Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 11 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,17 @@ Versioning follows [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
6.1.2/3.5.1, LLM08 hidden context 10.2.4, LLM10 generated code 9.3.7). AISVS has no requirement for scanning
generated code itself; the LLM10 section says so.

### Changed

- **ASVS framework renamed `OWASP ASVS 4.0.3` → `OWASP ASVS 5.0.0`** in the generated data, exports, registry,
webapp and docs. The three ASVS mapping files were already translated to 5.0.0 identifiers (#123); this brings the
framework's name in line. **Consumers that filter exports by framework name must update the string.** 5.0.0 is
the latest versioned ASVS release; ASVS's `latest` tag is its Bleeding Edge build, not a release. Six incident
`control_failures` (INC-138, 139, 140, 145, 146, 147) that cited 5.0.0 identifiers under the old name now carry
the correct one. The 24 rows whose 4.0.3 requirement 5.0.0 deleted keep their 4.0.3 identifier and their DRAFT
marker, and `docs/classifier-predictions.js`, the dated 2026-04-09 classifier snapshot on 4.0.3 chapters, keeps
its 4.0.3 label.

Next: npm publish to npmjs.com, custom domain (crosswalk.owasp.org), vendor integration packs, NeMo Guardrails configs.

---
Expand Down
2 changes: 1 addition & 1 deletion RATIONALE.md
Original file line number Diff line number Diff line change
Expand Up @@ -95,7 +95,7 @@ Every framework was selected based on at least two of the following:

| Framework | Why Included |
|---|---|
| **OWASP ASVS 4.0.3** | Application Security Verification Standard with three levels (L1/L2/L3). Maps GenAI risks to specific verification requirements so development teams can test for AI-specific vulnerabilities using the same ASVS methodology they use for traditional web apps. |
| **OWASP ASVS 5.0.0** | Application Security Verification Standard with three levels (L1/L2/L3). Maps GenAI risks to specific verification requirements so development teams can test for AI-specific vulnerabilities using the same ASVS methodology they use for traditional web apps. |
| **OWASP SAMM v2.0** | Software Assurance Maturity Model. Maps GenAI risks to maturity practices across Governance, Design, Implementation, Verification, and Operations. Helps organisations measure and improve their AI security programme maturity over time. |
| **NIST SP 800-218A** | Secure Software Development Framework extension for AI. Maps GenAI risks to AI-specific secure development practices (PW/PS/RV). The authoritative US guidance for secure AI SDLC — directly applicable to developer workflows. |

