Главная
Study mode:
on
1
Introduction
2
ASVS
3
The Team
4
NIST 863
5
Changes in web development
6
Common Weakness Enumeration
7
Standards Worth
8
Levels of Severity
9
DevOps
10
What we removed
11
Architecture
12
Authentication
13
Password Storage
14
Session Management
15
Input Validation
16
Store Cryptography
17
Data Protection
18
Communication Security
19
Business Logic Verification
20
REST Security
Description:
Explore a comprehensive conference talk that delves into the limitations of relying solely on the OWASP Top Ten for web application security. Learn why the OWASP Application Security Verification Standard (ASVS) v4.0 provides a more robust framework for defining and implementing secure software. Discover how the ASVS's 180+ requirements offer a nuanced approach to technical security controls for web and API applications, surpassing the basic awareness provided by top ten lists. Gain insights into using the ASVS as a foundation for a thorough Application Security program, covering topics such as architecture, authentication, password storage, session management, input validation, cryptography, data protection, communication security, business logic verification, and REST security.

From the OWASP Top Ten to the OWASP ASVS

NDC Conferences
Add to list
0:00 / 0:00