Resolution: No. Use of alternate level definitions or notations such as "ASVS Level 1B+" is discouraged.
  • References: ASVS section "Application Security Verification Levels"


News

Project News

  • 06/22/2009 - OWASP ASVS rulesets are added to Casaba Security's security testing tool Watcher version 1.2.0. First tool vendor to do so!
  • 06/09/2009 - OWASP ASVS users list updated to include CGI Federal
  • 05/15/2009 - OWASP ASVS users list updated to include Denim Group
  • 04/08/2009 - OWASP ASVS users list updated to include ps_testware.
  • 03/13/2009 - OWASP ASVS is presented by Dave Wichers at OWASP Software Assurance Day DC 2009 in conjunction with the Software Assurance Forum sponsored by the US Department of Homeland Security, Department of Defense and National Institute of Standards and Technology.
  • 02/25/2009 – OWASP ASVS proposed updates based on pilots being considered.
  • 12/08/2008 - OWASP ASVS Final assistance required! Please join the mailing list for more information and assignments.
  • 10/03/2008 - OWASP ASVS Alpha draft is released! Mike Boberski is the primary author.


Users/Contributors

Project Leader

Project Contributors

Project Sponsorship

Aspect logo.jpg

Bah-bw.JPG

SoC 08 Logo Mike Project.jpg

Users

A broad range of companies and agencies around the globe have added ASVS to their software assurance tool boxes, including:

Organizations listed above are not accredited by OWASP. Neither their products or services have been endorsed by OWASP. Use of ASVS may include for example providing verification services using the standard. Use of ASVS may also include for example performing internal evaluation of products with the OWASP ASVS in mind, and NOT making any claims of meeting any given level in the standard.

Please let us know how your organization is using OWASP ASVS. Include your name, organization's name, and brief description of how you use the standard. The project lead can be reached here.


This project licensed under the Creative Commons Attribution ShareAlike 3.0.

Articles Below - More About ASVS and Using It