Skip to content

OWASP

What is OWASP?

The Open Worldwide Application Security Project, a non-profit foundation that produces resources and tools for improving software security.

Information Security

Each of these is named in at least one of the same controls as owasp. The number is how many controls name both.

What the standards actually require on owasp

Requirements naming owasp across 6 standards, quoted from the control text.

The OWASP Top 10 Proactive Controls are used in the development of web applications.

ISM-1849 · The OWASP Top 10 Proactive Controls are used in the development of web applications.
OWASP ASVS14 controls

Per OWASP ASVS V12: protect file handling + resources. Requirements include (a) validate file uploads including type + size + content + scanning + (b) sandbox file processing + storage + serving + (c) protect against path traversal + null byte injection + simi...

OWASPASVS-12 · File and Resources (V12)

Address OWASP Top 10 A10 Server-Side Request Forgery (SSRF) per OWASP Top 10:2025. SSRF occurs when an application fetches a remote resource without validating the user-supplied URL allowing internal network access + cloud metadata service access + or other un...

OWASPTOP10-10 · A10:2025 Server-Side Request Forgery (SSRF)

Address API3:2023 Broken Object Property Level Authorization (BOPLA) per OWASP API Security Top 10 2023. BOPLA combines previous API3 Excessive Data Exposure and API6 Mass Assignment categories.

OWASPAPI-3 · Broken Object Property Level Authorization (BOPLA)
OWASP MASVS8 controls

Per OWASP MASVS v2 MASVS-PLATFORM: secure platform interaction. Requirements include (a) request only necessary permissions + provide clear justification + (b) implement secure inter-app communication (IPC) restricting receivers + intent filters + URL handlers...

OWASPMASVS-5 · MASVS-PLATFORM: Platform Interaction

Per OWASP DSOMM Metrics and Improvement: measure security maturity + drive continuous improvement. Requirements include (a) define security metrics covering culture + implementation + build + test + monitoring dimensions + (b) measure DSOMM maturity levels per...

DSOMM-6 · Metrics, Maturity Measurement, and Continuous Improvement

Questions people ask about owasp

What is OWASP?
The Open Worldwide Application Security Project, a non-profit foundation that produces resources and tools for improving software security.
Why is OWASP important for compliance?
OWASP is a key concept in Information Security. Understanding owasp helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address OWASP?
OWASP appears in the requirement text of Australian Information Security Manual, OWASP ASVS, OWASP Top 10:2025, OWASP API Security Top 10 - 2023, OWASP MASVS. Across these standards we have identified 49 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about OWASP?
Explore our compliance framework pages to see how owasp applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how OWASP applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.