OWASP

acronym

securityweb dev

Stands for: Open Worldwide Application Security Project

A nonprofit community that produces free, widely used guidance on application security.

OWASP is best known for the OWASP Top 10, its regularly updated list of the most critical web application risks, but it also ships tools and cheat sheets. It is a common reference point when talking about what a WAF or a secure-coding review should cover.

OWASP is the open community behind the Top Ten, the ASVS verification standard, the testing guide and a long list of tools. The Top Ten is the piece everyone knows and the piece most often misused: it is an awareness document describing the categories most commonly found, not a checklist that constitutes a security programme when completed.

The more useful artefacts are the less famous ones. ASVS gives graded, testable requirements suitable for writing into a contract; the cheat sheets answer specific implementation questions with current guidance rather than folklore. Anyone whose security requirements are literally the Top Ten has adopted a list of what other people found rather than an analysis of what they themselves are exposed to.

Also known as: owasp, owasp top 10, owasp top ten

All glossary entries