diff --git a/CHANGELOG.md b/CHANGELOG.md index 9d2065d..4d28e67 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -22,6 +22,17 @@ Versioning follows [Semantic Versioning](https://semver.org/spec/v2.0.0.html). 6.1.2/3.5.1, LLM08 hidden context 10.2.4, LLM10 generated code 9.3.7). AISVS has no requirement for scanning generated code itself; the LLM10 section says so. +### Changed + +- **ASVS framework renamed `OWASP ASVS 4.0.3` → `OWASP ASVS 5.0.0`** in the generated data, exports, registry, + webapp and docs. The three ASVS mapping files were already translated to 5.0.0 identifiers (#123); this brings the + framework's name in line. **Consumers that filter exports by framework name must update the string.** 5.0.0 is + the latest versioned ASVS release; ASVS's `latest` tag is its Bleeding Edge build, not a release. Six incident + `control_failures` (INC-138, 139, 140, 145, 146, 147) that cited 5.0.0 identifiers under the old name now carry + the correct one. The 24 rows whose 4.0.3 requirement 5.0.0 deleted keep their 4.0.3 identifier and their DRAFT + marker, and `docs/classifier-predictions.js`, the dated 2026-04-09 classifier snapshot on 4.0.3 chapters, keeps + its 4.0.3 label. + Next: npm publish to npmjs.com, custom domain (crosswalk.owasp.org), vendor integration packs, NeMo Guardrails configs. --- diff --git a/RATIONALE.md b/RATIONALE.md index 6b1d398..f361252 100644 --- a/RATIONALE.md +++ b/RATIONALE.md @@ -95,7 +95,7 @@ Every framework was selected based on at least two of the following: | Framework | Why Included | |---|---| -| **OWASP ASVS 4.0.3** | Application Security Verification Standard with three levels (L1/L2/L3). Maps GenAI risks to specific verification requirements so development teams can test for AI-specific vulnerabilities using the same ASVS methodology they use for traditional web apps. | +| **OWASP ASVS 5.0.0** | Application Security Verification Standard with three levels (L1/L2/L3). Maps GenAI risks to specific verification requirements so development teams can test for AI-specific vulnerabilities using the same ASVS methodology they use for traditional web apps. | | **OWASP SAMM v2.0** | Software Assurance Maturity Model. Maps GenAI risks to maturity practices across Governance, Design, Implementation, Verification, and Operations. Helps organisations measure and improve their AI security programme maturity over time. | | **NIST SP 800-218A** | Secure Software Development Framework extension for AI. Maps GenAI risks to AI-specific secure development practices (PW/PS/RV). The authoritative US guidance for secure AI SDLC — directly applicable to developer workflows. | diff --git a/README.md b/README.md index e8d436c..93047d5 100644 --- a/README.md +++ b/README.md @@ -113,7 +113,7 @@ All free. All open-source. Built for practitioners. | [MAESTRO — CSA](https://cloudsecurityalliance.org/blog/2025/02/06/agentic-ai-threat-modeling-framework-maestro) | ✅ | ✅ | ✅ | | [ISO/IEC 42001:2023](https://www.iso.org/standard/81230.html) | ✅ | ✅ | ✅ | | [CIS Controls v8.1](https://www.cisecurity.org/controls) | ✅ | ✅ | ✅ | -| [OWASP ASVS 4.0.3](https://owasp.org/projects/asvs) | ✅ | ✅ | ✅ | +| [OWASP ASVS 5.0.0](https://owasp.org/projects/asvs) | ✅ | ✅ | ✅ | | [OWASP AISVS 1.0](https://github.com/OWASP/AISVS/tree/main/1.0/en) | ✅ | ✅ | ✅ | | [SOC 2 Trust Services Criteria](https://www.aicpa-cima.com/resources/landing/2017-trust-services-criteria) | ✅ | ✅ | ✅ | | [PCI DSS v4.0](https://www.pcisecuritystandards.org/document_library/) | ✅ | ✅ | ✅ | @@ -140,7 +140,7 @@ All free. All open-source. Built for practitioners. | [LLM_ISO27001.md](llm-top10/LLM_ISO27001.md) | ISO/IEC 27001:2022 | ISMS extension checklist, 2022 new controls mapped to LLM risks | | [LLM_ISO42001.md](llm-top10/LLM_ISO42001.md) | ISO/IEC 42001:2023 | AIMS implementation checklist, ISO 27001 integration guidance | | [LLM_CISControls.md](llm-top10/LLM_CISControls.md) | CIS Controls v8.1 | IG1/IG2/IG3 tiered safeguards per vulnerability | -| [LLM_ASVS.md](llm-top10/LLM_ASVS.md) | OWASP ASVS 4.0.3 | L1/L2/L3 verification requirements with ASVS checklist | +| [LLM_ASVS.md](llm-top10/LLM_ASVS.md) | OWASP ASVS 5.0.0 | L1/L2/L3 verification requirements with ASVS checklist | | [LLM_ISA62443.md](llm-top10/LLM_ISA62443.md) | ISA/IEC 62443 — OT/ICS | Zone model, SL ratings, FR/SR references, OT deployment checklist | | [LLM_NISTSP80082.md](llm-top10/LLM_NISTSP80082.md) | NIST SP 800-82 Rev 3 | SP 800-53 controls, US regulatory crosswalk (NERC CIP, AWIA, CMMC) | | [LLM_NISTCSF2.md](llm-top10/LLM_NISTCSF2.md) | NIST CSF 2.0 | Six-function mapping including new GOVERN function, CSF 2.0 profile | @@ -174,7 +174,7 @@ All free. All open-source. Built for practitioners. | [Agentic_MAESTRO.md](agentic-top10/Agentic_MAESTRO.md) | MAESTRO — CSA | Seven-layer architectural threat model, layer-to-ASI mapping, session guide | | [Agentic_OWASP_NHI.md](agentic-top10/Agentic_OWASP_NHI.md) | OWASP NHI Top 10 | Full NHI-to-ASI cross-mapping, NHI programme maturity table | | [Agentic_CISControls.md](agentic-top10/Agentic_CISControls.md) | CIS Controls v8.1 | IG1/IG2/IG3 safeguards, agentic NHI treated as CIS 5 privileged access | -| [Agentic_ASVS.md](agentic-top10/Agentic_ASVS.md) | OWASP ASVS 4.0.3 | L1/L2/L3 verification checklist for agentic deployments | +| [Agentic_ASVS.md](agentic-top10/Agentic_ASVS.md) | OWASP ASVS 5.0.0 | L1/L2/L3 verification checklist for agentic deployments | | [Agentic_AITG.md](agentic-top10/Agentic_AITG.md) | OWASP AI Testing Guide | 50 structured test cases across ASI01–ASI10 with pre-deployment gates | | [Agentic_AIVSS.md](agentic-top10/Agentic_AIVSS.md) | OWASP AIVSS | Dual-scenario scoring (supervised vs autonomous), +1.79 autonomy premium | | [Agentic_ENISA.md](agentic-top10/Agentic_ENISA.md) | ENISA Multilayer Framework | L1/L2/L3 layer mapping, EU AI Act Art. 14/15/52 alignment, NIS2 Article 23 incident assessment guidance | @@ -203,7 +203,7 @@ All free. All open-source. Built for practitioners. | [DSGAI_MAESTRO.md](dsgai-2026/DSGAI_MAESTRO.md) | MAESTRO — CSA | Layer-origin analysis for all 21 entries, L2 data operations as 52% of DSGAI threat surface | | [DSGAI_SOC2.md](dsgai-2026/DSGAI_SOC2.md) | SOC 2 Trust Services Criteria | TSC mapping for SaaS and cloud GenAI deployments | | [DSGAI_PCIDSS.md](dsgai-2026/DSGAI_PCIDSS.md) | PCI DSS v4.0 | CHD scope guidance, PCI audit checklist for GenAI data | -| [DSGAI_ASVS.md](dsgai-2026/DSGAI_ASVS.md) | OWASP ASVS 4.0.3 | L1/L2/L3 verification requirements for all 21 DSGAI entries, 4-phase implementation priority | +| [DSGAI_ASVS.md](dsgai-2026/DSGAI_ASVS.md) | OWASP ASVS 5.0.0 | L1/L2/L3 verification requirements for all 21 DSGAI entries, 4-phase implementation priority | | [DSGAI_CISControls.md](dsgai-2026/DSGAI_CISControls.md) | CIS Controls v8.1 | IG1/IG2/IG3 safeguards for all 21 entries, GenAI data security implementation groups | | [DSGAI_CWE_CVE.md](dsgai-2026/DSGAI_CWE_CVE.md) | CWE / CVE | CWE root cause taxonomy and confirmed CVE evidence for all 21 DSGAI entries | | [DSGAI_ENISA.md](dsgai-2026/DSGAI_ENISA.md) | ENISA Multilayer Framework | L1/L2/L3 layer mapping, EU AI Act and NIS2 alignment for all 21 DSGAI entries | @@ -310,7 +310,7 @@ crosswalk/ │ ├── DSGAI_MAESTRO.md ← Threat modeling — data operations lens │ ├── DSGAI_SOC2.md │ ├── DSGAI_PCIDSS.md -│ ├── DSGAI_ASVS.md ← OWASP ASVS 4.0.3 +│ ├── DSGAI_ASVS.md ← OWASP ASVS 5.0.0 │ ├── DSGAI_CISControls.md ← CIS Controls v8.1 │ ├── DSGAI_CWE_CVE.md ← Root cause taxonomy + CVEs │ ├── DSGAI_ENISA.md ← EU / NIS2 diff --git a/agentic-top10/Agentic_ASVS.md b/agentic-top10/Agentic_ASVS.md index 3bf204b..84e5db8 100644 --- a/agentic-top10/Agentic_ASVS.md +++ b/agentic-top10/Agentic_ASVS.md @@ -7,15 +7,15 @@ License : CC BY-SA 4.0 --> -# Agentic Top 10 2026 × OWASP ASVS 4.0.3 +# Agentic Top 10 2026 × OWASP ASVS 5.0.0 Mapping the [OWASP Top 10 for Agentic Applications 2026](https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/) to the -[OWASP Application Security Verification Standard (ASVS) 4.0.3](https://owasp.org/projects/asvs) +[OWASP Application Security Verification Standard (ASVS) 5.0.0](https://owasp.org/projects/asvs) — the framework for testing and verifying web application and API -security, organised into 14 chapters with three verification levels. +security, organised into 17 chapters with three verification levels. > **Mapped against ASVS 5.0.0.** The identifiers below were translated from 4.0.3 > using the ASVS project’s own mapping file, [`mapping_v4.0.3_to_v5.0.0.yml`][asvs-map], @@ -725,7 +725,7 @@ Without complete audit trails, rogue behaviour cannot be detected. ## References -- [OWASP ASVS 4.0.3](https://owasp.org/projects/asvs) +- [OWASP ASVS 5.0.0](https://owasp.org/projects/asvs) - [OWASP ASVS GitHub](https://github.com/OWASP/ASVS) - [OWASP Agentic Top 10 2026](https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/) - [OWASP AI Testing Guide](https://owasp.org/www-project-ai-testing-guide/) diff --git a/data/backlinks.json b/data/backlinks.json index e5f09bb..6bf2d01 100644 --- a/data/backlinks.json +++ b/data/backlinks.json @@ -30527,7 +30527,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.1.2", "control_name": "Threat modelling of all data flows", "entries": [ @@ -30570,7 +30570,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.1.4", "control_name": "Trust boundaries documented and enforced", "entries": [ @@ -30586,7 +30586,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.2.4", "control_name": "Verify that data selection or database queries (e.g., SQL, HQL, NoSQL, Cypher) use parameterized queries, ORMs, entity frameworks, or are otherwise protected from SQL Injection and other database injection attacks. This is also relevant when writing stored procedures.", "entries": [ @@ -30620,7 +30620,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.1", "control_name": "Verify that all untrusted HTML input from WYSIWYG editors or similar is sanitized using a well-known and secure HTML sanitization library or framework feature.", "entries": [ @@ -30690,7 +30690,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.2", "control_name": "Verify that the application avoids the use of eval() or other dynamic code execution features such as Spring Expression Language (SpEL). Where there is no alternative, any user input being included must be sanitized before being executed.", "entries": [ @@ -30715,7 +30715,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.5", "control_name": "Output encoding for context", "entries": [ @@ -30731,7 +30731,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.6", "control_name": "Defined output structure", "entries": [ @@ -30747,7 +30747,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.7", "control_name": "Verify that the application protects against template injection attacks by not allowing templates to be built based on untrusted input. Where there is no alternative, any untrusted input being included dynamically during template creation must be sanitized or strictly validated.", "entries": [ @@ -30799,7 +30799,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.5.3", "control_name": "Verify API rate limiting", "entries": [ @@ -30851,7 +30851,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V10.2.1", "control_name": "Verify third-party components are current and free from vulnerabilities", "entries": [ @@ -30894,7 +30894,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V10.2.2", "control_name": "Verify only minimal approved external libraries are used", "entries": [ @@ -30937,7 +30937,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V11.1.7", "control_name": "Anti-automation controls", "entries": [ @@ -30953,7 +30953,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V12.2.1", "control_name": "Verify that TLS is used for all connectivity between a client and external facing, HTTP-based services, and does not fall back to insecure or unencrypted communications.", "entries": [ @@ -30987,7 +30987,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V13.1.2", "control_name": "API throttling", "entries": [ @@ -31003,7 +31003,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V13.2.1", "control_name": "Integration secrets not hardcoded", "entries": [ @@ -31019,7 +31019,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V13.4.5", "control_name": "Verify that documentation (such as for internal APIs) and monitoring endpoints are not exposed unless explicitly intended.", "entries": [ @@ -31044,7 +31044,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.1.1", "control_name": "Verify that all sensitive data created and processed by the application has been identified and classified into protection levels. This includes data that is only encoded and therefore easily decoded, such as Base64 strings or the plaintext payload inside a JWT. Protection levels need to take into account any data protection and privacy regulations and standards which the application is required to comply with.", "entries": [ @@ -31132,7 +31132,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.1.2", "control_name": "Data transferred using current TLS", "entries": [ @@ -31148,7 +31148,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.1.4", "control_name": "All components inventoried", "entries": [ @@ -31164,7 +31164,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.2.1", "control_name": "Verify that sensitive data is only sent to the server in the HTTP message body or header fields, and that the URL and query string do not contain sensitive information, such as an API key or session token.", "entries": [ @@ -31207,7 +31207,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.2.2", "control_name": "Verify that the application prevents sensitive data from being cached in server components, such as load balancers and application caches, or ensures that the data is securely purged after use.", "entries": [ @@ -31250,7 +31250,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V15.3.3", "control_name": "Verify that the application has countermeasures to protect against mass assignment attacks by limiting allowed fields per controller and action, e.g., it is not possible to insert or update a field value when it was not intended to be part of that action.", "entries": [ @@ -31266,7 +31266,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V15.3.7", "control_name": "Verify that the application has defenses against HTTP parameter pollution attacks, particularly if the application framework makes no distinction about the source of request parameters (query string, body parameters, cookies, or header fields).", "entries": [ @@ -31327,7 +31327,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.2.5", "control_name": "No credential logging", "entries": [ @@ -31343,7 +31343,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.3.1", "control_name": "Verify that all authentication operations are logged, including successful and unsuccessful attempts. Additional metadata, such as the type of authentication or factors used, should also be collected.", "entries": [ @@ -31386,7 +31386,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.3.2", "control_name": "Verify that failed authorization attempts are logged. For L3, this must include logging all authorization decisions, including logging when sensitive data is accessed (without logging the sensitive data itself).", "entries": [ @@ -31438,7 +31438,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.5.1", "control_name": "Verify that a generic message is returned to the consumer when an unexpected or security-sensitive error occurs, ensuring no exposure of sensitive internal system data such as stack traces, queries, secret keys, and tokens.", "entries": [ @@ -31490,7 +31490,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.5.3", "control_name": "Access control failures logged", "entries": [ @@ -31515,7 +31515,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V2.2.1", "control_name": "Input validation server-side", "entries": [ @@ -31549,7 +31549,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V2.3.1", "control_name": "Verify that the application will only process business logic flows for the same user in the expected sequential step order and without skipping steps.", "entries": [ @@ -31583,7 +31583,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V2.4.1", "control_name": "Verify that anti-automation controls are in place to protect against excessive calls to application functions that could lead to data exfiltration, garbage-data creation, quota exhaustion, rate-limit breaches, denial-of-service, or overuse of costly resources.", "entries": [ @@ -31617,7 +31617,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V2.4.2", "control_name": "Verify that business logic flows require realistic human timing, preventing excessively rapid transaction submissions.", "entries": [ @@ -31687,7 +31687,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V3.5.1", "control_name": "Verify that, if the application does not rely on the CORS preflight mechanism to prevent disallowed cross-origin requests to use sensitive functionality, these requests are validated to ensure they originate from the application itself. This may be done by using and validating anti-forgery tokens or requiring extra HTTP header fields that are not CORS-safelisted request-header fields. This is to defend against browser-based request forgery attacks, commonly known as cross-site request forgery (CSRF).", "entries": [ @@ -31703,7 +31703,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V3.6.1", "control_name": "Verify that client-side assets, such as JavaScript libraries, CSS, or web fonts, are only hosted externally (e.g., on a Content Delivery Network) if the resource is static and versioned and Subresource Integrity (SRI) is used to validate the integrity of the asset. If this is not possible, there should be a documented security decision to justify this for each resource.", "entries": [ @@ -31728,7 +31728,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V5.2.1", "control_name": "Verify that the application will only accept files of a size which it can process without causing a loss of performance or a denial of service attack.", "entries": [ @@ -31780,7 +31780,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V5.2.4", "control_name": "Malicious file detection on upload", "entries": [ @@ -31796,7 +31796,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V6.2.1", "control_name": "Verify that user set passwords are at least 8 characters in length although a minimum of 15 characters is strongly recommended.", "entries": [ @@ -31830,7 +31830,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V7.4.1", "control_name": "Verify that when session termination is triggered (such as logout or expiration), the application disallows any further use of the session. For reference tokens or stateful sessions, this means invalidating the session data at the application backend. Applications using self-contained tokens will need a solution such as maintaining a list of terminated tokens, disallowing tokens produced before a per-user date and time or rotating a per-user signing key.", "entries": [ @@ -31855,7 +31855,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.1.3", "control_name": "Sensitive data not in session storage", "entries": [ @@ -31871,7 +31871,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.1.4", "control_name": "Sensitive data minimisation", "entries": [ @@ -31914,7 +31914,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.2.1", "control_name": "Verify that the application ensures that function-level access is restricted to consumers with explicit permissions.", "entries": [ @@ -32047,7 +32047,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.3.1", "control_name": "Verify that the application enforces authorization rules at a trusted service layer and doesn't rely on controls that an untrusted consumer could manipulate, such as client-side JavaScript.", "entries": [ @@ -32117,7 +32117,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.3.10", "control_name": "Personal data not kept longer than needed", "entries": [ @@ -32133,7 +32133,7 @@ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.3.3", "control_name": "Consent obtained before PI processing", "entries": [ diff --git a/data/entries/ASI01.json b/data/entries/ASI01.json index 7c7da36..b445511 100644 --- a/data/entries/ASI01.json +++ b/data/entries/ASI01.json @@ -310,7 +310,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V15.3.7", "control_name": "Verify that the application has defenses against HTTP parameter pollution attacks, particularly if the application framework makes no distinction about the source of request parameters (query string, body parameters, cookies, or header fields).", "tier": "Foundational", @@ -321,7 +321,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.1", "control_name": "Verify that all untrusted HTML input from WYSIWYG editors or similar is sanitized using a well-known and secure HTML sanitization library or framework feature.", "tier": "Foundational", @@ -332,7 +332,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.7", "control_name": "Verify that the application protects against template injection attacks by not allowing templates to be built based on untrusted input. Where there is no alternative, any untrusted input being included dynamically during template creation must be sanitized or strictly validated.", "tier": "Foundational", @@ -343,7 +343,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.1.2", "control_name": "Threat modelling of all data flows", "tier": "Foundational", @@ -354,7 +354,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V2.4.2", "control_name": "Verify that business logic flows require realistic human timing, preventing excessively rapid transaction submissions.", "tier": "Foundational", diff --git a/data/entries/ASI02.json b/data/entries/ASI02.json index 585136b..88d59c9 100644 --- a/data/entries/ASI02.json +++ b/data/entries/ASI02.json @@ -317,7 +317,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.2.1", "control_name": "Verify that the application ensures that function-level access is restricted to consumers with explicit permissions.", "tier": "Foundational", @@ -328,7 +328,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.3.1", "control_name": "Verify that the application enforces authorization rules at a trusted service layer and doesn't rely on controls that an untrusted consumer could manipulate, such as client-side JavaScript.", "tier": "Foundational", @@ -339,7 +339,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.3.2", "control_name": "Verify that failed authorization attempts are logged. For L3, this must include logging all authorization decisions, including logging when sensitive data is accessed (without logging the sensitive data itself).", "tier": "Foundational", @@ -350,7 +350,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V2.4.2", "control_name": "Verify that business logic flows require realistic human timing, preventing excessively rapid transaction submissions.", "tier": "Foundational", @@ -361,7 +361,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.5.3", "control_name": "Verify API rate limiting", "tier": "Foundational", diff --git a/data/entries/ASI03.json b/data/entries/ASI03.json index 62088fd..76befdf 100644 --- a/data/entries/ASI03.json +++ b/data/entries/ASI03.json @@ -310,7 +310,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V6.2.1", "control_name": "Verify that user set passwords are at least 8 characters in length although a minimum of 15 characters is strongly recommended.", "tier": "Foundational", @@ -321,7 +321,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.2.1", "control_name": "Verify that the application ensures that function-level access is restricted to consumers with explicit permissions.", "tier": "Foundational", @@ -332,7 +332,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.1.1", "control_name": "Verify that all sensitive data created and processed by the application has been identified and classified into protection levels. This includes data that is only encoded and therefore easily decoded, such as Base64 strings or the plaintext payload inside a JWT. Protection levels need to take into account any data protection and privacy regulations and standards which the application is required to comply with.", "tier": "Foundational", @@ -343,7 +343,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.3.1", "control_name": "Verify that all authentication operations are logged, including successful and unsuccessful attempts. Additional metadata, such as the type of authentication or factors used, should also be collected.", "tier": "Foundational", @@ -354,7 +354,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V3.6.1", "control_name": "Verify that client-side assets, such as JavaScript libraries, CSS, or web fonts, are only hosted externally (e.g., on a Content Delivery Network) if the resource is static and versioned and Subresource Integrity (SRI) is used to validate the integrity of the asset. If this is not possible, there should be a documented security decision to justify this for each resource.", "tier": "Foundational", diff --git a/data/entries/ASI04.json b/data/entries/ASI04.json index 82ef2d3..406f1ca 100644 --- a/data/entries/ASI04.json +++ b/data/entries/ASI04.json @@ -321,7 +321,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V10.2.1", "control_name": "Verify third-party components current and free of vulnerabilities", "tier": "Foundational", @@ -332,7 +332,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V10.2.2", "control_name": "Verify only minimal approved external libraries", "tier": "Foundational", @@ -343,7 +343,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V13.4.5", "control_name": "Verify that documentation (such as for internal APIs) and monitoring endpoints are not exposed unless explicitly intended.", "tier": "Foundational", @@ -354,7 +354,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.1.2", "control_name": "Verify threat model covers all data flows", "tier": "Foundational", diff --git a/data/entries/ASI05.json b/data/entries/ASI05.json index 03f548d..0dfccf9 100644 --- a/data/entries/ASI05.json +++ b/data/entries/ASI05.json @@ -310,7 +310,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.1", "control_name": "Verify that all untrusted HTML input from WYSIWYG editors or similar is sanitized using a well-known and secure HTML sanitization library or framework feature.", "tier": "Hardening", @@ -321,7 +321,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.2", "control_name": "Verify that the application avoids the use of eval() or other dynamic code execution features such as Spring Expression Language (SpEL). Where there is no alternative, any user input being included must be sanitized before being executed.", "tier": "Hardening", @@ -332,7 +332,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.7", "control_name": "Verify that the application protects against template injection attacks by not allowing templates to be built based on untrusted input. Where there is no alternative, any untrusted input being included dynamically during template creation must be sanitized or strictly validated.", "tier": "Hardening", @@ -343,7 +343,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.2.4", "control_name": "Verify that data selection or database queries (e.g., SQL, HQL, NoSQL, Cypher) use parameterized queries, ORMs, entity frameworks, or are otherwise protected from SQL Injection and other database injection attacks. This is also relevant when writing stored procedures.", "tier": "Hardening", @@ -354,7 +354,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V2.4.2", "control_name": "Verify that business logic flows require realistic human timing, preventing excessively rapid transaction submissions.", "tier": "Hardening", diff --git a/data/entries/ASI06.json b/data/entries/ASI06.json index f0265d8..9d577d8 100644 --- a/data/entries/ASI06.json +++ b/data/entries/ASI06.json @@ -310,7 +310,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V15.3.7", "control_name": "Verify that the application has defenses against HTTP parameter pollution attacks, particularly if the application framework makes no distinction about the source of request parameters (query string, body parameters, cookies, or header fields).", "tier": "Hardening", @@ -321,7 +321,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.2.1", "control_name": "Verify that the application ensures that function-level access is restricted to consumers with explicit permissions.", "tier": "Hardening", @@ -332,7 +332,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.1.1", "control_name": "Verify that all sensitive data created and processed by the application has been identified and classified into protection levels. This includes data that is only encoded and therefore easily decoded, such as Base64 strings or the plaintext payload inside a JWT. Protection levels need to take into account any data protection and privacy regulations and standards which the application is required to comply with.", "tier": "Hardening", @@ -343,7 +343,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V5.2.1", "control_name": "Verify that the application will only accept files of a size which it can process without causing a loss of performance or a denial of service attack.", "tier": "Hardening", diff --git a/data/entries/ASI07.json b/data/entries/ASI07.json index c656a22..54c56bb 100644 --- a/data/entries/ASI07.json +++ b/data/entries/ASI07.json @@ -310,7 +310,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V12.2.1", "control_name": "Verify that TLS is used for all connectivity between a client and external facing, HTTP-based services, and does not fall back to insecure or unencrypted communications.", "tier": "Hardening", @@ -321,7 +321,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V7.4.1", "control_name": "Verify that when session termination is triggered (such as logout or expiration), the application disallows any further use of the session. For reference tokens or stateful sessions, this means invalidating the session data at the application backend. Applications using self-contained tokens will need a solution such as maintaining a list of terminated tokens, disallowing tokens produced before a per-user date and time or rotating a per-user signing key.", "tier": "Hardening", @@ -332,7 +332,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.2.1", "control_name": "Verify that the application ensures that function-level access is restricted to consumers with explicit permissions.", "tier": "Hardening", @@ -343,7 +343,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.3.1", "control_name": "Verify that all authentication operations are logged, including successful and unsuccessful attempts. Additional metadata, such as the type of authentication or factors used, should also be collected.", "tier": "Hardening", diff --git a/data/entries/ASI08.json b/data/entries/ASI08.json index 79d2ed8..c36e9e1 100644 --- a/data/entries/ASI08.json +++ b/data/entries/ASI08.json @@ -310,7 +310,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V2.3.1", "control_name": "Verify that the application will only process business logic flows for the same user in the expected sequential step order and without skipping steps.", "tier": "Foundational", @@ -321,7 +321,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V2.4.2", "control_name": "Verify that business logic flows require realistic human timing, preventing excessively rapid transaction submissions.", "tier": "Foundational", @@ -332,7 +332,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.5.3", "control_name": "Verify API rate limiting", "tier": "Foundational", @@ -343,7 +343,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.5.1", "control_name": "Verify that a generic message is returned to the consumer when an unexpected or security-sensitive error occurs, ensuring no exposure of sensitive internal system data such as stack traces, queries, secret keys, and tokens.", "tier": "Foundational", diff --git a/data/entries/ASI09.json b/data/entries/ASI09.json index e94d7e1..0ea512c 100644 --- a/data/entries/ASI09.json +++ b/data/entries/ASI09.json @@ -310,7 +310,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V2.3.1", "control_name": "Verify that the application will only process business logic flows for the same user in the expected sequential step order and without skipping steps.", "tier": "Foundational", @@ -321,7 +321,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.1", "control_name": "Verify that all untrusted HTML input from WYSIWYG editors or similar is sanitized using a well-known and secure HTML sanitization library or framework feature.", "tier": "Foundational", @@ -332,7 +332,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.5.1", "control_name": "Verify that a generic message is returned to the consumer when an unexpected or security-sensitive error occurs, ensuring no exposure of sensitive internal system data such as stack traces, queries, secret keys, and tokens.", "tier": "Foundational", @@ -343,7 +343,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.2.1", "control_name": "Verify that sensitive data is only sent to the server in the HTTP message body or header fields, and that the URL and query string do not contain sensitive information, such as an API key or session token.", "tier": "Foundational", diff --git a/data/entries/ASI10.json b/data/entries/ASI10.json index 055645b..446a007 100644 --- a/data/entries/ASI10.json +++ b/data/entries/ASI10.json @@ -320,7 +320,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.3.1", "control_name": "Verify that all authentication operations are logged, including successful and unsuccessful attempts. Additional metadata, such as the type of authentication or factors used, should also be collected.", "tier": "Hardening", @@ -331,7 +331,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.3.2", "control_name": "Verify that failed authorization attempts are logged. For L3, this must include logging all authorization decisions, including logging when sensitive data is accessed (without logging the sensitive data itself).", "tier": "Hardening", @@ -342,7 +342,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V2.4.2", "control_name": "Verify that business logic flows require realistic human timing, preventing excessively rapid transaction submissions.", "tier": "Hardening", @@ -353,7 +353,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.5.3", "control_name": "Verify API rate limiting", "tier": "Hardening", diff --git a/data/entries/DSGAI01.json b/data/entries/DSGAI01.json index fda9aff..1f8b7e5 100644 --- a/data/entries/DSGAI01.json +++ b/data/entries/DSGAI01.json @@ -314,7 +314,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.2.2", "control_name": "Sensitive