Example: bachelor of science

OWASP Application Security Verification Standard 4.0-en

Application Security Verification Standard Final March 2019 OWASP Application Security Verification Standard 2 Table of Contents Frontispiece .. 7 About the Standard .. 7 Copyright and License .. 7 Project Leads .. 7 Contributors and Reviewers .. 7 Preface .. 8 What's new in .. 8 Using the ASVS .. 9 Application Security Verification Levels .. 9 How to use this Standard .. 10 Level 1 - First steps, automated, or whole of portfolio view .. 10 Level 2 - Most applications .. 10 Level 3 - High value, high assurance, or high safety .. 11 Applying ASVS in Practice .. 11 Assessment and Certification .. 11 OWASP 's Stance on ASVS Certifications and Trust Marks .. 11 Guidance for Certifying Organizations .. 11 Testing Method .. 12 Other uses for the ASVS .. 12 As Detailed Security Architecture Guidance .. 12 As a Replacement for Off-the-shelf Secure Coding Checklists .. 13 As a Guide for Automated Unit and Integration Tests.

gaps from long-vanished chapters, and to allow us to segment longer chapters to minimize the number of controls that a developer or team have to comply. For example, if an application does not use JWT, the entire section on JWT in session management is not applicable.

Tags:

  Management, Segment

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Other abuse

Advertisement

Transcription of OWASP Application Security Verification Standard 4.0-en

1 Application Security Verification Standard Final March 2019 OWASP Application Security Verification Standard 2 Table of Contents Frontispiece .. 7 About the Standard .. 7 Copyright and License .. 7 Project Leads .. 7 Contributors and Reviewers .. 7 Preface .. 8 What's new in .. 8 Using the ASVS .. 9 Application Security Verification Levels .. 9 How to use this Standard .. 10 Level 1 - First steps, automated, or whole of portfolio view .. 10 Level 2 - Most applications .. 10 Level 3 - High value, high assurance, or high safety .. 11 Applying ASVS in Practice .. 11 Assessment and Certification .. 11 OWASP 's Stance on ASVS Certifications and Trust Marks .. 11 Guidance for Certifying Organizations .. 11 Testing Method .. 12 Other uses for the ASVS .. 12 As Detailed Security Architecture Guidance .. 12 As a Replacement for Off-the-shelf Secure Coding Checklists .. 13 As a Guide for Automated Unit and Integration Tests.

2 13 For Secure Development Training .. 13 As a Driver for Agile Application Security .. 13 As a Framework for Guiding the Procurement of Secure Software .. 13 V1: Architecture, Design and Threat Modeling Requirements .. 14 Control Objective .. 14 Secure Software Development Lifecycle Requirements .. 14 Authentication Architectural Requirements .. 15 Session management Architectural Requirements .. 15 Access Control Architectural Requirements .. 15 Input and Output Architectural Requirements .. 16 Cryptographic Architectural Requirements .. 16 Errors, Logging and Auditing Architectural Requirements .. 17 Data Protection and Privacy Architectural Requirements .. 17 OWASP Application Security Verification Standard 3 Communications Architectural Requirements .. 17 Malicious Software Architectural Requirements .. 17 Business Logic Architectural Requirements .. 18 Secure File Upload Architectural Requirements.

3 18 API Architectural Requirements .. 18 Configuration Architectural Requirements .. 18 References .. 19 V2: Authentication Verification Requirements .. 20 Control Objective .. 20 NIST 800-63 - Modern, evidence-based authentication Standard .. 20 Selecting an appropriate NIST AAL Level .. 20 Legend .. 20 Password Security Requirements .. 21 General Authenticator Requirements .. 22 Authenticator Lifecycle Requirements .. 23 Credential Storage Requirements .. 23 Credential Recovery Requirements .. 24 Look-up Secret Verifier Requirements .. 25 Out of Band Verifier Requirements .. 25 Single or Multi Factor One Time Verifier Requirements .. 26 Cryptographic Software and Devices Verifier Requirements .. 27 Service Authentication Requirements .. 27 Additional US Agency Requirements .. 27 Glossary of terms .. 28 References .. 28 V3: Session management Verification Requirements .. 29 Control Objective.

4 29 Security Verification Requirements .. 29 Fundamental Session management Requirements .. 29 Session Binding Requirements .. 29 Session Logout and Timeout Requirements .. 29 Cookie-based Session management .. 30 Token-based Session management .. 31 Re-authentication from a Federation or Assertion .. 31 OWASP Application Security Verification Standard 4 Defenses Against Session management Exploits .. 31 Description of the half-open Attack .. 31 References .. 32 V4: Access Control Verification Requirements .. 33 Control Objective .. 33 Security Verification Requirements .. 33 General Access Control Design .. 33 Operation Level Access Control .. 33 Other Access Control Considerations .. 33 References .. 34 V5: Validation, Sanitization and Encoding Verification Requirements .. 35 Control Objective .. 35 Input Validation Requirements .. 35 Sanitization and Sandboxing Requirements.

