Transcription of OWASP Application Security Verification Standard 4.0-en
{{id}} {{{paragraph}}}
Application Security Verification Standard Final March 2019 OWASP Application Security Verification Standard 2 Table of Contents Frontispiece .. 7 About the Standard .. 7 Copyright and License .. 7 Project Leads .. 7 Contributors and Reviewers .. 7 Preface .. 8 What's new in .. 8 Using the ASVS .. 9 Application Security Verification Levels .. 9 How to use this Standard .. 10 Level 1 - First steps, automated, or whole of portfolio view .. 10 Level 2 - Most applications .. 10 Level 3 - High value, high assurance, or high safety .. 11 Applying ASVS in Practice .. 11 Assessment and Certification .. 11 OWASP 's Stance on ASVS Certifications and Trust Marks .. 11 Guidance for Certifying Organizations .. 11 Testing Method .. 12 Other uses for the ASVS.
The most significant change in this version is the adoption of the NIST 800-63-3 Digital Identity Guidelines, introducing modern, evidence based, and advanced authentication controls. Although we expect some pushback on aligning with an advanced authentication standard, we feel that it is essential for standards to be aligned,
Domain:
Source:
Link to this page:
Please notify us if you found a problem with this document:
{{id}} {{{paragraph}}}