data not transmitted in URL parameters", "tier": "Foundational", @@ -325,7 +325,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.1.1", "control_name": "Sensitive data identified and classified", "tier": "Foundational", @@ -336,7 +336,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.2.1", "control_name": "Deny by default access control", "tier": "Foundational", @@ -347,7 +347,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.5", "control_name": "Output encoding for context", "tier": "Foundational", @@ -358,7 +358,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.1.1", "control_name": "Sensitive data not stored in cleartext", "tier": "Foundational", diff --git a/data/entries/DSGAI02.json b/data/entries/DSGAI02.json index 208e419..4851933 100644 --- a/data/entries/DSGAI02.json +++ b/data/entries/DSGAI02.json @@ -314,7 +314,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V6.2.1", "control_name": "Passwords minimum 12 characters", "tier": "Foundational", @@ -325,7 +325,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V13.2.1", "control_name": "Integration secrets not hardcoded", "tier": "Foundational", @@ -336,7 +336,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.2.1", "control_name": "Least privilege for service accounts", "tier": "Foundational", @@ -347,7 +347,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.1.2", "control_name": "Data transferred using current TLS", "tier": "Foundational", diff --git a/data/entries/DSGAI03.json b/data/entries/DSGAI03.json index f005dae..dae7bb5 100644 --- a/data/entries/DSGAI03.json +++ b/data/entries/DSGAI03.json @@ -304,7 +304,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.1.4", "control_name": "Trust boundaries documented and enforced", "tier": "Foundational", @@ -316,7 +316,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.5.3", "control_name": "Access control failures logged", "tier": "Foundational", @@ -327,7 +327,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.3.2", "control_name": "Log entries contain required information", "tier": "Foundational", @@ -338,7 +338,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.1.4", "control_name": "All components inventoried", "tier": "Foundational", diff --git a/data/entries/DSGAI04.json b/data/entries/DSGAI04.json index 2f8015c..c5b8be5 100644 --- a/data/entries/DSGAI04.json +++ b/data/entries/DSGAI04.json @@ -304,7 +304,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V2.2.1", "control_name": "Input validation server-side", "tier": "Hardening", @@ -315,7 +315,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V10.2.1", "control_name": "Application only uses official repositories", "tier": "Hardening", @@ -327,7 +327,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V10.2.2", "control_name": "Dependency managers check for vulnerabilities", "tier": "Hardening", @@ -339,7 +339,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V5.2.1", "control_name": "File upload size limits", "tier": "Hardening", diff --git a/data/entries/DSGAI05.json b/data/entries/DSGAI05.json index 07810d0..7b50d59 100644 --- a/data/entries/DSGAI05.json +++ b/data/entries/DSGAI05.json @@ -284,7 +284,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V15.3.7", "control_name": "Input validation using allowlists", "tier": "Foundational", @@ -295,7 +295,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.1", "control_name": "HTML/JS output sanitised", "tier": "Foundational", @@ -306,7 +306,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.5.1", "control_name": "Generic error messages", "tier": "Foundational", diff --git a/data/entries/DSGAI06.json b/data/entries/DSGAI06.json index 8412182..94b504e 100644 --- a/data/entries/DSGAI06.json +++ b/data/entries/DSGAI06.json @@ -294,7 +294,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.3.1", "control_name": "Access control on every request", "tier": "Foundational", @@ -305,7 +305,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V12.2.1", "control_name": "TLS for all connections", "tier": "Foundational", @@ -316,7 +316,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V2.4.1", "control_name": "Business logic limits on repeated actions", "tier": "Foundational", diff --git a/data/entries/DSGAI07.json b/data/entries/DSGAI07.json index 03a4e83..0431d12 100644 --- a/data/entries/DSGAI07.json +++ b/data/entries/DSGAI07.json @@ -304,7 +304,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.1.4", "control_name": "Sensitive data minimisation", "tier": "Foundational", @@ -316,7 +316,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.1.1", "control_name": "Sensitive data identified and classified", "tier": "Foundational", @@ -327,7 +327,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.5.3", "control_name": "Attribute-based access control", "tier": "Foundational", diff --git a/data/entries/DSGAI08.json b/data/entries/DSGAI08.json index 66f4ae0..12b5886 100644 --- a/data/entries/DSGAI08.json +++ b/data/entries/DSGAI08.json @@ -294,7 +294,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.3.3", "control_name": "Consent obtained before PI processing", "tier": "Foundational", @@ -306,7 +306,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.3.10", "control_name": "Personal data not kept longer than needed", "tier": "Foundational", @@ -318,7 +318,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.3.2", "control_name": "Audit trail sufficient for compliance", "tier": "Foundational", diff --git a/data/entries/DSGAI09.json b/data/entries/DSGAI09.json index ec0c751..10159c8 100644 --- a/data/entries/DSGAI09.json +++ b/data/entries/DSGAI09.json @@ -294,7 +294,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.7", "control_name": "Unstructured data sanitised", "tier": "Hardening", @@ -305,7 +305,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.1.4", "control_name": "Sensitive data minimised", "tier": "Hardening", @@ -317,7 +317,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V5.2.4", "control_name": "Malicious file detection on upload", "tier": "Hardening", diff --git a/data/entries/DSGAI10.json b/data/entries/DSGAI10.json index 45929d4..ef8b220 100644 --- a/data/entries/DSGAI10.json +++ b/data/entries/DSGAI10.json @@ -274,7 +274,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.1.1", "control_name": "Sensitive data classified", "tier": "Hardening", @@ -285,7 +285,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.6", "control_name": "Defined output structure", "tier": "Hardening", diff --git a/data/entries/DSGAI11.json b/data/entries/DSGAI11.json index fc9f2f3..8f181cd 100644 --- a/data/entries/DSGAI11.json +++ b/data/entries/DSGAI11.json @@ -294,7 +294,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.2.1", "control_name": "Session tokens unique and random", "tier": "Foundational", @@ -305,7 +305,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V7.4.1", "control_name": "Sessions invalidated after logout", "tier": "Foundational", @@ -316,7 +316,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.3.1", "control_name": "Access control enforced on every request", "tier": "Foundational", @@ -327,7 +327,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.1.3", "control_name": "Sensitive data not in session storage", "tier": "Foundational", diff --git a/data/entries/DSGAI12.json b/data/entries/DSGAI12.json index c75cf94..2b7158f 100644 --- a/data/entries/DSGAI12.json +++ b/data/entries/DSGAI12.json @@ -304,7 +304,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V15.3.7", "control_name": "Allowlist input validation", "tier": "Foundational", @@ -315,7 +315,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.2.4", "control_name": "SQL injection prevention", "tier": "Foundational", @@ -334,7 +334,7 @@ } }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.3.1", "control_name": "Access control on every request", "tier": "Foundational", @@ -345,7 +345,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.5.3", "control_name": "API protection against enumeration", "tier": "Foundational", diff --git a/data/entries/DSGAI13.json b/data/entries/DSGAI13.json index 5bfede0..d2250d5 100644 --- a/data/entries/DSGAI13.json +++ b/data/entries/DSGAI13.json @@ -294,7 +294,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.2.1", "control_name": "Deny by default", "tier": "Foundational", @@ -305,7 +305,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.1.1", "control_name": "Sensitive data not stored in cleartext", "tier": "Foundational", @@ -316,7 +316,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V5.2.1", "control_name": "File upload validation", "tier": "Foundational", diff --git a/data/entries/DSGAI14.json b/data/entries/DSGAI14.json index 2c74821..c3e4f78 100644 --- a/data/entries/DSGAI14.json +++ b/data/entries/DSGAI14.json @@ -294,7 +294,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.2.5", "control_name": "No credential logging", "tier": "Foundational", @@ -305,7 +305,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.2.5", "control_name": "No sensitive data in logs", "tier": "Foundational", @@ -316,7 +316,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.2.2", "control_name": "Sensitive data not in URLs", "tier": "Foundational", @@ -327,7 +327,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.3.1", "control_name": "Access control on log stores", "tier": "Foundational", diff --git a/data/entries/DSGAI15.json b/data/entries/DSGAI15.json index 84a7a7e..6b3d63d 100644 --- a/data/entries/DSGAI15.json +++ b/data/entries/DSGAI15.json @@ -294,7 +294,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.2.1", "control_name": "Deny by default access control", "tier": "Foundational", @@ -305,7 +305,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.1.4", "control_name": "Data minimisation", "tier": "Foundational", @@ -317,7 +317,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.2.1", "control_name": "Session isolation", "tier": "Foundational", diff --git a/data/entries/DSGAI16.json b/data/entries/DSGAI16.json index e5d6285..8b55e00 100644 --- a/data/entries/DSGAI16.json +++ b/data/entries/DSGAI16.json @@ -294,7 +294,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.2.1", "control_name": "Least privilege", "tier": "Foundational", @@ -305,7 +305,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V2.2.1", "control_name": "Business logic prevents excess data access", "tier": "Foundational", @@ -316,7 +316,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.1.2", "control_name": "Secure architecture and design", "tier": "Foundational", diff --git a/data/entries/DSGAI17.json b/data/entries/DSGAI17.json index 367f943..89578d4 100644 --- a/data/entries/DSGAI17.json +++ b/data/entries/DSGAI17.json @@ -284,7 +284,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V11.1.7", "control_name": "Anti-automation controls", "tier": "Foundational", @@ -296,7 +296,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V13.1.2", "control_name": "API throttling", "tier": "Foundational", diff --git a/data/entries/DSGAI18.json b/data/entries/DSGAI18.json index 3eea231..15b07c4 100644 --- a/data/entries/DSGAI18.json +++ b/data/entries/DSGAI18.json @@ -274,7 +274,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.1.1", "control_name": "Sensitive data identified", "tier": "Hardening", @@ -285,7 +285,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.1.1", "control_name": "Sensitive data not stored in cleartext", "tier": "Hardening", diff --git a/data/entries/DSGAI19.json b/data/entries/DSGAI19.json index 891f050..a4ca1b4 100644 --- a/data/entries/DSGAI19.json +++ b/data/entries/DSGAI19.json @@ -284,7 +284,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.2.1", "control_name": "Least privilege", "tier": "Foundational", @@ -295,7 +295,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.3.3", "control_name": "Consent for personal data processing", "tier": "Foundational", @@ -307,7 +307,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V6.2.1", "control_name": "Strong authentication", "tier": "Foundational", diff --git a/data/entries/DSGAI20.json b/data/entries/DSGAI20.json index 7174f86..6d5204a 100644 --- a/data/entries/DSGAI20.json +++ b/data/entries/DSGAI20.json @@ -294,7 +294,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.3.1", "control_name": "Access control per request", "tier": "Hardening", @@ -305,7 +305,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.1.4", "control_name": "Data minimisation in responses", "tier": "Hardening", @@ -317,7 +317,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V10.2.2", "control_name": "Component integrity checking", "tier": "Hardening", diff --git a/data/entries/DSGAI21.json b/data/entries/DSGAI21.json index 8822935..487061d 100644 --- a/data/entries/DSGAI21.json +++ b/data/entries/DSGAI21.json @@ -304,7 +304,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V2.2.1", "control_name": "Server-side input validation", "tier": "Hardening", @@ -315,7 +315,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V2.4.1", "control_name": "Enforce business logic limits", "tier": "Hardening", diff --git a/data/entries/LLM01.json b/data/entries/LLM01.json index d412e54..b0aec48 100644 --- a/data/entries/LLM01.json +++ b/data/entries/LLM01.json @@ -248,7 +248,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V15.3.7", "control_name": "Verify that the application has defenses against HTTP parameter pollution attacks, particularly if the application framework makes no distinction about the source of request parameters (query string, body parameters, cookies, or header fields).", "tier": "Foundational", @@ -259,7 +259,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V15.3.3", "control_name": "Verify that the application has countermeasures to protect against mass assignment attacks by limiting allowed fields per controller and action, e.g., it is not possible to insert or update a field value when it was not intended to be part of that action.", "tier": "Foundational", @@ -270,7 +270,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.1", "control_name": "Verify that all untrusted HTML input from WYSIWYG editors or similar is sanitized using a well-known and secure HTML sanitization library or framework feature.", "tier": "Foundational", @@ -281,7 +281,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.7", "control_name": "Verify that the application protects against template injection attacks by not allowing templates to be built based on untrusted input. Where there is no alternative, any untrusted input being included dynamically during template creation must be sanitized or strictly validated.", "tier": "Foundational", @@ -292,7 +292,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.1.2", "control_name": "Threat modelling of all data flows", "tier": "Foundational", @@ -303,7 +303,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V2.4.2", "control_name": "Verify that business logic flows require realistic human timing, preventing excessively rapid transaction submissions.", "tier": "Foundational", diff --git a/data/entries/LLM02.json b/data/entries/LLM02.json index 80618de..f77a884 100644 --- a/data/entries/LLM02.json +++ b/data/entries/LLM02.json @@ -258,7 +258,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.2.2", "control_name": "Verify that the application prevents sensitive data from being cached in server components, such as load balancers and application caches, or ensures that the data is securely purged after use.", "tier": "Foundational", @@ -269,7 +269,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.1.1", "control_name": "Verify that all sensitive data created and processed by the application has been identified and classified into protection levels. This includes data that is only encoded and therefore easily decoded, such as Base64 strings or the plaintext payload inside a JWT. Protection levels need to take into account any data protection and privacy regulations and standards which the application is required to comply with.", "tier": "Foundational", @@ -280,7 +280,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.2.1", "control_name": "Verify that the application ensures that function-level access is restricted to consumers with explicit permissions.", "tier": "Foundational", @@ -291,7 +291,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.1.1", "control_name": "Verify that all sensitive data created and processed by the application has been identified and classified into protection levels. This includes data that is only encoded and therefore easily decoded, such as Base64 strings or the plaintext payload inside a JWT. Protection levels need to take into account any data protection and privacy regulations and standards which the application is required to comply with.", "tier": "Foundational", @@ -302,7 +302,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V12.2.1", "control_name": "Verify that TLS is used for all connectivity between a client and external facing, HTTP-based services, and does not fall back to insecure or unencrypted communications.", "tier": "Foundational", diff --git a/data/entries/LLM03.json b/data/entries/LLM03.json index 289a7a1..f42e726 100644 --- a/data/entries/LLM03.json +++ b/data/entries/LLM03.json @@ -226,7 +226,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.2.1", "control_name": "Verify that the application ensures that function-level access is restricted to consumers with explicit permissions.", "tier": "Foundational", @@ -237,7 +237,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.3.1", "control_name": "Verify that the application enforces authorization rules at a trusted service layer and doesn't rely on controls that an untrusted consumer could manipulate, such as client-side JavaScript.", "tier": "Foundational", @@ -248,7 +248,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.3.2", "control_name": "Verify that failed authorization attempts are logged. For L3, this must include logging all authorization decisions, including logging when sensitive data is accessed (without logging the sensitive data itself).", "tier": "Foundational", @@ -259,7 +259,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V2.4.2", "control_name": "Verify that business logic flows require realistic human timing, preventing excessively rapid transaction submissions.", "tier": "Foundational", diff --git a/data/entries/LLM04.json b/data/entries/LLM04.json index 6a21666..23126ed 100644 --- a/data/entries/LLM04.json +++ b/data/entries/LLM04.json @@ -247,7 +247,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V10.2.1", "control_name": "Verify third-party components are current and free from vulnerabilities", "tier": "Foundational", @@ -258,7 +258,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V10.2.2", "control_name": "Verify only minimal approved external libraries are used", "tier": "Foundational", @@ -269,7 +269,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V13.4.5", "control_name": "Verify that documentation (such as for internal APIs) and monitoring endpoints are not exposed unless explicitly intended.", "tier": "Foundational", diff --git a/data/entries/LLM05.json b/data/entries/LLM05.json index f3e6993..1d90f3b 100644 --- a/data/entries/LLM05.json +++ b/data/entries/LLM05.json @@ -258,7 +258,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V15.3.7", "control_name": "Verify that the application has defenses against HTTP parameter pollution attacks, particularly if the application framework makes no distinction about the source of request parameters (query string, body parameters, cookies, or header fields).", "tier": "Hardening", @@ -269,7 +269,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V10.2.1", "control_name": "Verify third-party components free of vulnerabilities", "tier": "Hardening", @@ -280,7 +280,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V5.2.1", "control_name": "Verify that the application will only accept files of a size which it can process without causing a loss of performance or a denial of service attack.", "tier": "Hardening", diff --git a/data/entries/LLM06.json b/data/entries/LLM06.json index b969e7b..d4c6fe6 100644 --- a/data/entries/LLM06.json +++ b/data/entries/LLM06.json @@ -226,7 +226,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.5.3", "control_name": "Verify API rate limiting", "tier": "Foundational", @@ -237,7 +237,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.2.1", "control_name": "Verify that sensitive data is only sent to the server in the HTTP message body or header fields, and that the URL and query string do not contain sensitive information, such as an API key or session token.", "tier": "Foundational", @@ -248,7 +248,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V2.4.1", "control_name": "Verify that anti-automation controls are in place to protect against excessive calls to application functions that could lead to data exfiltration, garbage-data creation, quota exhaustion, rate-limit breaches, denial-of-service, or overuse of costly resources.", "tier": "Foundational", @@ -259,7 +259,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.5.1", "control_name": "Verify that a generic message is returned to the consumer when an unexpected or security-sensitive error occurs, ensuring no exposure of sensitive internal system data such as stack traces, queries, secret keys, and tokens.", "tier": "Foundational", diff --git a/data/entries/LLM07.json b/data/entries/LLM07.json index 570bbe7..e9889df 100644 --- a/data/entries/LLM07.json +++ b/data/entries/LLM07.json @@ -226,7 +226,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V2.3.1", "control_name": "Verify that the application will only process business logic flows for the same user in the expected sequential step order and without skipping steps.", "tier": "Foundational", @@ -237,7 +237,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.5.1", "control_name": "Verify that a generic message is returned to the consumer when an unexpected or security-sensitive error occurs, ensuring no exposure of sensitive internal system data such as stack traces, queries, secret keys, and tokens.", "tier": "Foundational", @@ -248,7 +248,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.1", "control_name": "Verify that all untrusted HTML input from WYSIWYG editors or similar is sanitized using a well-known and secure HTML sanitization library or framework feature.", "tier": "Foundational", diff --git a/data/entries/LLM08.json b/data/entries/LLM08.json index ac1e34c..16b17c4 100644 --- a/data/entries/LLM08.json +++ b/data/entries/LLM08.json @@ -226,7 +226,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.2.2", "control_name": "Verify that the application prevents sensitive data from being cached in server components, such as load balancers and application caches, or ensures that the data is securely purged after use.", "tier": "Foundational", @@ -237,7 +237,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.2.1", "control_name": "Verify that the application ensures that function-level access is restricted to consumers with explicit permissions.", "tier": "Foundational", @@ -248,7 +248,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.3.1", "control_name": "Verify that all authentication operations are logged, including successful and unsuccessful attempts. Additional metadata, such as the type of authentication or factors used, should also be collected.", "tier": "Foundational", @@ -259,7 +259,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V3.6.1", "control_name": "Verify that client-side assets, such as JavaScript libraries, CSS, or web fonts, are only hosted externally (e.g., on a Content Delivery Network) if the resource is static and versioned and Subresource Integrity (SRI) is used to validate the integrity of the asset. If this is not possible, there should be a documented security decision to justify this for each resource.", "tier": "Foundational", diff --git a/data/entries/LLM09.json b/data/entries/LLM09.json index 1ec21d4..3f4fc9c 100644 --- a/data/entries/LLM09.json +++ b/data/entries/LLM09.json @@ -226,7 +226,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.2.1", "control_name": "Verify that the application ensures that function-level access is restricted to consumers with explicit permissions.", "tier": "Hardening", @@ -237,7 +237,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.1.1", "control_name": "Verify that all sensitive data created and processed by the application has been identified and classified into protection levels. This includes data that is only encoded and therefore easily decoded, such as Base64 strings or the plaintext payload inside a JWT. Protection levels need to take into account any data protection and privacy regulations and standards which the application is required to comply with.", "tier": "Hardening", @@ -248,7 +248,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V5.2.1", "control_name": "Verify that the application will only accept files of a size which it can process without causing a loss of performance or a denial of service attack.", "tier": "Hardening", diff --git a/data/entries/LLM10.json b/data/entries/LLM10.json index f453e11..b35f9af 100644 --- a/data/entries/LLM10.json +++ b/data/entries/LLM10.json @@ -226,7 +226,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.1", "control_name": "Verify that all untrusted HTML input from WYSIWYG editors or similar is sanitized using a well-known and secure HTML sanitization library or framework feature.", "tier": "Foundational", @@ -237,7 +237,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.2.4", "control_name": "Verify that data selection or database queries (e.g., SQL, HQL, NoSQL, Cypher) use parameterized queries, ORMs, entity frameworks, or are otherwise protected from SQL Injection and other database injection attacks. This is also relevant when writing stored procedures.", "tier": "Foundational", @@ -248,7 +248,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.7", "control_name": "Verify that the application protects against template injection attacks by not allowing templates to be built based on untrusted input. Where there is no alternative, any untrusted input being included dynamically during template creation must be sanitized or strictly validated.", "tier": "Foundational", @@ -259,7 +259,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.2", "control_name": "Verify that the application avoids the use of eval() or other dynamic code execution features such as Spring Expression Language (SpEL). Where there is no alternative, any user input being included must be sanitized before being executed.", "tier": "Foundational", @@ -270,7 +270,7 @@ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V3.5.1", "control_name": "Verify that, if the application does not rely on the CORS preflight mechanism to prevent disallowed cross-origin requests to use sensitive functionality, these requests are validated to ensure they originate from the application itself. This may be done by using and validating anti-forgery tokens or requiring extra HTTP header fields that are not CORS-safelisted request-header fields. This is to defend against browser-based request forgery attacks, commonly known as cross-site request forgery (CSRF).", "tier": "Foundational", diff --git a/data/framework-sources.json b/data/framework-sources.json index 451a128..ec7d713 100644 --- a/data/framework-sources.json +++ b/data/framework-sources.json @@ -163,7 +163,7 @@ "notes": "Verified against the frozen OWASP/AISVS 1.0/en chapter files: 191 requirements, ids, text and levels identical to the registry. No tagged release upstream; 1.01-dev is in development and not yet released." }, "owasp-asvs": { - "name": "OWASP ASVS 4.0.3", + "name": "OWASP ASVS 5.0.0", "mapped_version": "5.0.0", "current_version": "5.0.0", "checked": "2026-09-18", diff --git a/data/frameworks/owasp-asvs.json b/data/frameworks/owasp-asvs.json index d5e0768..c74b6d6 100644 --- a/data/frameworks/owasp-asvs.json +++ b/data/frameworks/owasp-asvs.json @@ -1,6 +1,6 @@ { "id": "owasp-asvs", - "name": "OWASP ASVS 4.0.3", + "name": "OWASP ASVS 5.0.0", "short_name": "ASVS", "version": "5.0.0", "url": "https://owasp.org/projects/asvs", diff --git a/data/incidents.json b/data/incidents.json index 6024d3a..823b57f 100644 --- a/data/incidents.json +++ b/data/incidents.json @@ -8801,7 +8801,7 @@ ], "control_failures": [ { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.5", "outcome": "absent", "basis": "This advisory tracks remotely reachable arbitrary code execution caused by deserializing untrusted ZMQ RPC messages with `pickle.loads()`.", @@ -8881,7 +8881,7 @@ ], "control_failures": [ { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.5", "outcome": "absent", "basis": "LMDeploy's PyTorch DistServe/PD-disaggregation control plane used `recv_pyobj()` to deserialize messages received through a ZeroMQ PULL socket. PyZMQ implements `recv_pyobj()` using Python pickle deserialization, which can execute arbitrary code while reconstructing an object.", @@ -8967,7 +8967,7 @@ ], "control_failures": [ { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.2", "outcome": "absent", "basis": "When a user loads the model with lmdeploy, the `quant_dtype` is passed to `eval(f'torch.{quant_dtype}')` without any validation.", @@ -9341,7 +9341,7 @@ ], "control_failures": [ { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.2.4", "outcome": "absent", "basis": "The supplied `table_name` is incorporated into the generated SQL query without sufficient validation or safe identifier handling, allowing attacker-controlled SQL fragments to become part of the executed query.", @@ -9427,7 +9427,7 @@ ], "control_failures": [ { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.2.4", "outcome": "absent", "basis": "When the datasource is later deleted, this stored data is directly interpolated into SQL queries without parameterized query usage or proper escaping.", @@ -9521,7 +9521,7 @@ ], "control_failures": [ { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.6", "outcome": "absent", "basis": "`export_space` and `import_space` tools in `@contentful/mcp-tools` accept LLM-controlled `host` and `proxy` parameters that are spread directly into the options object passed to `contentful-export` / `contentful-import`.", diff --git a/docs/ai-standards-crosswalk/index.html b/docs/ai-standards-crosswalk/index.html index 14e7b30..a7b6300 100644 --- a/docs/ai-standards-crosswalk/index.html +++ b/docs/ai-standards-crosswalk/index.html @@ -74,7 +74,7 @@

26 frameworks crosswalked

NIST SP 800-82 Rev 3NISTOT/ICS OWASP AI Testing GuideOWASPTesting OWASP AISVS 1.0OWASPApplication security - OWASP ASVS 4.0.3OWASPApplication security + OWASP ASVS 5.0.0OWASPApplication security OWASP NHI Top 10OWASPIdentity OWASP SAMM v2.0OWASPApplication security PCI DSS v4.0PCI Security Standards CouncilInfosec diff --git a/docs/backlinks.js b/docs/backlinks.js index 926b15b..f8a8402 100644 --- a/docs/backlinks.js +++ b/docs/backlinks.js @@ -30529,7 +30529,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.1.2", "control_name": "Threat modelling of all data flows", "entries": [ @@ -30572,7 +30572,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.1.4", "control_name": "Trust boundaries documented and enforced", "entries": [ @@ -30588,7 +30588,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.2.4", "control_name": "Verify that data selection or database queries (e.g., SQL, HQL, NoSQL, Cypher) use parameterized queries, ORMs, entity frameworks, or are otherwise protected from SQL Injection and other database injection attacks. This is also relevant when writing stored procedures.", "entries": [ @@ -30622,7 +30622,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.1", "control_name": "Verify that all untrusted HTML input from WYSIWYG editors or similar is sanitized using a well-known and secure HTML sanitization library or framework feature.", "entries": [ @@ -30692,7 +30692,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.2", "control_name": "Verify that the application avoids the use of eval() or other dynamic code execution features such as Spring Expression Language (SpEL). Where there is no alternative, any user input being included must be sanitized before being executed.", "entries": [ @@ -30717,7 +30717,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.5", "control_name": "Output encoding for context", "entries": [ @@ -30733,7 +30733,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.6", "control_name": "Defined output structure", "entries": [ @@ -30749,7 +30749,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.7", "control_name": "Verify that the application protects against template injection attacks by not allowing templates to be built based on untrusted input. Where there is no alternative, any untrusted input being included dynamically during template creation must be sanitized or strictly validated.", "entries": [ @@ -30801,7 +30801,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.5.3", "control_name": "Verify API rate limiting", "entries": [ @@ -30853,7 +30853,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V10.2.1", "control_name": "Verify third-party components are current and free from vulnerabilities", "entries": [ @@ -30896,7 +30896,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V10.2.2", "control_name": "Verify only minimal approved external libraries are used", "entries": [ @@ -30939,7 +30939,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V11.1.7", "control_name": "Anti-automation controls", "entries": [ @@ -30955,7 +30955,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V12.2.1", "control_name": "Verify that TLS is used for all connectivity between a client and external facing, HTTP-based services, and does not fall back to insecure or unencrypted communications.", "entries": [ @@ -30989,7 +30989,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V13.1.2", "control_name": "API throttling", "entries": [ @@ -31005,7 +31005,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V13.2.1", "control_name": "Integration secrets not hardcoded", "entries": [ @@ -31021,7 +31021,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V13.4.5", "control_name": "Verify that documentation (such as for internal APIs) and monitoring endpoints are not exposed unless explicitly intended.", "entries": [ @@ -31046,7 +31046,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.1.1", "control_name": "Verify that all sensitive data created and processed by the application has been identified and classified into protection levels. This includes data that is only encoded and therefore easily decoded, such as Base64 strings or the plaintext payload inside a JWT. Protection levels need to take into account any data protection and privacy regulations and standards which the application is required to comply with.", "entries": [ @@ -31134,7 +31134,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.1.2", "control_name": "Data transferred using current TLS", "entries": [ @@ -31150,7 +31150,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.1.4", "control_name": "All components inventoried", "entries": [ @@ -31166,7 +31166,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.2.1", "control_name": "Verify that sensitive data is only sent to the server in the HTTP message body or header fields, and that the URL and query string do not contain sensitive information, such as an API key or session token.", "entries": [ @@ -31209,7 +31209,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.2.2", "control_name": "Verify that the application prevents sensitive data from being cached in server components, such as load balancers and application caches, or ensures that the data is securely purged after use.", "entries": [ @@ -31252,7 +31252,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V15.3.3", "control_name": "Verify that the application has countermeasures to protect against mass assignment attacks by limiting allowed fields per controller and action, e.g., it is not possible to insert or update a field value when it was not intended to be part of that action.", "entries": [ @@ -31268,7 +31268,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V15.3.7", "control_name": "Verify that the application has defenses against HTTP parameter pollution attacks, particularly if the application framework makes no distinction about the source of request parameters (query string, body parameters, cookies, or header fields).", "entries": [ @@ -31329,7 +31329,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.2.5", "control_name": "No credential logging", "entries": [ @@ -31345,7 +31345,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.3.1", "control_name": "Verify that all authentication operations are logged, including successful and unsuccessful attempts. Additional metadata, such as the type of authentication or factors used, should also be collected.", "entries": [ @@ -31388,7 +31388,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.3.2", "control_name": "Verify that failed authorization attempts are logged. For L3, this must include logging all authorization decisions, including logging when sensitive data is accessed (without logging the sensitive data itself).", "entries": [ @@ -31440,7 +31440,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.5.1", "control_name": "Verify that a generic message is returned to the consumer when an unexpected or security-sensitive error occurs, ensuring no exposure of sensitive internal system data such as stack traces, queries, secret keys, and tokens.", "entries": [ @@ -31492,7 +31492,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.5.3", "control_name": "Access control failures logged", "entries": [ @@ -31517,7 +31517,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V2.2.1", "control_name": "Input validation server-side", "entries": [ @@ -31551,7 +31551,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V2.3.1", "control_name": "Verify that the application will only process business logic flows for the same user in the expected sequential step order and without skipping steps.", "entries": [ @@ -31585,7 +31585,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V2.4.1", "control_name": "Verify that anti-automation controls are in place to protect against excessive calls to application functions that could lead to data exfiltration, garbage-data creation, quota exhaustion, rate-limit breaches, denial-of-service, or overuse of costly resources.", "entries": [ @@ -31619,7 +31619,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V2.4.2", "control_name": "Verify that business logic flows require realistic human timing, preventing excessively rapid transaction submissions.", "entries": [ @@ -31689,7 +31689,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V3.5.1", "control_name": "Verify that, if the application does not rely on the CORS preflight mechanism to prevent disallowed cross-origin requests to use sensitive functionality, these requests are validated to ensure they originate from the application itself. This may be done by using and validating anti-forgery tokens or requiring extra HTTP header fields that are not CORS-safelisted request-header fields. This is to defend against browser-based request forgery attacks, commonly known as cross-site request forgery (CSRF).", "entries": [ @@ -31705,7 +31705,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V3.6.1", "control_name": "Verify that client-side assets, such as JavaScript libraries, CSS, or web fonts, are only hosted externally (e.g., on a Content Delivery Network) if the resource is static and versioned and Subresource Integrity (SRI) is used to validate the integrity of the asset. If this is not possible, there should be a documented security decision to justify this for each resource.", "entries": [ @@ -31730,7 +31730,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V5.2.1", "control_name": "Verify that the application will only accept files of a size which it can process without causing a loss of performance or a denial of service attack.", "entries": [ @@ -31782,7 +31782,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V5.2.4", "control_name": "Malicious file detection on upload", "entries": [ @@ -31798,7 +31798,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V6.2.1", "control_name": "Verify that user set passwords are at least 8 characters in length although a minimum of 15 characters is strongly recommended.", "entries": [ @@ -31832,7 +31832,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V7.4.1", "control_name": "Verify that when session termination is triggered (such as logout or expiration), the application disallows any further use of the session. For reference tokens or stateful sessions, this means invalidating the session data at the application backend. Applications using self-contained tokens will need a solution such as maintaining a list of terminated tokens, disallowing tokens produced before a per-user date and time or rotating a per-user signing key.", "entries": [ @@ -31857,7 +31857,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.1.3", "control_name": "Sensitive data not in session storage", "entries": [ @@ -31873,7 +31873,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.1.4", "control_name": "Sensitive data minimisation", "entries": [ @@ -31916,7 +31916,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.2.1", "control_name": "Verify that the application ensures that function-level access is restricted to consumers with explicit permissions.", "entries": [ @@ -32049,7 +32049,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.3.1", "control_name": "Verify that the application enforces authorization rules at a trusted service layer and doesn't rely on controls that an untrusted consumer could manipulate, such as client-side JavaScript.", "entries": [ @@ -32119,7 +32119,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.3.10", "control_name": "Personal data not kept longer than needed", "entries": [ @@ -32135,7 +32135,7 @@ window.CROSSWALK_BACKLINKS = [ ] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.3.3", "control_name": "Consent obtained before PI processing", "entries": [ diff --git a/docs/data.js b/docs/data.js index e529169..29c4861 100644 --- a/docs/data.js +++ b/docs/data.js @@ -252,7 +252,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V15.3.7", "control_name": "Verify that the application has defenses against HTTP parameter pollution attacks, particularly if the application framework makes no distinction about the source of request parameters (query string, body parameters, cookies, or header fields).", "tier": "Foundational", @@ -263,7 +263,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V15.3.3", "control_name": "Verify that the application has countermeasures to protect against mass assignment attacks by limiting allowed fields per controller and action, e.g., it is not possible to insert or update a field value when it was not intended to be part of that action.", "tier": "Foundational", @@ -274,7 +274,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.1", "control_name": "Verify that all untrusted HTML input from WYSIWYG editors or similar is sanitized using a well-known and secure HTML sanitization library or framework feature.", "tier": "Foundational", @@ -285,7 +285,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.7", "control_name": "Verify that the application protects against template injection attacks by not allowing templates to be built based on untrusted input. Where there is no alternative, any untrusted input being included dynamically during template creation must be sanitized or strictly validated.", "tier": "Foundational", @@ -296,7 +296,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.1.2", "control_name": "Threat modelling of all data flows", "tier": "Foundational", @@ -307,7 +307,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V2.4.2", "control_name": "Verify that business logic flows require realistic human timing, preventing excessively rapid transaction submissions.", "tier": "Foundational", @@ -1736,7 +1736,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.2.2", "control_name": "Verify that the application prevents sensitive data from being cached in server components, such as load balancers and application caches, or ensures that the data is securely purged after use.", "tier": "Foundational", @@ -1747,7 +1747,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.1.1", "control_name": "Verify that all sensitive data created and processed by the application has been identified and classified into protection levels. This includes data that is only encoded and therefore easily decoded, such as Base64 strings or the plaintext payload inside a JWT. Protection levels need to take into account any data protection and privacy regulations and standards which the application is required to comply with.", "tier": "Foundational", @@ -1758,7 +1758,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.2.1", "control_name": "Verify that the application ensures that function-level access is restricted to consumers with explicit permissions.", "tier": "Foundational", @@ -1769,7 +1769,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.1.1", "control_name": "Verify that all sensitive data created and processed by the application has been identified and classified into protection levels. This includes data that is only encoded and therefore easily decoded, such as Base64 strings or the plaintext payload inside a JWT. Protection levels need to take into account any data protection and privacy regulations and standards which the application is required to comply with.", "tier": "Foundational", @@ -1780,7 +1780,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V12.2.1", "control_name": "Verify that TLS is used for all connectivity between a client and external facing, HTTP-based services, and does not fall back to insecure or unencrypted communications.", "tier": "Foundational", @@ -2917,7 +2917,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.2.1", "control_name": "Verify that the application ensures that function-level access is restricted to consumers with explicit permissions.", "tier": "Foundational", @@ -2928,7 +2928,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.3.1", "control_name": "Verify that the application enforces authorization rules at a trusted service layer and doesn't rely on controls that an untrusted consumer could manipulate, such as client-side JavaScript.", "tier": "Foundational", @@ -2939,7 +2939,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.3.2", "control_name": "Verify that failed authorization attempts are logged. For L3, this must include logging all authorization decisions, including logging when sensitive data is accessed (without logging the sensitive data itself).", "tier": "Foundational", @@ -2950,7 +2950,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V2.4.2", "control_name": "Verify that business logic flows require realistic human timing, preventing excessively rapid transaction submissions.", "tier": "Foundational", @@ -4191,7 +4191,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V10.2.1", "control_name": "Verify third-party components are current and free from vulnerabilities", "tier": "Foundational", @@ -4202,7 +4202,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V10.2.2", "control_name": "Verify only minimal approved external libraries are used", "tier": "Foundational", @@ -4213,7 +4213,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V13.4.5", "control_name": "Verify that documentation (such as for internal APIs) and monitoring endpoints are not exposed unless explicitly intended.", "tier": "Foundational", @@ -5425,7 +5425,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V15.3.7", "control_name": "Verify that the application has defenses against HTTP parameter pollution attacks, particularly if the application framework makes no distinction about the source of request parameters (query string, body parameters, cookies, or header fields).", "tier": "Hardening", @@ -5436,7 +5436,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V10.2.1", "control_name": "Verify third-party components free of vulnerabilities", "tier": "Hardening", @@ -5447,7 +5447,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V5.2.1", "control_name": "Verify that the application will only accept files of a size which it can process without causing a loss of performance or a denial of service attack.", "tier": "Hardening", @@ -6572,7 +6572,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.5.3", "control_name": "Verify API rate limiting", "tier": "Foundational", @@ -6583,7 +6583,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.2.1", "control_name": "Verify that sensitive data is only sent to the server in the HTTP message body or header fields, and that the URL and query string do not contain sensitive information, such as an API key or session token.", "tier": "Foundational", @@ -6594,7 +6594,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V2.4.1", "control_name": "Verify that anti-automation controls are in place to protect against excessive calls to application functions that could lead to data exfiltration, garbage-data creation, quota exhaustion, rate-limit breaches, denial-of-service, or overuse of costly resources.", "tier": "Foundational", @@ -6605,7 +6605,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.5.1", "control_name": "Verify that a generic message is returned to the consumer when an unexpected or security-sensitive error occurs, ensuring no exposure of sensitive internal system data such as stack traces, queries, secret keys, and tokens.", "tier": "Foundational", @@ -7661,7 +7661,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V2.3.1", "control_name": "Verify that the application will only process business logic flows for the same user in the expected sequential step order and without skipping steps.", "tier": "Foundational", @@ -7672,7 +7672,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.5.1", "control_name": "Verify that a generic message is returned to the consumer when an unexpected or security-sensitive error occurs, ensuring no exposure of sensitive internal system data such as stack traces, queries, secret keys, and tokens.", "tier": "Foundational", @@ -7683,7 +7683,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.1", "control_name": "Verify that all untrusted HTML input from WYSIWYG editors or similar is sanitized using a well-known and secure HTML sanitization library or framework feature.", "tier": "Foundational", @@ -8845,7 +8845,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.2.2", "control_name": "Verify that the application prevents sensitive data from being cached in server components, such as load balancers and application caches, or ensures that the data is securely purged after use.", "tier": "Foundational", @@ -8856,7 +8856,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.2.1", "control_name": "Verify that the application ensures that function-level access is restricted to consumers with explicit permissions.", "tier": "Foundational", @@ -8867,7 +8867,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.3.1", "control_name": "Verify that all authentication operations are logged, including successful and unsuccessful attempts. Additional metadata, such as the type of authentication or factors used, should also be collected.", "tier": "Foundational", @@ -8878,7 +8878,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V3.6.1", "control_name": "Verify that client-side assets, such as JavaScript libraries, CSS, or web fonts, are only hosted externally (e.g., on a Content Delivery Network) if the resource is static and versioned and Subresource Integrity (SRI) is used to validate the integrity of the asset. If this is not possible, there should be a documented security decision to justify this for each resource.", "tier": "Foundational", @@ -9910,7 +9910,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.2.1", "control_name": "Verify that the application ensures that function-level access is restricted to consumers with explicit permissions.", "tier": "Hardening", @@ -9921,7 +9921,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.1.1", "control_name": "Verify