Skip to main content

OWASP ASVS 4.0.3 Level 3

69 requirements mapped to controls.

Requirements

RequirementTitleControlsOwner
V1.1Secure Software Development LifecycleSID-OPS-08platform
V1.2Authentication ArchitectureSID-AUTH-01, SID-AUTH-02, SID-AUTH-03, SID-AUTH-04platform
V1.4Access Control ArchitectureSID-ACCESS-01, SID-ACCESS-04platform
V1.5Input and Output ArchitectureSID-HARD-02, SID-TRANS-04platform
V1.6Cryptographic ArchitectureSID-CRYPTO-01, SID-CRYPTO-02, SID-CRYPTO-03, SID-CRYPTO-05platform
V1.7Errors, Logging and Auditing ArchitectureSID-AUDIT-01, SID-OPS-06platform
V1.8Data Protection and Privacy ArchitectureSID-DATA-06, SID-PRIV-01platform
V1.9Communications ArchitectureSID-TRANS-01platform
V1.10Malicious Software ArchitectureSID-OPS-04platform
V1.11Business Logic ArchitectureSID-OPS-08platform
V1.12Secure File Upload ArchitectureSID-HARD-07platform
V1.14Configuration ArchitectureSID-HARD-03, SID-OPS-04platform
V2.1Password SecuritySID-ARCH-01platform
V2.2General Authenticator SecuritySID-AUTH-01, SID-ACCESS-02platform
V2.3Authenticator LifecycleSID-AUTH-01platform
V2.4Credential StorageSID-ARCH-01platform
V2.5Credential RecoverySID-ARCH-01platform
V2.6Look-up Secret VerifierSID-ARCH-01platform
V2.7Out of Band VerifierSID-ARCH-01platform
V2.8One Time VerifierSID-ARCH-01platform
V2.9Cryptographic VerifierSID-CRYPTO-01, SID-KEY-01platform
V2.10SID-CRYPTO-01platform
V3.1Fundamental Session Management SecuritySID-AUTH-02platform
V3.2Session BindingSID-AUTH-02platform
V3.3Session TerminationSID-AUTH-02platform
V3.4Cookie-based Session ManagementSID-AUTH-02platform
V3.5Token-based Session ManagementSID-AUTH-02platform
V3.6Federated Re-authenticationSID-AUTH-03platform
V3.7Defenses Against Session Management ExploitsSID-AUTH-02platform
V4.1General Access Control DesignSID-ACCESS-01, SID-ACCESS-04platform
V4.2Operation Level Access ControlSID-ACCESS-01platform
V4.3Other Access Control ConsiderationsSID-HARD-03, SID-ACCESS-01platform
V5.1Input ValidationSID-HARD-02platform
V5.2Sanitization and SandboxingSID-HARD-02, SID-TRANS-04platform
V5.3Output Encoding and Injection PreventionSID-HARD-02platform
V5.4Memory, String, and Unmanaged CodeSID-HARD-02platform
V5.5Deserialization PreventionSID-HARD-02platform
V6.1Data ClassificationSID-DATA-06, SID-CRYPTO-03platform
V6.2AlgorithmsSID-CRYPTO-01, SID-CRYPTO-05platform
V6.3Random ValuesSID-CRYPTO-05platform
V6.4Secret ManagementSID-CRYPTO-01platform
V7.1Log ContentSID-AUDIT-01platform
V7.2Log ProcessingSID-AUDIT-01, SID-OPS-06platform
V7.3Log ProtectionSID-AUDIT-01platform
V7.4Error HandlingSID-HARD-01platform
V8.1General Data ProtectionSID-DATA-08, SID-HARD-02platform
V8.2Client-side Data ProtectionSID-HARD-05platform
V8.3Sensitive Private DataSID-DATA-06, SID-PRIV-01, SID-PRIV-03platform
V9.1Client Communication SecuritySID-TRANS-01platform
V9.2Server Communication SecuritySID-TRANS-01platform
V10.1Code IntegritySID-OPS-04platform
V10.2Malicious Code SearchSID-OPS-04platform
V10.3Application IntegritySID-HARD-05, SID-OPS-04platform
V11.1Business Logic SecuritySID-ACCESS-02, SID-OPS-08platform
V12.1File UploadSID-HARD-07platform
V12.2File IntegritySID-HARD-07platform
V12.3File ExecutionSID-HARD-02platform
V12.4File StorageSID-HARD-07platform
V12.5File DownloadSID-HARD-07platform
V12.6SSRF ProtectionSID-TRANS-04platform
V13.1Generic Web Service SecuritySID-HARD-02, SID-ACCESS-04platform
V13.2RESTful Web ServiceSID-HARD-02platform
V13.3SOAP Web ServiceSID-ARCH-01platform
V13.4GraphQLSID-ARCH-01platform
V14.1Build and DeploySID-OPS-08, SID-OPS-04platform
V14.2DependencySID-OPS-04, SID-ORG-04platform
V14.3Unintended Security DisclosureSID-HARD-01platform
V14.4HTTP Security HeadersSID-HARD-05platform
V14.5HTTP Request Header ValidationSID-HARD-02platform