This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Category:OWASP Top Ten Project

From OWASP
Revision as of 02:57, 13 April 2017 by Wichers (talk | contribs)

Jump to: navigation, search
Flagship big.jpg

OWASP Top 10 - 2017 Release Candidate

The release candidate for public comment was published 10 April 2017 and can be downloaded here. OWASP plans to release the final OWASP Top 10 - 2017 in July or August 2017 after a public comment period ending June 30, 2017.

Constructive comments on this OWASP Top 10 - 2017 Release Candidate should be forwarded via email to the OWASP Top 10 Project Email List. Private comments may be sent to Dave Wichers. Anonymous comments are welcome. All non-private comments will be catalogued and published at the same time as the final public release. Comments recommending changes to the Top 10 should include a complete suggested list of changes, along with a rationale for each change. All comments should indicate the specific relevant page and section.

OWASP Top 10 Most Critical Web Application Security Risks

The OWASP Top 10 is a powerful awareness document for web application security. It represents a broad consensus about the most critical security risks to web applications. Project members include a variety of security experts from around the world who have shared their expertise to produce this list.

We urge all companies to adopt this awareness document within their organization and start the process of ensuring that their web applications do not contain these flaws. Adopting the OWASP Top 10 is perhaps the most effective first step towards changing the software development culture within your organization into one that produces secure code.

Translation Efforts

The OWASP Top 10 has been translated to many different languages by numerous volunteers. These translations are available as follows:

Licensing

The OWASP Top 10 is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.


What is the OWASP Top 10?

The OWASP Top 10 provides:

  • A list of the 10 Most Critical Web Application Security Risks

For each Risk it provides:

  • A description
  • Example vulnerabilities
  • Example attacks
  • Guidance on how to avoid
  • References to OWASP and other related resources

Project Leader

Related Projects

Ohloh

Quick Download

Email List

Project Email List

News and Events

  • [10 Apr 2017] OWAP Top 20 - 2017 Release Candidate Published
  • [17 Dec 2016] OWASP Top 10 - 2017 Data Call Data Published
  • [20 May 2016] OWASP Top 10 - 2017 Data Call Announced
  • [12 Jun 2013] OWASP Top 10 - 2013 Final Released
  • [Feb 2013] OWASP Top 10 - 2013 - Release Candidate Published

Classifications

Owasp-flagship-trans-85.png Owasp-builders-small.png
Owasp-defenders-small.png
Cc-button-y-sa-small.png
Project Type Files DOC.jpg

Subcategories

This category has the following 2 subcategories, out of 2 total.

O

Pages in category "OWASP Top Ten Project"

The following 107 pages are in this category, out of 107 total.

T

Media in category "OWASP Top Ten Project"

The following 2 files are in this category, out of 2 total.