that all sensitive data created and processed by the application has been identified and classified into protection levels. This includes data that is only encoded and therefore easily decoded, such as Base64 strings or the plaintext payload inside a JWT. Protection levels need to take into account any data protection and privacy regulations and standards which the application is required to comply with.", "tier": "Hardening", @@ -9932,7 +9932,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V5.2.1", "control_name": "Verify that the application will only accept files of a size which it can process without causing a loss of performance or a denial of service attack.", "tier": "Hardening", @@ -10988,7 +10988,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.1", "control_name": "Verify that all untrusted HTML input from WYSIWYG editors or similar is sanitized using a well-known and secure HTML sanitization library or framework feature.", "tier": "Foundational", @@ -10999,7 +10999,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.2.4", "control_name": "Verify that data selection or database queries (e.g., SQL, HQL, NoSQL, Cypher) use parameterized queries, ORMs, entity frameworks, or are otherwise protected from SQL Injection and other database injection attacks. This is also relevant when writing stored procedures.", "tier": "Foundational", @@ -11010,7 +11010,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.7", "control_name": "Verify that the application protects against template injection attacks by not allowing templates to be built based on untrusted input. Where there is no alternative, any untrusted input being included dynamically during template creation must be sanitized or strictly validated.", "tier": "Foundational", @@ -11021,7 +11021,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.2", "control_name": "Verify that the application avoids the use of eval() or other dynamic code execution features such as Spring Expression Language (SpEL). Where there is no alternative, any user input being included must be sanitized before being executed.", "tier": "Foundational", @@ -11032,7 +11032,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V3.5.1", "control_name": "Verify that, if the application does not rely on the CORS preflight mechanism to prevent disallowed cross-origin requests to use sensitive functionality, these requests are validated to ensure they originate from the application itself. This may be done by using and validating anti-forgery tokens or requiring extra HTTP header fields that are not CORS-safelisted request-header fields. This is to defend against browser-based request forgery attacks, commonly known as cross-site request forgery (CSRF).", "tier": "Foundational", @@ -13229,7 +13229,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V15.3.7", "control_name": "Verify that the application has defenses against HTTP parameter pollution attacks, particularly if the application framework makes no distinction about the source of request parameters (query string, body parameters, cookies, or header fields).", "tier": "Foundational", @@ -13240,7 +13240,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.1", "control_name": "Verify that all untrusted HTML input from WYSIWYG editors or similar is sanitized using a well-known and secure HTML sanitization library or framework feature.", "tier": "Foundational", @@ -13251,7 +13251,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.7", "control_name": "Verify that the application protects against template injection attacks by not allowing templates to be built based on untrusted input. Where there is no alternative, any untrusted input being included dynamically during template creation must be sanitized or strictly validated.", "tier": "Foundational", @@ -13262,7 +13262,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.1.2", "control_name": "Threat modelling of all data flows", "tier": "Foundational", @@ -13273,7 +13273,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V2.4.2", "control_name": "Verify that business logic flows require realistic human timing, preventing excessively rapid transaction submissions.", "tier": "Foundational", @@ -14598,7 +14598,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.2.1", "control_name": "Verify that the application ensures that function-level access is restricted to consumers with explicit permissions.", "tier": "Foundational", @@ -14609,7 +14609,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.3.1", "control_name": "Verify that the application enforces authorization rules at a trusted service layer and doesn't rely on controls that an untrusted consumer could manipulate, such as client-side JavaScript.", "tier": "Foundational", @@ -14620,7 +14620,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.3.2", "control_name": "Verify that failed authorization attempts are logged. For L3, this must include logging all authorization decisions, including logging when sensitive data is accessed (without logging the sensitive data itself).", "tier": "Foundational", @@ -14631,7 +14631,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V2.4.2", "control_name": "Verify that business logic flows require realistic human timing, preventing excessively rapid transaction submissions.", "tier": "Foundational", @@ -14642,7 +14642,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.5.3", "control_name": "Verify API rate limiting", "tier": "Foundational", @@ -15902,7 +15902,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V6.2.1", "control_name": "Verify that user set passwords are at least 8 characters in length although a minimum of 15 characters is strongly recommended.", "tier": "Foundational", @@ -15913,7 +15913,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.2.1", "control_name": "Verify that the application ensures that function-level access is restricted to consumers with explicit permissions.", "tier": "Foundational", @@ -15924,7 +15924,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.1.1", "control_name": "Verify that all sensitive data created and processed by the application has been identified and classified into protection levels. This includes data that is only encoded and therefore easily decoded, such as Base64 strings or the plaintext payload inside a JWT. Protection levels need to take into account any data protection and privacy regulations and standards which the application is required to comply with.", "tier": "Foundational", @@ -15935,7 +15935,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.3.1", "control_name": "Verify that all authentication operations are logged, including successful and unsuccessful attempts. Additional metadata, such as the type of authentication or factors used, should also be collected.", "tier": "Foundational", @@ -15946,7 +15946,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V3.6.1", "control_name": "Verify that client-side assets, such as JavaScript libraries, CSS, or web fonts, are only hosted externally (e.g., on a Content Delivery Network) if the resource is static and versioned and Subresource Integrity (SRI) is used to validate the integrity of the asset. If this is not possible, there should be a documented security decision to justify this for each resource.", "tier": "Foundational", @@ -17269,7 +17269,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V10.2.1", "control_name": "Verify third-party components current and free of vulnerabilities", "tier": "Foundational", @@ -17280,7 +17280,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V10.2.2", "control_name": "Verify only minimal approved external libraries", "tier": "Foundational", @@ -17291,7 +17291,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V13.4.5", "control_name": "Verify that documentation (such as for internal APIs) and monitoring endpoints are not exposed unless explicitly intended.", "tier": "Foundational", @@ -17302,7 +17302,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.1.2", "control_name": "Verify threat model covers all data flows", "tier": "Foundational", @@ -18466,7 +18466,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.1", "control_name": "Verify that all untrusted HTML input from WYSIWYG editors or similar is sanitized using a well-known and secure HTML sanitization library or framework feature.", "tier": "Hardening", @@ -18477,7 +18477,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.2", "control_name": "Verify that the application avoids the use of eval() or other dynamic code execution features such as Spring Expression Language (SpEL). Where there is no alternative, any user input being included must be sanitized before being executed.", "tier": "Hardening", @@ -18488,7 +18488,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.7", "control_name": "Verify that the application protects against template injection attacks by not allowing templates to be built based on untrusted input. Where there is no alternative, any untrusted input being included dynamically during template creation must be sanitized or strictly validated.", "tier": "Hardening", @@ -18499,7 +18499,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.2.4", "control_name": "Verify that data selection or database queries (e.g., SQL, HQL, NoSQL, Cypher) use parameterized queries, ORMs, entity frameworks, or are otherwise protected from SQL Injection and other database injection attacks. This is also relevant when writing stored procedures.", "tier": "Hardening", @@ -18510,7 +18510,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V2.4.2", "control_name": "Verify that business logic flows require realistic human timing, preventing excessively rapid transaction submissions.", "tier": "Hardening", @@ -19669,7 +19669,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V15.3.7", "control_name": "Verify that the application has defenses against HTTP parameter pollution attacks, particularly if the application framework makes no distinction about the source of request parameters (query string, body parameters, cookies, or header fields).", "tier": "Hardening", @@ -19680,7 +19680,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.2.1", "control_name": "Verify that the application ensures that function-level access is restricted to consumers with explicit permissions.", "tier": "Hardening", @@ -19691,7 +19691,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.1.1", "control_name": "Verify that all sensitive data created and processed by the application has been identified and classified into protection levels. This includes data that is only encoded and therefore easily decoded, such as Base64 strings or the plaintext payload inside a JWT. Protection levels need to take into account any data protection and privacy regulations and standards which the application is required to comply with.", "tier": "Hardening", @@ -19702,7 +19702,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V5.2.1", "control_name": "Verify that the application will only accept files of a size which it can process without causing a loss of performance or a denial of service attack.", "tier": "Hardening", @@ -20850,7 +20850,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V12.2.1", "control_name": "Verify that TLS is used for all connectivity between a client and external facing, HTTP-based services, and does not fall back to insecure or unencrypted communications.", "tier": "Hardening", @@ -20861,7 +20861,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V7.4.1", "control_name": "Verify that when session termination is triggered (such as logout or expiration), the application disallows any further use of the session. For reference tokens or stateful sessions, this means invalidating the session data at the application backend. Applications using self-contained tokens will need a solution such as maintaining a list of terminated tokens, disallowing tokens produced before a per-user date and time or rotating a per-user signing key.", "tier": "Hardening", @@ -20872,7 +20872,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.2.1", "control_name": "Verify that the application ensures that function-level access is restricted to consumers with explicit permissions.", "tier": "Hardening", @@ -20883,7 +20883,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.3.1", "control_name": "Verify that all authentication operations are logged, including successful and unsuccessful attempts. Additional metadata, such as the type of authentication or factors used, should also be collected.", "tier": "Hardening", @@ -21991,7 +21991,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V2.3.1", "control_name": "Verify that the application will only process business logic flows for the same user in the expected sequential step order and without skipping steps.", "tier": "Foundational", @@ -22002,7 +22002,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V2.4.2", "control_name": "Verify that business logic flows require realistic human timing, preventing excessively rapid transaction submissions.", "tier": "Foundational", @@ -22013,7 +22013,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.5.3", "control_name": "Verify API rate limiting", "tier": "Foundational", @@ -22024,7 +22024,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.5.1", "control_name": "Verify that a generic message is returned to the consumer when an unexpected or security-sensitive error occurs, ensuring no exposure of sensitive internal system data such as stack traces, queries, secret keys, and tokens.", "tier": "Foundational", @@ -23125,7 +23125,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V2.3.1", "control_name": "Verify that the application will only process business logic flows for the same user in the expected sequential step order and without skipping steps.", "tier": "Foundational", @@ -23136,7 +23136,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.1", "control_name": "Verify that all untrusted HTML input from WYSIWYG editors or similar is sanitized using a well-known and secure HTML sanitization library or framework feature.", "tier": "Foundational", @@ -23147,7 +23147,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.5.1", "control_name": "Verify that a generic message is returned to the consumer when an unexpected or security-sensitive error occurs, ensuring no exposure of sensitive internal system data such as stack traces, queries, secret keys, and tokens.", "tier": "Foundational", @@ -23158,7 +23158,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.2.1", "control_name": "Verify that sensitive data is only sent to the server in the HTTP message body or header fields, and that the URL and query string do not contain sensitive information, such as an API key or session token.", "tier": "Foundational", @@ -24288,7 +24288,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.3.1", "control_name": "Verify that all authentication operations are logged, including successful and unsuccessful attempts. Additional metadata, such as the type of authentication or factors used, should also be collected.", "tier": "Hardening", @@ -24299,7 +24299,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.3.2", "control_name": "Verify that failed authorization attempts are logged. For L3, this must include logging all authorization decisions, including logging when sensitive data is accessed (without logging the sensitive data itself).", "tier": "Hardening", @@ -24310,7 +24310,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V2.4.2", "control_name": "Verify that business logic flows require realistic human timing, preventing excessively rapid transaction submissions.", "tier": "Hardening", @@ -24321,7 +24321,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.5.3", "control_name": "Verify API rate limiting", "tier": "Hardening", @@ -25541,7 +25541,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.2.2", "control_name": "Sensitive data not transmitted in URL parameters", "tier": "Foundational", @@ -25552,7 +25552,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.1.1", "control_name": "Sensitive data identified and classified", "tier": "Foundational", @@ -25563,7 +25563,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.2.1", "control_name": "Deny by default access control", "tier": "Foundational", @@ -25574,7 +25574,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.5", "control_name": "Output encoding for context", "tier": "Foundational", @@ -25585,7 +25585,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.1.1", "control_name": "Sensitive data not stored in cleartext", "tier": "Foundational", @@ -26785,7 +26785,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V6.2.1", "control_name": "Passwords minimum 12 characters", "tier": "Foundational", @@ -26796,7 +26796,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V13.2.1", "control_name": "Integration secrets not hardcoded", "tier": "Foundational", @@ -26807,7 +26807,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.2.1", "control_name": "Least privilege for service accounts", "tier": "Foundational", @@ -26818,7 +26818,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.1.2", "control_name": "Data transferred using current TLS", "tier": "Foundational", @@ -27878,7 +27878,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.1.4", "control_name": "Trust boundaries documented and enforced", "tier": "Foundational", @@ -27890,7 +27890,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.5.3", "control_name": "Access control failures logged", "tier": "Foundational", @@ -27901,7 +27901,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.3.2", "control_name": "Log entries contain required information", "tier": "Foundational", @@ -27912,7 +27912,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.1.4", "control_name": "All components inventoried", "tier": "Foundational", @@ -28867,7 +28867,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V2.2.1", "control_name": "Input validation server-side", "tier": "Hardening", @@ -28878,7 +28878,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V10.2.1", "control_name": "Application only uses official repositories", "tier": "Hardening", @@ -28890,7 +28890,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V10.2.2", "control_name": "Dependency managers check for vulnerabilities", "tier": "Hardening", @@ -28902,7 +28902,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V5.2.1", "control_name": "File upload size limits", "tier": "Hardening", @@ -29966,7 +29966,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V15.3.7", "control_name": "Input validation using allowlists", "tier": "Foundational", @@ -29977,7 +29977,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.1", "control_name": "HTML/JS output sanitised", "tier": "Foundational", @@ -29988,7 +29988,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.5.1", "control_name": "Generic error messages", "tier": "Foundational", @@ -31024,7 +31024,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.3.1", "control_name": "Access control on every request", "tier": "Foundational", @@ -31035,7 +31035,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V12.2.1", "control_name": "TLS for all connections", "tier": "Foundational", @@ -31046,7 +31046,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V2.4.1", "control_name": "Business logic limits on repeated actions", "tier": "Foundational", @@ -32018,7 +32018,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.1.4", "control_name": "Sensitive data minimisation", "tier": "Foundational", @@ -32030,7 +32030,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.1.1", "control_name": "Sensitive data identified and classified", "tier": "Foundational", @@ -32041,7 +32041,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.5.3", "control_name": "Attribute-based access control", "tier": "Foundational", @@ -32997,7 +32997,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.3.3", "control_name": "Consent obtained before PI processing", "tier": "Foundational", @@ -33009,7 +33009,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.3.10", "control_name": "Personal data not kept longer than needed", "tier": "Foundational", @@ -33021,7 +33021,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.3.2", "control_name": "Audit trail sufficient for compliance", "tier": "Foundational", @@ -34084,7 +34084,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.7", "control_name": "Unstructured data sanitised", "tier": "Hardening", @@ -34095,7 +34095,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.1.4", "control_name": "Sensitive data minimised", "tier": "Hardening", @@ -34107,7 +34107,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V5.2.4", "control_name": "Malicious file detection on upload", "tier": "Hardening", @@ -35056,7 +35056,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.1.1", "control_name": "Sensitive data classified", "tier": "Hardening", @@ -35067,7 +35067,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.6", "control_name": "Defined output structure", "tier": "Hardening", @@ -35979,7 +35979,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.2.1", "control_name": "Session tokens unique and random", "tier": "Foundational", @@ -35990,7 +35990,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V7.4.1", "control_name": "Sessions invalidated after logout", "tier": "Foundational", @@ -36001,7 +36001,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.3.1", "control_name": "Access control enforced on every request", "tier": "Foundational", @@ -36012,7 +36012,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.1.3", "control_name": "Sensitive data not in session storage", "tier": "Foundational", @@ -36963,7 +36963,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V15.3.7", "control_name": "Allowlist input validation", "tier": "Foundational", @@ -36974,7 +36974,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.2.4", "control_name": "SQL injection prevention", "tier": "Foundational", @@ -36993,7 +36993,7 @@ window.CROSSWALK_DATA = [ } }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.3.1", "control_name": "Access control on every request", "tier": "Foundational", @@ -37004,7 +37004,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.5.3", "control_name": "API protection against enumeration", "tier": "Foundational", @@ -37994,7 +37994,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.2.1", "control_name": "Deny by default", "tier": "Foundational", @@ -38005,7 +38005,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.1.1", "control_name": "Sensitive data not stored in cleartext", "tier": "Foundational", @@ -38016,7 +38016,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V5.2.1", "control_name": "File upload validation", "tier": "Foundational", @@ -39019,7 +39019,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.2.5", "control_name": "No credential logging", "tier": "Foundational", @@ -39030,7 +39030,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V16.2.5", "control_name": "No sensitive data in logs", "tier": "Foundational", @@ -39041,7 +39041,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.2.2", "control_name": "Sensitive data not in URLs", "tier": "Foundational", @@ -39052,7 +39052,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.3.1", "control_name": "Access control on log stores", "tier": "Foundational", @@ -40043,7 +40043,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.2.1", "control_name": "Deny by default access control", "tier": "Foundational", @@ -40054,7 +40054,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.1.4", "control_name": "Data minimisation", "tier": "Foundational", @@ -40066,7 +40066,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.2.1", "control_name": "Session isolation", "tier": "Foundational", @@ -41012,7 +41012,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.2.1", "control_name": "Least privilege", "tier": "Foundational", @@ -41023,7 +41023,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V2.2.1", "control_name": "Business logic prevents excess data access", "tier": "Foundational", @@ -41034,7 +41034,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.1.2", "control_name": "Secure architecture and design", "tier": "Foundational", @@ -42025,7 +42025,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V11.1.7", "control_name": "Anti-automation controls", "tier": "Foundational", @@ -42037,7 +42037,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V13.1.2", "control_name": "API throttling", "tier": "Foundational", @@ -43057,7 +43057,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.1.1", "control_name": "Sensitive data identified", "tier": "Hardening", @@ -43068,7 +43068,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V14.1.1", "control_name": "Sensitive data not stored in cleartext", "tier": "Hardening", @@ -43962,7 +43962,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.2.1", "control_name": "Least privilege", "tier": "Foundational", @@ -43973,7 +43973,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.3.3", "control_name": "Consent for personal data processing", "tier": "Foundational", @@ -43985,7 +43985,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V6.2.1", "control_name": "Strong authentication", "tier": "Foundational", @@ -44926,7 +44926,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.3.1", "control_name": "Access control per request", "tier": "Hardening", @@ -44937,7 +44937,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V8.1.4", "control_name": "Data minimisation in responses", "tier": "Hardening", @@ -44949,7 +44949,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V10.2.2", "control_name": "Component integrity checking", "tier": "Hardening", @@ -45935,7 +45935,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V2.2.1", "control_name": "Server-side input validation", "tier": "Hardening", @@ -45946,7 +45946,7 @@ window.CROSSWALK_DATA = [ "reviewed_by": [] }, { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V2.4.1", "control_name": "Enforce business logic limits", "tier": "Hardening", diff --git a/docs/frameworks-registry.js b/docs/frameworks-registry.js index bd6dfd4..d3435e4 100644 --- a/docs/frameworks-registry.js +++ b/docs/frameworks-registry.js @@ -7732,7 +7732,7 @@ window.CROSSWALK_FRAMEWORKS = [ }, { "id": "owasp-asvs", - "name": "OWASP ASVS 4.0.3", + "name": "OWASP ASVS 5.0.0", "short_name": "ASVS", "version": "5.0.0", "url": "https://owasp.org/projects/asvs", diff --git a/docs/incidents.js b/docs/incidents.js index a277b09..2f070ee 100644 --- a/docs/incidents.js +++ b/docs/incidents.js @@ -8799,7 +8799,7 @@ window.CROSSWALK_INCIDENTS = [ ], "control_failures": [ { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.5", "outcome": "absent", "basis": "This advisory tracks remotely reachable arbitrary code execution caused by deserializing untrusted ZMQ RPC messages with `pickle.loads()`.", @@ -8879,7 +8879,7 @@ window.CROSSWALK_INCIDENTS = [ ], "control_failures": [ { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.5", "outcome": "absent", "basis": "LMDeploy's PyTorch DistServe/PD-disaggregation control plane used `recv_pyobj()` to deserialize messages received through a ZeroMQ PULL socket. PyZMQ implements `recv_pyobj()` using Python pickle deserialization, which can execute arbitrary code while reconstructing an object.", @@ -8965,7 +8965,7 @@ window.CROSSWALK_INCIDENTS = [ ], "control_failures": [ { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.2", "outcome": "absent", "basis": "When a user loads the model with lmdeploy, the `quant_dtype` is passed to `eval(f'torch.{quant_dtype}')` without any validation.", @@ -9339,7 +9339,7 @@ window.CROSSWALK_INCIDENTS = [ ], "control_failures": [ { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.2.4", "outcome": "absent", "basis": "The supplied `table_name` is incorporated into the generated SQL query without sufficient validation or safe identifier handling, allowing attacker-controlled SQL fragments to become part of the executed query.", @@ -9425,7 +9425,7 @@ window.CROSSWALK_INCIDENTS = [ ], "control_failures": [ { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.2.4", "outcome": "absent", "basis": "When the datasource is later deleted, this stored data is directly interpolated into SQL queries without parameterized query usage or proper escaping.", @@ -9519,7 +9519,7 @@ window.CROSSWALK_INCIDENTS = [ ], "control_failures": [ { - "framework": "OWASP ASVS 4.0.3", + "framework": "OWASP ASVS 5.0.0", "control_id": "V1.3.6", "outcome": "absent", "basis": "`export_space` and `import_space` tools in `@contentful/mcp-tools` accept LLM-controlled `host` and `proxy` parameters that are spread directly into the options object passed to `contentful-export` / `contentful-import`.", diff --git a/docs/llms.txt b/docs/llms.txt index 270375f..3a47574 100644 --- a/docs/llms.txt +++ b/docs/llms.txt @@ -27,7 +27,7 @@ LLM01 Prompt Injection · LLM02 Sensitive Information Disclosure · LLM04 Supply ## Frameworks crosswalked (26) -AIUC-1, CIS Controls v8.1, CoSAI, CWE/CVE, DORA, ENISA Multilayer Framework, EU AI Act, EU AI Act Code of Practice, FedRAMP, ISA/IEC 62443, ISO/IEC 27001:2022, ISO/IEC 42001:2023, MAESTRO, MITRE ATLAS, NIST AI RMF 1.0, NIST CSF 2.0, NIST SP 800-218A, NIST SP 800-82 Rev 3, OWASP AI Testing Guide, OWASP AISVS 1.0, OWASP ASVS 4.0.3, OWASP NHI Top 10, OWASP SAMM v2.0, PCI DSS v4.0, SOC 2, STRIDE +AIUC-1, CIS Controls v8.1, CoSAI, CWE/CVE, DORA, ENISA Multilayer Framework, EU AI Act, EU AI Act Code of Practice, FedRAMP, ISA/IEC 62443, ISO/IEC 27001:2022, ISO/IEC 42001:2023, MAESTRO, MITRE ATLAS, NIST AI RMF 1.0, NIST CSF 2.0, NIST SP 800-218A, NIST SP 800-82 Rev 3, OWASP AI Testing Guide, OWASP AISVS 1.0, OWASP ASVS 5.0.0, OWASP NHI Top 10, OWASP SAMM v2.0, PCI DSS v4.0, SOC 2, STRIDE ## License diff --git a/dsgai-2026/DSGAI_ASVS.md b/dsgai-2026/DSGAI_ASVS.md index a5df46e..2a65dfe 100644 --- a/dsgai-2026/DSGAI_ASVS.md +++ b/dsgai-2026/DSGAI_ASVS.md @@ -7,14 +7,14 @@ License : CC BY-SA 4.0 --> -# DSGAI 2026 × OWASP ASVS 4.0.3 +# DSGAI 2026 × OWASP ASVS 5.0.0 Mapping the [OWASP GenAI Data Security Risks & Mitigations 2026](https://genai.owasp.org/resource/owasp-genai-data-security-risks-mitigations-2026/) (DSGAI01–DSGAI21) to the -[OWASP Application Security Verification Standard (ASVS) 4.0.3](https://owasp.org/projects/asvs) +[OWASP Application Security Verification Standard (ASVS) 5.0.0](https://owasp.org/projects/asvs) — the framework for verifying the security of web applications and APIs, organised -into 14 chapters with three verification levels (L1/L2/L3). +into 17 chapters with three verification levels (L1/L2/L3). DSGAI risks emerge at the data layer — training pipelines, RAG stores, vector databases, context windows, and multimodal input channels. All of these are @@ -1184,7 +1184,7 @@ targeting specific topics, entities, or user segments with malicious intent. ## References -- [OWASP ASVS 4.0.3](https://owasp.org/projects/asvs) +- [OWASP ASVS 5.0.0](https://owasp.org/projects/asvs) - [OWASP GenAI Data Security Risks 2026](https://genai.owasp.org/resource/owasp-genai-data-security-risks-mitigations-2026/) - [OWASP AIVSS](https://aivss.owasp.org) diff --git a/i18n/de/README.md b/i18n/de/README.md index a864222..8fbfe09 100644 --- a/i18n/de/README.md +++ b/i18n/de/README.md @@ -67,7 +67,7 @@ Alles kostenlos. Alles Open Source. Entwickelt fuer Praktiker. | [MAESTRO — CSA](https://cloudsecurityalliance.org/blog/2025/02/06/agentic-ai-threat-modeling-framework-maestro) | ✅ | ✅ | ✅ | | [ISO/IEC 42001:2023](https://www.iso.org/standard/81230.html) | ✅ | ✅ | ✅ | | [CIS Controls v8.1](https://www.cisecurity.org/controls) | ✅ | ✅ | ✅ | -| [OWASP ASVS 4.0.3](https://owasp.org/projects/asvs) | ✅ | ✅ | ✅ | +| [OWASP ASVS 5.0.0](https://owasp.org/projects/asvs) | ✅ | ✅ | ✅ | | [SOC 2 Trust Services Criteria](https://www.aicpa-cima.com/resources/landing/2017-trust-services-criteria) | ✅ | ✅ | ✅ | | [PCI DSS v4.0](https://www.pcisecuritystandards.org/document_library/) | ✅ | ✅ | ✅ | | [ENISA Multilayer Framework](https://www.enisa.europa.eu/publications/multilayer-framework-for-good-cybersecurity-practices-for-ai) | ✅ | ✅ | ✅ | @@ -90,7 +90,7 @@ Alles kostenlos. Alles Open Source. Entwickelt fuer Praktiker. | [LLM_ISO27001.md](../../llm-top10/LLM_ISO27001.md) | ISO/IEC 27001:2022 | ISMS-Erweiterungscheckliste, neue Kontrollen 2022 zugeordnet zu LLM-Risiken | | [LLM_ISO42001.md](../../llm-top10/LLM_ISO42001.md) | ISO/IEC 42001:2023 | AIMS-Implementierungscheckliste, ISO 27001-Integrationsleitfaden | | [LLM_CISControls.md](../../llm-top10/LLM_CISControls.md) | CIS Controls v8.1 | IG1/IG2/IG3-gestufte Schutzmassnahmen pro Schwachstelle | -| [LLM_ASVS.md](../../llm-top10/LLM_ASVS.md) | OWASP ASVS 4.0.3 | L1/L2/L3-Verifizierungsanforderungen mit ASVS-Checkliste | +| [LLM_ASVS.md](../../llm-top10/LLM_ASVS.md) | OWASP ASVS 5.0.0 | L1/L2/L3-Verifizierungsanforderungen mit ASVS-Checkliste | | [LLM_ISA62443.md](../../llm-top10/LLM_ISA62443.md) | ISA/IEC 62443 — OT/ICS | Zonenmodell, SL-Bewertungen, FR/SR-Referenzen, OT-Bereitstellungscheckliste | | [LLM_NISTSP80082.md](../../llm-top10/LLM_NISTSP80082.md) | NIST SP 800-82 Rev 3 | SP 800-53-Kontrollen, regulatorischer US-Crosswalk (NERC CIP, AWIA, CMMC) | | [LLM_NISTCSF2.md](../../llm-top10/LLM_NISTCSF2.md) | NIST CSF 2.0 | Sechs-Funktionen-Zuordnung einschliesslich der neuen GOVERN-Funktion, CSF 2.0-Profil | @@ -120,7 +120,7 @@ Alles kostenlos. Alles Open Source. Entwickelt fuer Praktiker. | [Agentic_MAESTRO.md](../../agentic-top10/Agentic_MAESTRO.md) | MAESTRO — CSA | Sieben-Schichten-Architektur-Bedrohungsmodell, Schicht-zu-ASI-Zuordnung, Sitzungsleitfaden | | [Agentic_OWASP_NHI.md](../../agentic-top10/Agentic_OWASP_NHI.md) | OWASP NHI Top 10 | Vollstaendige NHI-zu-ASI-Kreuzzuordnung, NHI-Programmreifetabelle | | [Agentic_CISControls.md](../../agentic-top10/Agentic_CISControls.md) | CIS Controls v8.1 | IG1/IG2/IG3-Schutzmassnahmen, agentische NHI als CIS 5 privilegierter Zugang behandelt | -| [Agentic_ASVS.md](../../agentic-top10/Agentic_ASVS.md) | OWASP ASVS 4.0.3 | L1/L2/L3-Verifizierungscheckliste fuer agentische Bereitstellungen | +| [Agentic_ASVS.md](../../agentic-top10/Agentic_ASVS.md) | OWASP ASVS 5.0.0 | L1/L2/L3-Verifizierungscheckliste fuer agentische Bereitstellungen | | [Agentic_AITG.md](../../agentic-top10/Agentic_AITG.md) | OWASP AI Testing Guide | 50 strukturierte Testfaelle fuer ASI01–ASI10 mit Vor-Bereitstellungstoren | | [Agentic_AIVSS.md](../../agentic-top10/Agentic_AIVSS.md) | OWASP AIVSS | Dual-Szenario-Bewertung (ueberwacht vs. autonom), Autonomiepraemie +1.79 | | [Agentic_ENISA.md](../../agentic-top10/Agentic_ENISA.md) | ENISA Multilayer Framework | L1/L2/L3-Schichtenzuordnung, EU AI Act Art. 14/15/52-Abstimmung, NIS2 Artikel 23 Vorfallbewertungsleitfaden | @@ -145,7 +145,7 @@ Alles kostenlos. Alles Open