OWASP Top 10
What is OWASP Top 10?
A regularly updated report from the Open Web Application Security Project that lists the ten most critical web application security risks. The OWASP Top 10 is widely adopted as a baseline for web application security testing.
Terms that appear alongside owasp top 10
Each of these is named in at least one of the same controls as owasp top 10. The number is how many controls name both.
- owasp 17 shared controls
- policy 4 shared controls
- authentication 4 shared controls
- security testing 3 shared controls
- threat modelling 3 shared controls
- software bill of materials sbom 3 shared controls
- software bill of materials 3 shared controls
- integrity 3 shared controls
Frameworks that govern owasp top 10
What the standards actually require on owasp top 10
Requirements naming owasp top 10 across 6 standards, quoted from the control text.
The OWASP Top 10 Proactive Controls are used in the development of web applications.
ISM-1849 · The OWASP Top 10 Proactive Controls are used in the development of web applications. →Address OWASP Top 10 A10 Server-Side Request Forgery (SSRF) per OWASP Top 10:2025. SSRF occurs when an application fetches a remote resource without validating the user-supplied URL allowing internal network access + cloud metadata service access + or other un...
OWASPTOP10-10 · A10:2025 Server-Side Request Forgery (SSRF) →Provide developers with secure coding training covering OWASP Top 10, AWS specific risks, IAM least privilege and use of managed security services.
SEC11-BP01 · Train for application security →Conduct role-specific security awareness and skills training. Example implementations include secure system administration courses for IT professionals, (OWASP® Top 10 vulnerability awareness and prevention training for web application developers, and advanced...
CIS-14.9 · Conduct Role-Specific Security Awareness and Skills Training →Security Layer 3 Applications per X.805 Clause 7.3: The Applications Security Layer addresses requirements of network-based applications accessed by service provider customers.
X805-Layer3-Applications-Security-Email-Web-Directory-File-Transfer-E-Commerce-Video · ITU-T X.805 Security Layer 3 - Applications Security + Email + Web + Directory + File Transfer + E-Commerce + Video Conferencing + IM + Office Collaboration + SaaS + B2B EDI + Mobile Apps + APIs →Vulnerability Management is a core technical control area per FSA Cybersecurity Guidelines. (1) Vulnerability Discovery: (a) Authenticated and Unauthenticated Scanning - Nessus + Qualys + Rapid7 + open source; (b) DAST Dynamic Application Security Testing;
JP-FSA-CYB-Vulnerability-Management-Patching-CVE-Risk-Based-Prioritisation-Penetration-Testing-Red-Team · Japan FSA Cybersecurity Vulnerability Management + Patching + CVE Tracking + Risk-Based Prioritisation + Penetration Testing + Red-Team + Bug Bounty + Coordinated Vulnerability Disclosure + Zero-Day Response →Questions people ask about owasp top 10
What is OWASP Top 10?
Why is OWASP Top 10 important for compliance?
Which compliance frameworks address OWASP Top 10?
Where can I learn more about OWASP Top 10?
See how OWASP Top 10 applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.