Abuse Case
What is Abuse Case?
A security testing technique that identifies ways a system could be misused by threat actors, complementing traditional use case analysis.
Terms that appear alongside abuse case
Each of these is named in at least one of the same controls as abuse case. The number is how many controls name both.
- owasp 3 shared controls
- security controls 2 shared controls
- security testing 2 shared controls
Frameworks that govern abuse case
What the standards actually require on abuse case
Requirements naming abuse case across 3 standards, quoted from the control text.
Per OWASP ASVS V11: verify business logic. Requirements include (a) identify + threat-model business logic flows including sensitive operations + multi-step workflows + (b) implement business logic security controls including step ordering + state validation +...
OWASPASVS-11 · Business Logic Verification (V11) →Per OWASP SAMM v2 Verification business function: verify security through assessment + testing. Security Practices: (1) Architecture Assessment including architecture validation + compliance + (2) Requirements-Driven Testing including security testing per requ...
OWASPSAMM-4 · Verification: Architecture Assessment, Requirements-Driven Testing, Security Testing →Address OWASP Top 10 A04 Insecure Design + A11 API Abuse and Business Logic Attacks per OWASP Top 10:2025. Insecure Design reflects missing or inadequate security design including missing threat modelling + missing security requirements + insecure reference ar...
OWASPTOP10-4 · A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse) →Questions people ask about abuse case
What is Abuse Case?
Why is Abuse Case important for compliance?
Which compliance frameworks address Abuse Case?
Where can I learn more about Abuse Case?
See how Abuse Case applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.