Source. Entwickelt fuer Praktiker. | [DSGAI_MAESTRO.md](../../dsgai-2026/DSGAI_MAESTRO.md) | MAESTRO — CSA | Schicht-Ursprungsanalyse fuer alle 21 Eintraege, L2 Datenoperationen als 52% der DSGAI-Bedrohungsoberflaeche | | [DSGAI_SOC2.md](../../dsgai-2026/DSGAI_SOC2.md) | SOC 2 Trust Services Criteria | TSC-Zuordnung fuer SaaS- und Cloud-GenAI-Bereitstellungen | | [DSGAI_PCIDSS.md](../../dsgai-2026/DSGAI_PCIDSS.md) | PCI DSS v4.0 | CHD-Scope-Leitfaden, PCI-Audit-Checkliste fuer GenAI-Daten | -| [DSGAI_ASVS.md](../../dsgai-2026/DSGAI_ASVS.md) | OWASP ASVS 4.0.3 | L1/L2/L3-Verifizierungsanforderungen fuer alle 21 DSGAI-Eintraege, 4-Phasen-Implementierungsprioritaet | +| [DSGAI_ASVS.md](../../dsgai-2026/DSGAI_ASVS.md) | OWASP ASVS 5.0.0 | L1/L2/L3-Verifizierungsanforderungen fuer alle 21 DSGAI-Eintraege, 4-Phasen-Implementierungsprioritaet | | [DSGAI_CISControls.md](../../dsgai-2026/DSGAI_CISControls.md) | CIS Controls v8.1 | IG1/IG2/IG3-Schutzmassnahmen fuer alle 21 Eintraege, GenAI-Datensicherheits-Implementierungsgruppen | | [DSGAI_CWE_CVE.md](../../dsgai-2026/DSGAI_CWE_CVE.md) | CWE / CVE | CWE-Ursachentaxonomie und bestaetigte CVE-Nachweise fuer alle 21 DSGAI-Eintraege | | [DSGAI_ENISA.md](../../dsgai-2026/DSGAI_ENISA.md) | ENISA Multilayer Framework | L1/L2/L3-Schichtenzuordnung, EU AI Act- und NIS2-Abstimmung fuer alle 21 DSGAI-Eintraege | @@ -234,7 +234,7 @@ crosswalk/ │ ├── DSGAI_MAESTRO.md ← Bedrohungsmodellierung — Datenoperations-Perspektive │ ├── DSGAI_SOC2.md │ ├── DSGAI_PCIDSS.md -│ ├── DSGAI_ASVS.md ← OWASP ASVS 4.0.3 +│ ├── DSGAI_ASVS.md ← OWASP ASVS 5.0.0 │ ├── DSGAI_CISControls.md ← CIS Controls v8.1 │ ├── DSGAI_CWE_CVE.md ← Ursachentaxonomie + CVEs │ ├── DSGAI_ENISA.md ← EU / NIS2 diff --git a/i18n/es/README.md b/i18n/es/README.md index f4c58e2..3ecf7c3 100644 --- a/i18n/es/README.md +++ b/i18n/es/README.md @@ -67,7 +67,7 @@ Todo gratuito. Todo de código abierto. Construido para profesionales. | [MAESTRO — CSA](https://cloudsecurityalliance.org/blog/2025/02/06/agentic-ai-threat-modeling-framework-maestro) | ✅ | ✅ | ✅ | | [ISO/IEC 42001:2023](https://www.iso.org/standard/81230.html) | ✅ | ✅ | ✅ | | [CIS Controls v8.1](https://www.cisecurity.org/controls) | ✅ | ✅ | ✅ | -| [OWASP ASVS 4.0.3](https://owasp.org/projects/asvs) | ✅ | ✅ | ✅ | +| [OWASP ASVS 5.0.0](https://owasp.org/projects/asvs) | ✅ | ✅ | ✅ | | [SOC 2 Trust Services Criteria](https://www.aicpa-cima.com/resources/landing/2017-trust-services-criteria) | ✅ | ✅ | ✅ | | [PCI DSS v4.0](https://www.pcisecuritystandards.org/document_library/) | ✅ | ✅ | ✅ | | [ENISA Multilayer Framework](https://www.enisa.europa.eu/publications/multilayer-framework-for-good-cybersecurity-practices-for-ai) | ✅ | ✅ | ✅ | @@ -90,7 +90,7 @@ Todo gratuito. Todo de código abierto. Construido para profesionales. | [LLM_ISO27001.md](../../llm-top10/LLM_ISO27001.md) | ISO/IEC 27001:2022 | Lista de verificación de extensión ISMS, controles nuevos de 2022 mapeados a riesgos LLM | | [LLM_ISO42001.md](../../llm-top10/LLM_ISO42001.md) | ISO/IEC 42001:2023 | Lista de verificación de implementación AIMS, guía de integración con ISO 27001 | | [LLM_CISControls.md](../../llm-top10/LLM_CISControls.md) | CIS Controls v8.1 | Salvaguardas escalonadas IG1/IG2/IG3 por vulnerabilidad | -| [LLM_ASVS.md](../../llm-top10/LLM_ASVS.md) | OWASP ASVS 4.0.3 | Requisitos de verificación L1/L2/L3 con lista de verificación ASVS | +| [LLM_ASVS.md](../../llm-top10/LLM_ASVS.md) | OWASP ASVS 5.0.0 | Requisitos de verificación L1/L2/L3 con lista de verificación ASVS | | [LLM_ISA62443.md](../../llm-top10/LLM_ISA62443.md) | ISA/IEC 62443 — OT/ICS | Modelo de zonas, calificaciones SL, referencias FR/SR, lista de verificación de despliegue OT | | [LLM_NISTSP80082.md](../../llm-top10/LLM_NISTSP80082.md) | NIST SP 800-82 Rev 3 | Controles SP 800-53, mapeo cruzado regulatorio de EE.UU. (NERC CIP, AWIA, CMMC) | | [LLM_NISTCSF2.md](../../llm-top10/LLM_NISTCSF2.md) | NIST CSF 2.0 | Mapeo de seis funciones incluyendo la nueva función GOVERN, perfil CSF 2.0 | @@ -120,7 +120,7 @@ Todo gratuito. Todo de código abierto. Construido para profesionales. | [Agentic_MAESTRO.md](../../agentic-top10/Agentic_MAESTRO.md) | MAESTRO — CSA | Modelo de amenazas arquitectónico de siete capas, mapeo capa-a-ASI, guía de sesión | | [Agentic_OWASP_NHI.md](../../agentic-top10/Agentic_OWASP_NHI.md) | OWASP NHI Top 10 | Mapeo cruzado completo NHI-a-ASI, tabla de madurez del programa NHI | | [Agentic_CISControls.md](../../agentic-top10/Agentic_CISControls.md) | CIS Controls v8.1 | Salvaguardas IG1/IG2/IG3, NHI agéntico tratado como acceso privilegiado CIS 5 | -| [Agentic_ASVS.md](../../agentic-top10/Agentic_ASVS.md) | OWASP ASVS 4.0.3 | Lista de verificación L1/L2/L3 para despliegues agénticos | +| [Agentic_ASVS.md](../../agentic-top10/Agentic_ASVS.md) | OWASP ASVS 5.0.0 | Lista de verificación L1/L2/L3 para despliegues agénticos | | [Agentic_AITG.md](../../agentic-top10/Agentic_AITG.md) | OWASP AI Testing Guide | 50 casos de prueba estructurados para ASI01–ASI10 con puertas de pre-despliegue | | [Agentic_AIVSS.md](../../agentic-top10/Agentic_AIVSS.md) | OWASP AIVSS | Puntuación de doble escenario (supervisado vs autónomo), prima de autonomía +1.79 | | [Agentic_ENISA.md](../../agentic-top10/Agentic_ENISA.md) | ENISA Multilayer Framework | Mapeo de capas L1/L2/L3, alineación con EU AI Act Art. 14/15/52, guía de evaluación de incidentes NIS2 Artículo 23 | @@ -145,7 +145,7 @@ Todo gratuito. Todo de código abierto. Construido para profesionales. | [DSGAI_MAESTRO.md](../../dsgai-2026/DSGAI_MAESTRO.md) | MAESTRO — CSA | Análisis de capa de origen para las 21 entradas, L2 operaciones de datos como 52% de la superficie de amenazas DSGAI | | [DSGAI_SOC2.md](../../dsgai-2026/DSGAI_SOC2.md) | SOC 2 Trust Services Criteria | Mapeo TSC para despliegues GenAI en SaaS y nube | | [DSGAI_PCIDSS.md](../../dsgai-2026/DSGAI_PCIDSS.md) | PCI DSS v4.0 | Guía de alcance CHD, lista de verificación de auditoría PCI para datos GenAI | -| [DSGAI_ASVS.md](../../dsgai-2026/DSGAI_ASVS.md) | OWASP ASVS 4.0.3 | Requisitos de verificación L1/L2/L3 para las 21 entradas DSGAI, prioridad de implementación en 4 fases | +| [DSGAI_ASVS.md](../../dsgai-2026/DSGAI_ASVS.md) | OWASP ASVS 5.0.0 | Requisitos de verificación L1/L2/L3 para las 21 entradas DSGAI, prioridad de implementación en 4 fases | | [DSGAI_CISControls.md](../../dsgai-2026/DSGAI_CISControls.md) | CIS Controls v8.1 | Salvaguardas IG1/IG2/IG3 para las 21 entradas, grupos de implementación de seguridad de datos GenAI | | [DSGAI_CWE_CVE.md](../../dsgai-2026/DSGAI_CWE_CVE.md) | CWE / CVE | Taxonomía de causa raíz CWE y evidencia CVE confirmada para las 21 entradas DSGAI | | [DSGAI_ENISA.md](../../dsgai-2026/DSGAI_ENISA.md) | ENISA Multilayer Framework | Mapeo de capas L1/L2/L3, alineación con EU AI Act y NIS2 para las 21 entradas DSGAI | @@ -234,7 +234,7 @@ crosswalk/ │ ├── DSGAI_MAESTRO.md ← Modelado de amenazas — perspectiva de operaciones de datos │ ├── DSGAI_SOC2.md │ ├── DSGAI_PCIDSS.md -│ ├── DSGAI_ASVS.md ← OWASP ASVS 4.0.3 +│ ├── DSGAI_ASVS.md ← OWASP ASVS 5.0.0 │ ├── DSGAI_CISControls.md ← CIS Controls v8.1 │ ├── DSGAI_CWE_CVE.md ← Taxonomía de causa raíz + CVEs │ ├── DSGAI_ENISA.md ← UE / NIS2 diff --git a/i18n/ja/README.md b/i18n/ja/README.md index 5409724..8a19501 100644 --- a/i18n/ja/README.md +++ b/i18n/ja/README.md @@ -66,7 +66,7 @@ | [MAESTRO — CSA](https://cloudsecurityalliance.org/blog/2025/02/06/agentic-ai-threat-modeling-framework-maestro) | ✅ | ✅ | ✅ | | [ISO/IEC 42001:2023](https://www.iso.org/standard/81230.html) | ✅ | ✅ | ✅ | | [CIS Controls v8.1](https://www.cisecurity.org/controls) | ✅ | ✅ | ✅ | -| [OWASP ASVS 4.0.3](https://owasp.org/projects/asvs) | ✅ | ✅ | ✅ | +| [OWASP ASVS 5.0.0](https://owasp.org/projects/asvs) | ✅ | ✅ | ✅ | | [SOC 2 Trust Services Criteria](https://www.aicpa-cima.com/resources/landing/2017-trust-services-criteria) | ✅ | ✅ | ✅ | | [PCI DSS v4.0](https://www.pcisecuritystandards.org/document_library/) | ✅ | ✅ | ✅ | | [ENISA Multilayer Framework](https://www.enisa.europa.eu/publications/multilayer-framework-for-good-cybersecurity-practices-for-ai) | ✅ | ✅ | ✅ | @@ -89,7 +89,7 @@ | [LLM_ISO27001.md](../../llm-top10/LLM_ISO27001.md) | ISO/IEC 27001:2022 | ISMS拡張チェックリスト、LLMリスクにマッピングされた2022年新規コントロール | | [LLM_ISO42001.md](../../llm-top10/LLM_ISO42001.md) | ISO/IEC 42001:2023 | AIMS実装チェックリスト、ISO 27001統合ガイダンス | | [LLM_CISControls.md](../../llm-top10/LLM_CISControls.md) | CIS Controls v8.1 | 脆弱性ごとのIG1/IG2/IG3段階別セーフガード | -| [LLM_ASVS.md](../../llm-top10/LLM_ASVS.md) | OWASP ASVS 4.0.3 | ASVSチェックリスト付きL1/L2/L3検証要件 | +| [LLM_ASVS.md](../../llm-top10/LLM_ASVS.md) | OWASP ASVS 5.0.0 | ASVSチェックリスト付きL1/L2/L3検証要件 | | [LLM_ISA62443.md](../../llm-top10/LLM_ISA62443.md) | ISA/IEC 62443 — OT/ICS | ゾーンモデル、SLレーティング、FR/SR参照、OTデプロイメントチェックリスト | | [LLM_NISTSP80082.md](../../llm-top10/LLM_NISTSP80082.md) | NIST SP 800-82 Rev 3 | SP 800-53コントロール、米国規制クロスウォーク(NERC CIP、AWIA、CMMC) | | [LLM_NISTCSF2.md](../../llm-top10/LLM_NISTCSF2.md) | NIST CSF 2.0 | 新しいGOVERN機能を含む6機能マッピング、CSF 2.0プロファイル | @@ -119,7 +119,7 @@ | [Agentic_MAESTRO.md](../../agentic-top10/Agentic_MAESTRO.md) | MAESTRO — CSA | 7層アーキテクチャ脅威モデル、レイヤー対ASIマッピング、セッションガイド | | [Agentic_OWASP_NHI.md](../../agentic-top10/Agentic_OWASP_NHI.md) | OWASP NHI Top 10 | 完全なNHI対ASIクロスマッピング、NHIプログラム成熟度テーブル | | [Agentic_CISControls.md](../../agentic-top10/Agentic_CISControls.md) | CIS Controls v8.1 | IG1/IG2/IG3セーフガード、CIS 5特権アクセスとして扱われるエージェントNHI | -| [Agentic_ASVS.md](../../agentic-top10/Agentic_ASVS.md) | OWASP ASVS 4.0.3 | エージェントデプロイメント向けL1/L2/L3検証チェックリスト | +| [Agentic_ASVS.md](../../agentic-top10/Agentic_ASVS.md) | OWASP ASVS 5.0.0 | エージェントデプロイメント向けL1/L2/L3検証チェックリスト | | [Agentic_AITG.md](../../agentic-top10/Agentic_AITG.md) | OWASP AI Testing Guide | ASI01–ASI10にわたる50の構造化テストケースとデプロイメント前ゲート | | [Agentic_AIVSS.md](../../agentic-top10/Agentic_AIVSS.md) | OWASP AIVSS | デュアルシナリオスコアリング(監視下 vs 自律)、自律性プレミアム +1.79 | | [Agentic_ENISA.md](../../agentic-top10/Agentic_ENISA.md) | ENISA Multilayer Framework | L1/L2/L3レイヤーマッピング、EU AI Act Art. 14/15/52整合、NIS2 Article 23インシデント評価ガイダンス | @@ -143,7 +143,7 @@ | [DSGAI_MAESTRO.md](../../dsgai-2026/DSGAI_MAESTRO.md) | MAESTRO — CSA | 全21エントリのレイヤー起点分析、DSGAI脅威サーフェスの52%としてのL2データオペレーション | | [DSGAI_SOC2.md](../../dsgai-2026/DSGAI_SOC2.md) | SOC 2 Trust Services Criteria | SaaSおよびクラウドGenAIデプロイメント向けTSCマッピング | | [DSGAI_PCIDSS.md](../../dsgai-2026/DSGAI_PCIDSS.md) | PCI DSS v4.0 | CHDスコープガイダンス、GenAIデータ向けPCI監査チェックリスト | -| [DSGAI_ASVS.md](../../dsgai-2026/DSGAI_ASVS.md) | OWASP ASVS 4.0.3 | 全21 DSGAIエントリのL1/L2/L3検証要件、4フェーズ実装優先度 | +| [DSGAI_ASVS.md](../../dsgai-2026/DSGAI_ASVS.md) | OWASP ASVS 5.0.0 | 全21 DSGAIエントリのL1/L2/L3検証要件、4フェーズ実装優先度 | | [DSGAI_CISControls.md](../../dsgai-2026/DSGAI_CISControls.md) | CIS Controls v8.1 | 全21エントリのIG1/IG2/IG3セーフガード、GenAIデータセキュリティ実装グループ | | [DSGAI_CWE_CVE.md](../../dsgai-2026/DSGAI_CWE_CVE.md) | CWE / CVE | 全21 DSGAIエントリのCWE根本原因分類と確認済みCVEエビデンス | | [DSGAI_ENISA.md](../../dsgai-2026/DSGAI_ENISA.md) | ENISA Multilayer Framework | 全21 DSGAIエントリのL1/L2/L3レイヤーマッピング、EU AI ActおよびNIS2整合 | @@ -232,7 +232,7 @@ crosswalk/ │ ├── DSGAI_MAESTRO.md ← 脅威モデリング — データオペレーション視点 │ ├── DSGAI_SOC2.md │ ├── DSGAI_PCIDSS.md -│ ├── DSGAI_ASVS.md ← OWASP ASVS 4.0.3 +│ ├── DSGAI_ASVS.md ← OWASP ASVS 5.0.0 │ ├── DSGAI_CISControls.md ← CIS Controls v8.1 │ ├── DSGAI_CWE_CVE.md ← 根本原因分類 + CVE │ ├── DSGAI_ENISA.md ← EU / NIS2 diff --git a/llm-top10/LLM_AITG.md b/llm-top10/LLM_AITG.md index 23ebf75..8921521 100644 --- a/llm-top10/LLM_AITG.md +++ b/llm-top10/LLM_AITG.md @@ -950,7 +950,7 @@ For each automated test case: - [OWASP AI Testing Guide](https://owasp.org/www-project-ai-testing-guide/) - [OWASP Top 10 for LLM Applications 2026](https://genai.owasp.org/llm-top-10/) -- [OWASP ASVS 4.0.3](https://owasp.org/projects/asvs) +- [OWASP ASVS 5.0.0](https://owasp.org/projects/asvs) - [MITRE ATLAS](https://atlas.mitre.org) - [NIST AI RMF Playbook](https://airc.nist.gov/AI_RMF_Knowledge_Base/Playbook) - [Garak — LLM vulnerability scanner](https://github.com/leondz/garak) diff --git a/llm-top10/LLM_ASVS.md b/llm-top10/LLM_ASVS.md index 4cbfb66..a38bdad 100644 --- a/llm-top10/LLM_ASVS.md +++ b/llm-top10/LLM_ASVS.md @@ -7,13 +7,13 @@ License : CC BY-SA 4.0 --> -# LLM Top 10 2026 × OWASP ASVS 4.0.3 +# LLM Top 10 2026 × OWASP ASVS 5.0.0 Mapping the [OWASP Top 10 for LLM Applications 2026](https://genai.owasp.org/llm-top-10/) to the -[OWASP Application Security Verification Standard (ASVS) 4.0.3](https://owasp.org/projects/asvs) +[OWASP Application Security Verification Standard (ASVS) 5.0.0](https://owasp.org/projects/asvs) — the framework for testing and verifying the security of web -applications and APIs, organised into 14 chapters with three +applications and APIs, organised into 17 chapters with three verification levels (L1/L2/L3). ASVS is the go-to reference for security architects, developers, @@ -835,7 +835,7 @@ reaches a shell, a browser, or a database. ## References -- [OWASP ASVS 4.0.3](https://owasp.org/projects/asvs) +- [OWASP ASVS 5.0.0](https://owasp.org/projects/asvs) - [OWASP ASVS GitHub](https://github.com/OWASP/ASVS) - [OWASP LLM Top 10 2026](https://genai.owasp.org/llm-top-10/) - [OWASP AI Testing Guide](https://owasp.org/www-project-ai-testing-guide/) diff --git a/scripts/compliance-report.js b/scripts/compliance-report.js index ef2d524..c1a838c 100644 --- a/scripts/compliance-report.js +++ b/scripts/compliance-report.js @@ -53,7 +53,7 @@ const REPORT_FRAMEWORKS = [ 'CIS Controls v8.1', 'ISA/IEC 62443', 'NIST SP 800-82 Rev 3', - 'OWASP ASVS 4.0.3', + 'OWASP ASVS 5.0.0', 'OWASP AISVS 1.0', 'OWASP SAMM v2.0', 'PCI DSS v4.0', @@ -128,7 +128,7 @@ const FW_META = { audience: 'ICS/SCADA teams', note: 'OT-specific overlay for NIST CSF and RMF.', }, - 'OWASP ASVS 4.0.3': { + 'OWASP ASVS 5.0.0': { short: 'OWASP ASVS', deadline: 'Ongoing — L1/L2/L3 verification', audience: 'AppSec engineers, pen testers', diff --git a/scripts/control-ids.js b/scripts/control-ids.js index b68b6ac..f3cdc58 100644 --- a/scripts/control-ids.js +++ b/scripts/control-ids.js @@ -63,7 +63,7 @@ const GRAMMARS = { // the em dash should be. re: /\b([A-Z]{3})\b(?=\s*[^\sA-Za-z0-9])/, }, - 'OWASP ASVS 4.0.3': { + 'OWASP ASVS 5.0.0': { // Requirement ids are V.
.; the chapter alone // (V8) is the parent, and some tables put the chapter in its own column. re: /\b(V\d{1,2}\.\d{1,2}\.\d{1,2})\b/, @@ -164,7 +164,7 @@ const ID_SHAPES = { 'CWE/CVE': /^(?:CWE-\d{1,4}|CVE-\d{4}-\d{4,7})$/, 'OWASP AI Testing Guide': /^[A-Z]{3}$/, 'ISO/IEC 42001:2023': /^(?:[AB]\.\d{1,2}(?:\.\d{1,2}){0,2}|\d{1,2}(?:\.\d{1,2}){0,2})$/, - 'OWASP ASVS 4.0.3': /^V\d{1,2}\.\d{1,2}\.\d{1,2}$/, + 'OWASP ASVS 5.0.0': /^V\d{1,2}\.\d{1,2}\.\d{1,2}$/, }; /** @@ -177,7 +177,7 @@ const REGISTRY_EXTRA_SHAPES = { 'CIS Controls v8.1': /^CIS-\d{1,2}$/, // ASVS registries carry the chapters (V8) beside the requirements (V8.1.1). // chapters (V8) and sections (V8.1) sit in the registry beside requirements - 'OWASP ASVS 4.0.3': /^V\d{1,2}(\.\d{1,2})?$/, + 'OWASP ASVS 5.0.0': /^V\d{1,2}(\.\d{1,2})?$/, }; /** True when `id` is well-formed for `framework` in a registry file. */ diff --git a/scripts/generate.js b/scripts/generate.js index 8bd5858..75d0c96 100644 --- a/scripts/generate.js +++ b/scripts/generate.js @@ -136,7 +136,7 @@ const FRAMEWORK_FILES = [ { rel: 'llm-top10/LLM_ISO27001.md', framework: 'ISO/IEC 27001:2022', ids: LLM_IDS }, { rel: 'llm-top10/LLM_ISO42001.md', framework: 'ISO/IEC 42001:2023', ids: LLM_IDS }, { rel: 'llm-top10/LLM_CISControls.md', framework: 'CIS Controls v8.1', ids: LLM_IDS }, - { rel: 'llm-top10/LLM_ASVS.md', framework: 'OWASP ASVS 4.0.3', ids: LLM_IDS }, + { rel: 'llm-top10/LLM_ASVS.md', framework: 'OWASP ASVS 5.0.0', ids: LLM_IDS }, { rel: 'llm-top10/LLM_ISA62443.md', framework: 'ISA/IEC 62443', ids: LLM_IDS }, { rel: 'llm-top10/LLM_NISTSP80082.md', framework: 'NIST SP 800-82 Rev 3', ids: LLM_IDS }, { rel: 'llm-top10/LLM_NISTCSF2.md', framework: 'NIST CSF 2.0', ids: LLM_IDS }, @@ -168,7 +168,7 @@ const FRAMEWORK_FILES = [ { rel: 'agentic-top10/Agentic_ISO27001.md', framework: 'ISO/IEC 27001:2022', ids: ASI_IDS }, { rel: 'agentic-top10/Agentic_ISO42001.md', framework: 'ISO/IEC 42001:2023', ids: ASI_IDS }, { rel: 'agentic-top10/Agentic_CISControls.md', framework: 'CIS Controls v8.1', ids: ASI_IDS }, - { rel: 'agentic-top10/Agentic_ASVS.md', framework: 'OWASP ASVS 4.0.3', ids: ASI_IDS }, + { rel: 'agentic-top10/Agentic_ASVS.md', framework: 'OWASP ASVS 5.0.0', ids: ASI_IDS }, { rel: 'agentic-top10/Agentic_ISA62443.md', framework: 'ISA/IEC 62443', ids: ASI_IDS }, { rel: 'agentic-top10/Agentic_NISTSP80082.md', framework: 'NIST SP 800-82 Rev 3', ids: ASI_IDS }, { rel: 'agentic-top10/Agentic_NISTCSF2.md', framework: 'NIST CSF 2.0', ids: ASI_IDS }, @@ -193,7 +193,7 @@ const FRAMEWORK_FILES = [ { rel: 'dsgai-2026/DSGAI_ISO27001.md', framework: 'ISO/IEC 27001:2022', ids: DSGAI_IDS }, { rel: 'dsgai-2026/DSGAI_ISO42001.md', framework: 'ISO/IEC 42001:2023', ids: DSGAI_IDS }, { rel: 'dsgai-2026/DSGAI_CISControls.md', framework: 'CIS Controls v8.1', ids: DSGAI_IDS }, - { rel: 'dsgai-2026/DSGAI_ASVS.md', framework: 'OWASP ASVS 4.0.3', ids: DSGAI_IDS }, + { rel: 'dsgai-2026/DSGAI_ASVS.md', framework: 'OWASP ASVS 5.0.0', ids: DSGAI_IDS }, { rel: 'dsgai-2026/DSGAI_ISA62443.md', framework: 'ISA/IEC 62443', ids: DSGAI_IDS }, { rel: 'dsgai-2026/DSGAI_NISTSP80082.md', framework: 'NIST SP 800-82 Rev 3', ids: DSGAI_IDS }, { rel: 'dsgai-2026/DSGAI_NISTCSF2.md', framework: 'NIST CSF 2.0', ids: DSGAI_IDS },