Category:OWASP Application Security Verification Standard Project

From OWASP
Revision as of 17:49, 2 June 2009 by Deleted user (talk | contribs)

Jump to: navigation, search

About

OWASP Documentation Project

Application Security Verification Standards (ASVS)

Application Security Verification Standards are specifications produced by OWASP in cooperation with secure applications developers and verifiers worldwide for the purpose of accelerating the deployment of secure Web applications. First published in 2008 as a result of an OWASP Summer of Code grant and meetings with a small group of early adopters, the ASVS documents have become widely referenced and implemented.

Further development of ASVS occurs through mailing list discussions and occasional workshops, and suggestions for improvement are welcome. For more information, please contact us.

Application Security Verification Standards

How ASVS Works

ASVS defines four levels of Web application security verification. Each level includes a set of requirements for verifying the effectiveness of security controls that are being used.

Asvs-levels.jpg


Latest News


FAQ

More About OWASP ASVS

Related projects

FAQs

Did You Know...

  • Businesses are under no obligation to seek inclusion in any sort of a registry or a program in order to perform application security verifications according to OWASP ASVS. Download the latest version and start using ASVS today!
  • More complex applications typically take more time to analyze resulting in longer and more costly verifications. Lines of code are not the only factors that determine the complexity of an application – different technologies will typically require different amounts of analysis.
  • Simple applications may include for example libraries and frameworks. Applications of moderate complexity may include simple Web 1.0 applications. Complex applications may include Web 2.0 applications and new/unique Web technologies.

Web Application Standard

Web Application Standard

This document defines four levels of application security verification for web applications. Each level includes a set of requirements for verifying the effectiveness of security controls that protect applications.

Release Version

Beta Version

  • Web Application Verification Standard 2008 (PDF, Word)

Alpha Version

  • Web Application Verification Standard 2008 (PDF, Word)


OWASP Books logo.png This project has produced a book that can be downloaded or purchased.
Feel free to browse the full catalog of available OWASP books.


Web Service, Other Standards

Web Service Standard - First release is under development

  • Details will be filled in as work progresses. Volunteers wanted!
  • Contact Mike Boberski for further details.

Cloud Computing Standard - Under consideration

Client Server Standard - Under consideration

News

Project News

  • 05/15/2009 - OWASP ASVS users and adopters list updated to include Denim Group
  • 05/04/2009 - OWASP ASVS users and adopters list updated to include Casaba Security
  • 04/08/2009 - OWASP ASVS users and adopters list updated to include ps_testware.
  • 03/13/2009 - OWASP ASVS is presented by Dave Wichers at OWASP Software Assurance Day DC 2009 in conjunction with the Software Assurance Forum sponsored by the US Department of Homeland Security, Department of Defense and National Institute of Standards and Technology.
  • 02/25/2009 – OWASP ASVS proposed updates based on pilots being considered.
  • 12/08/2008 - OWASP ASVS Final assistance required! Please join the mailing list for more information and assignments.
  • 10/03/2008 - OWASP ASVS Alpha draft is released! Mike Boberski is the primary author.

Contributors/Users

Project Leader

Project Contributors

Project Sponsorship

Aspect logo.jpg Bah-bw.JPG SoC 08 Logo Mike Project.jpg

Users and Adopters

A broad range of companies and agencies around the globe are using OWASP ASVS, including:

Please let us know how your organization is using OWASP ASVS. Include your name, organization's name, and brief description of how you use the standard. The project lead can be reached here.

Businesses are under no obligation to seek inclusion in the list above in order to perform application security verifications according to OWASP ASVS. Download the latest version and start using ASVS today!


This project licensed under the Creative Commons Attribution ShareAlike 3.0.

Articles Below - More About ASVS and Using It