Example: confidence

OWASP Application Security Verification Standard 4.0-en

Application Security Verification Standard Final March 2019 OWASP Application Security Verification Standard 2 Table of Contents Frontispiece .. 7 About the Standard .. 7 Copyright and License .. 7 Project Leads .. 7 Contributors and Reviewers .. 7 Preface .. 8 What's new in .. 8 Using the ASVS .. 9 Application Security Verification Levels .. 9 How to use this Standard .. 10 Level 1 - First steps, automated, or whole of portfolio view .. 10 Level 2 - Most applications .. 10 Level 3 - High value, high assurance, or high safety .. 11 Applying ASVS in Practice .. 11 Assessment and Certification .. 11 OWASP 's Stance on ASVS Certifications and Trust Marks.

OWASP Application Security Verification Standard 4.0 8 Preface Welcome to the Application Security Verification Standard (ASVS) version 4.0. The ASVS is a community-driven

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Other abuse

Advertisement

Transcription of OWASP Application Security Verification Standard 4.0-en

1 Application Security Verification Standard Final March 2019 OWASP Application Security Verification Standard 2 Table of Contents Frontispiece .. 7 About the Standard .. 7 Copyright and License .. 7 Project Leads .. 7 Contributors and Reviewers .. 7 Preface .. 8 What's new in .. 8 Using the ASVS .. 9 Application Security Verification Levels .. 9 How to use this Standard .. 10 Level 1 - First steps, automated, or whole of portfolio view .. 10 Level 2 - Most applications .. 10 Level 3 - High value, high assurance, or high safety .. 11 Applying ASVS in Practice .. 11 Assessment and Certification .. 11 OWASP 's Stance on ASVS Certifications and Trust Marks.

2 11 Guidance for Certifying Organizations .. 11 Testing Method .. 12 Other uses for the ASVS .. 12 As Detailed Security Architecture Guidance .. 12 As a Replacement for Off-the-shelf Secure Coding Checklists .. 13 As a Guide for Automated Unit and Integration Tests .. 13 For Secure Development Training .. 13 As a Driver for Agile Application Security .. 13 As a Framework for Guiding the Procurement of Secure Software .. 13 V1: Architecture, Design and Threat Modeling Requirements .. 14 Control Objective .. 14 Secure Software Development Lifecycle Requirements .. 14 Authentication Architectural Requirements .. 15 Session Management Architectural Requirements.

3 15 Access Control Architectural Requirements .. 15 Input and Output Architectural Requirements .. 16 Cryptographic Architectural Requirements .. 16 Errors, Logging and Auditing Architectural Requirements .. 17 Data Protection and Privacy Architectural Requirements .. 17 OWASP Application Security Verification Standard 3 Communications Architectural Requirements .. 17 Malicious Software Architectural Requirements .. 17 Business Logic Architectural Requirements .. 18 Secure File Upload Architectural Requirements .. 18 API Architectural Requirements .. 18 Configuration Architectural Requirements.

4 18 References .. 19 V2: Authentication Verification Requirements .. 20 Control Objective .. 20 NIST 800-63 - Modern, evidence-based authentication Standard .. 20 Selecting an appropriate NIST AAL Level .. 20 Legend .. 20 Password Security Requirements .. 21 General Authenticator Requirements .. 22 Authenticator Lifecycle Requirements .. 23 Credential Storage Requirements .. 23 Credential Recovery Requirements .. 24 Look-up Secret Verifier Requirements .. 25 Out of Band Verifier Requirements .. 25 Single or Multi Factor One Time Verifier Requirements .. 26 Cryptographic Software and Devices Verifier Requirements.

5 27 Service Authentication Requirements .. 27 Additional US Agency Requirements .. 27 Glossary of terms .. 28 References .. 28 V3: Session Management Verification Requirements .. 29 Control Objective .. 29 Security Verification Requirements .. 29 Fundamental Session Management Requirements .. 29 Session Binding Requirements .. 29 Session Logout and Timeout Requirements .. 29 Cookie-based Session Management .. 30 Token-based Session Management .. 31 Re-authentication from a Federation or Assertion .. 31 OWASP Application Security Verification Standard 4 Defenses Against Session Management Exploits.

6 31 Description of the half-open Attack .. 31 References .. 32 V4: Access Control Verification Requirements .. 33 Control Objective .. 33 Security Verification Requirements .. 33 General Access Control Design .. 33 Operation Level Access Control .. 33 Other Access Control Considerations .. 33 References .. 34 V5: Validation, Sanitization and Encoding Verification Requirements .. 35 Control Objective .. 35 Input Validation Requirements .. 35 Sanitization and Sandboxing Requirements .. 36 Output encoding and Injection Prevention Requirements .. 36 Memory, String, and Unmanaged Code Requirements .. 37 Deserialization Prevention Requirements.

7 37 References .. 38 V6: Stored Cryptography Verification Requirements .. 39 Control Objective .. 39 Data Classification .. 39 Algorithms .. 39 Random Values .. 40 Secret Management .. 40 References .. 40 V7: Error Handling and Logging Verification Requirements .. 42 Control Objective .. 42 Log Content Requirements .. 42 Log Processing Requirements .. 42 Log Protection Requirements .. 43 Error Handling .. 43 References .. 44 V8: Data Protection Verification Requirements .. 45 OWASP Application Security Verification Standard 5 Control Objective .. 45 General Data Protection .. 45 Client-side Data Protection.

8 45 Sensitive Private Data .. 46 References .. 47 V9: Communications Verification Requirements .. 48 Control Objective .. 48 Communications Security Requirements .. 48 Server Communications Security Requirements .. 48 References .. 49 V10: Malicious Code Verification Requirements .. 50 Control Objective .. 50 Code Integrity Controls .. 50 Malicious Code Search .. 50 Deployed Application Integrity Controls .. 51 References .. 51 V11: Business Logic Verification Requirements .. 52 Control Objective .. 52 Business Logic Security Requirements .. 52 References .. 53 V12: File and Resources Verification Requirements.

9 54 Control Objective .. 54 File Upload Requirements .. 54 File Integrity Requirements .. 54 File execution Requirements .. 54 File Storage Requirements .. 55 File Download Requirements .. 55 SSRF Protection Requirements .. 55 References .. 55 V13: API and Web Service Verification Requirements .. 56 Control Objective .. 56 Generic Web Service Security Verification Requirements .. 56 RESTful Web Service Verification Requirements .. 56 OWASP Application Security Verification Standard 6 SOAP Web Service Verification Requirements .. 57 GraphQL and other Web Service Data Layer Security Requirements.

10 57 References .. 59 V14: Configuration Verification Requirements .. 60 Control Objective .. 60 Build .. 60 Dependency .. 61 Unintended Security Disclosure Requirements .. 61 HTTP Security Headers Requirements .. 62 Validate HTTP Request Header Requirements .. 62 References .. 62 Appendix A: Glossary .. 63 Appendix B: References .. 65 OWASP Core Projects .. 65 Mobile Security Related Projects .. 65 OWASP Internet of Things related projects .. 65 OWASP Serverless projects .. 65 Others .. 65 Appendix C: Internet of Things Verification Requirements .. 66 Control Objective .. 66 Security Verification Requirements.


Related search queries