5 36 Output encoding and Injection Prevention Requirements .. 36 Memory, String, and Unmanaged Code Requirements .. 37 Deserialization Prevention Requirements .. 37 References .. 38 V6: Stored Cryptography Verification Requirements .. 39 Control Objective .. 39 Data Classification .. 39 Algorithms .. 39 Random Values .. 40 Secret management .. 40 References .. 40 V7: Error Handling and Logging Verification Requirements .. 42 Control Objective .. 42 Log Content Requirements .. 42 Log Processing Requirements .. 42 Log Protection Requirements .. 43 Error Handling .. 43 References .. 44 V8: Data Protection Verification Requirements .. 45 OWASP Application Security Verification Standard 5 Control Objective .. 45 General Data Protection .. 45 Client-side Data Protection .. 45 Sensitive Private Data .. 46 References .. 47 V9: Communications Verification Requirements .. 48 Control Objective.

6 48 Communications Security Requirements .. 48 Server Communications Security Requirements .. 48 References .. 49 V10: Malicious Code Verification Requirements .. 50 Control Objective .. 50 Code Integrity Controls .. 50 Malicious Code Search .. 50 Deployed Application Integrity Controls .. 51 References .. 51 V11: Business Logic Verification Requirements .. 52 Control Objective .. 52 Business Logic Security Requirements .. 52 References .. 53 V12: File and Resources Verification Requirements .. 54 Control Objective .. 54 File Upload Requirements .. 54 File Integrity Requirements .. 54 File execution Requirements .. 54 File Storage Requirements .. 55 File Download Requirements .. 55 SSRF Protection Requirements .. 55 References .. 55 V13: API and Web Service Verification Requirements .. 56 Control Objective .. 56 Generic Web Service Security Verification Requirements .. 56 RESTful Web Service Verification Requirements.

7 56 OWASP Application Security Verification Standard 6 SOAP Web Service Verification Requirements .. 57 GraphQL and other Web Service Data Layer Security Requirements .. 57 References .. 59 V14: Configuration Verification Requirements .. 60 Control Objective .. 60 Build .. 60 Dependency .. 61 Unintended Security Disclosure Requirements .. 61 HTTP Security Headers Requirements .. 62 Validate HTTP Request Header Requirements .. 62 References .. 62 Appendix A: Glossary .. 63 Appendix B: References .. 65 OWASP Core Projects .. 65 Mobile Security Related Projects .. 65 OWASP Internet of Things related projects .. 65 OWASP Serverless projects .. 65 Others .. 65 Appendix C: Internet of Things Verification Requirements .. 66 Control Objective .. 66 Security Verification Requirements .. 66 References .. 68 OWASP Application Security Verification Standard 7 Frontispiece About the Standard The Application Security Verification Standard is a list of Application Security requirements or tests that can be used by architects, developers, testers, Security professionals, tool vendors, and consumers to define, build, test and verify secure applications.

8 Copyright and License Version , March 2019 Copyright 2008-2019 The OWASP Foundation. This document is released under the Creative Commons Attribution ShareAlike license. For any reuse or distribution, you must make clear to others the license terms of this work. Project Leads Andrew van der Stock Daniel Cuthbert Jim Manico Josh C Grossman Mark Burnett Contributors and Reviewers Osama Elnaggar Erlend Oftedal Serg Belkommen David Johansson Tonimir Kisasondi Ron Perris Jason Axley Abhay Bhargav Benedikt Bauer Elar Lang ScriptingXSS Philippe De Ryck Grog's Axle Marco Schn riger Jacob Salassi Glenn ten Cate Anthony Weems bschach javixeneize Dan Cornell hello7s Lewis Ardern Jim Newman Stuart Gunter Geoff Baskwill Talargoni St le Pettersen Kelby Ludwig Jason Morrow Rogan Dawes The Application Security Verification Standard is built upon the shoulders of those involved from ASVS in 2008 to in 2016.

9 Much of the structure and Verification items that are still in the ASVS today were originally written by Mike Boberski, Jeff Williams and Dave Wichers, but there are many more contributors. Thank you to all those previously involved. For a comprehensive list of all those who have contributed to earlier versions, please consult each prior version. If a credit is missing from the credit list above, please contact or log a ticket at GitHub to be recognized in future updates. OWASP Application Security Verification Standard 8 Preface Welcome to the Application Security Verification Standard (ASVS) version The ASVS is a community-driven effort to establish a framework of Security requirements and controls that focus on defining the functional and non-functional Security controls required when designing, developing and testing modern web applications and web services. ASVS is the culmination of community effort and industry feedback over the last decade.

10 We have attempted to make it easier to adopt the ASVS for a variety of different use cases throughout any secure software development lifecycle. We expect that there will most likely never be 100% agreement on the contents of any web Application Standard , including the ASVS. Risk analysis is always subjective to some extent, which creates a challenge when attempting to generalize in a one-size-fits-all Standard . However, we hope that the latest updates made in this version are a step in the right direction, and enhance the concepts introduced in this critical industry Standard . What's new in The most significant change in this version is the adoption of the NIST 800-63-3 Digital Identity Guidelines, introducing modern, evidence based, and advanced authentication controls. Although we expect some pushback on aligning with an advanced authentication Standard , we feel that it is essential for standards to be aligned, mainly when another well-regarded Application Security Standard is evidence-based.


Related search queries