Expand Down
10 changes: 5 additions & 5 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -113,7 +113,7 @@ All free. All open-source. Built for practitioners.
| [MAESTRO — CSA](https://cloudsecurityalliance.org/blog/2025/02/06/agentic-ai-threat-modeling-framework-maestro) | ✅ | ✅ | ✅ |
| [ISO/IEC 42001:2023](https://www.iso.org/standard/81230.html) | ✅ | ✅ | ✅ |
| [CIS Controls v8.1](https://www.cisecurity.org/controls) | ✅ | ✅ | ✅ |
| [OWASP ASVS 4.0.3](https://owasp.org/projects/asvs) | ✅ | ✅ | ✅ |
| [OWASP ASVS 5.0.0](https://owasp.org/projects/asvs) | ✅ | ✅ | ✅ |
| [OWASP AISVS 1.0](https://github.com/OWASP/AISVS/tree/main/1.0/en) | ✅ | ✅ | ✅ |
| [SOC 2 Trust Services Criteria](https://www.aicpa-cima.com/resources/landing/2017-trust-services-criteria) | ✅ | ✅ | ✅ |
| [PCI DSS v4.0](https://www.pcisecuritystandards.org/document_library/) | ✅ | ✅ | ✅ |
Expand All @@ -140,7 +140,7 @@ All free. All open-source. Built for practitioners.
| [LLM_ISO27001.md](llm-top10/LLM_ISO27001.md) | ISO/IEC 27001:2022 | ISMS extension checklist, 2022 new controls mapped to LLM risks |
| [LLM_ISO42001.md](llm-top10/LLM_ISO42001.md) | ISO/IEC 42001:2023 | AIMS implementation checklist, ISO 27001 integration guidance |
| [LLM_CISControls.md](llm-top10/LLM_CISControls.md) | CIS Controls v8.1 | IG1/IG2/IG3 tiered safeguards per vulnerability |
| [LLM_ASVS.md](llm-top10/LLM_ASVS.md) | OWASP ASVS 4.0.3 | L1/L2/L3 verification requirements with ASVS checklist |
| [LLM_ASVS.md](llm-top10/LLM_ASVS.md) | OWASP ASVS 5.0.0 | L1/L2/L3 verification requirements with ASVS checklist |
| [LLM_ISA62443.md](llm-top10/LLM_ISA62443.md) | ISA/IEC 62443 — OT/ICS | Zone model, SL ratings, FR/SR references, OT deployment checklist |
| [LLM_NISTSP80082.md](llm-top10/LLM_NISTSP80082.md) | NIST SP 800-82 Rev 3 | SP 800-53 controls, US regulatory crosswalk (NERC CIP, AWIA, CMMC) |
| [LLM_NISTCSF2.md](llm-top10/LLM_NISTCSF2.md) | NIST CSF 2.0 | Six-function mapping including new GOVERN function, CSF 2.0 profile |
Expand Down Expand Up @@ -174,7 +174,7 @@ All free. All open-source. Built for practitioners.
| [Agentic_MAESTRO.md](agentic-top10/Agentic_MAESTRO.md) | MAESTRO — CSA | Seven-layer architectural threat model, layer-to-ASI mapping, session guide |
| [Agentic_OWASP_NHI.md](agentic-top10/Agentic_OWASP_NHI.md) | OWASP NHI Top 10 | Full NHI-to-ASI cross-mapping, NHI programme maturity table |
| [Agentic_CISControls.md](agentic-top10/Agentic_CISControls.md) | CIS Controls v8.1 | IG1/IG2/IG3 safeguards, agentic NHI treated as CIS 5 privileged access |
| [Agentic_ASVS.md](agentic-top10/Agentic_ASVS.md) | OWASP ASVS 4.0.3 | L1/L2/L3 verification checklist for agentic deployments |
| [Agentic_ASVS.md](agentic-top10/Agentic_ASVS.md) | OWASP ASVS 5.0.0 | L1/L2/L3 verification checklist for agentic deployments |
| [Agentic_AITG.md](agentic-top10/Agentic_AITG.md) | OWASP AI Testing Guide | 50 structured test cases across ASI01–ASI10 with pre-deployment gates |
| [Agentic_AIVSS.md](agentic-top10/Agentic_AIVSS.md) | OWASP AIVSS | Dual-scenario scoring (supervised vs autonomous), +1.79 autonomy premium |
| [Agentic_ENISA.md](agentic-top10/Agentic_ENISA.md) | ENISA Multilayer Framework | L1/L2/L3 layer mapping, EU AI Act Art. 14/15/52 alignment, NIS2 Article 23 incident assessment guidance |
Expand Down Expand Up @@ -203,7 +203,7 @@ All free. All open-source. Built for practitioners.
| [DSGAI_MAESTRO.md](dsgai-2026/DSGAI_MAESTRO.md) | MAESTRO — CSA | Layer-origin analysis for all 21 entries, L2 data operations as 52% of DSGAI threat surface |
| [DSGAI_SOC2.md](dsgai-2026/DSGAI_SOC2.md) | SOC 2 Trust Services Criteria | TSC mapping for SaaS and cloud GenAI deployments |
| [DSGAI_PCIDSS.md](dsgai-2026/DSGAI_PCIDSS.md) | PCI DSS v4.0 | CHD scope guidance, PCI audit checklist for GenAI data |
| [DSGAI_ASVS.md](dsgai-2026/DSGAI_ASVS.md) | OWASP ASVS 4.0.3 | L1/L2/L3 verification requirements for all 21 DSGAI entries, 4-phase implementation priority |
| [DSGAI_ASVS.md](dsgai-2026/DSGAI_ASVS.md) | OWASP ASVS 5.0.0 | L1/L2/L3 verification requirements for all 21 DSGAI entries, 4-phase implementation priority |
| [DSGAI_CISControls.md](dsgai-2026/DSGAI_CISControls.md) | CIS Controls v8.1 | IG1/IG2/IG3 safeguards for all 21 entries, GenAI data security implementation groups |
| [DSGAI_CWE_CVE.md](dsgai-2026/DSGAI_CWE_CVE.md) | CWE / CVE | CWE root cause taxonomy and confirmed CVE evidence for all 21 DSGAI entries |
| [DSGAI_ENISA.md](dsgai-2026/DSGAI_ENISA.md) | ENISA Multilayer Framework | L1/L2/L3 layer mapping, EU AI Act and NIS2 alignment for all 21 DSGAI entries |
Expand Down Expand Up @@ -310,7 +310,7 @@ crosswalk/
│ ├── DSGAI_MAESTRO.md ← Threat modeling — data operations lens
│ ├── DSGAI_SOC2.md
│ ├── DSGAI_PCIDSS.md
│ ├── DSGAI_ASVS.md ← OWASP ASVS 4.0.3
│ ├── DSGAI_ASVS.md ← OWASP ASVS 5.0.0
│ ├── DSGAI_CISControls.md ← CIS Controls v8.1
│ ├── DSGAI_CWE_CVE.md ← Root cause taxonomy + CVEs
│ ├── DSGAI_ENISA.md ← EU / NIS2
Expand Down
8 changes: 4 additions & 4 deletions agentic-top10/Agentic_ASVS.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,15 +7,15 @@
License : CC BY-SA 4.0
-->

# Agentic Top 10 2026 × OWASP ASVS 4.0.3
# Agentic Top 10 2026 × OWASP ASVS 5.0.0

Mapping the
[OWASP Top 10 for Agentic Applications 2026](https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/)
to the
[OWASP Application Security Verification Standard (ASVS) 4.0.3](https://owasp.org/projects/asvs)
[OWASP Application Security Verification Standard (ASVS) 5.0.0](https://owasp.org/projects/asvs)
—
the framework for testing and verifying web application and API
security, organised into 14 chapters with three verification levels.
security, organised into 17 chapters with three verification levels.

> **Mapped against ASVS 5.0.0.** The identifiers below were translated from 4.0.3
> using the ASVS project’s own mapping file, [`mapping_v4.0.3_to_v5.0.0.yml`][asvs-map],
Expand Down Expand Up @@ -725,7 +725,7 @@ Without complete audit trails, rogue behaviour cannot be detected.

## References

- [OWASP ASVS 4.0.3](https://owasp.org/projects/asvs)
- [OWASP ASVS 5.0.0](https://owasp.org/projects/asvs)
- [OWASP ASVS GitHub](https://github.com/OWASP/ASVS)
- [OWASP Agentic Top 10 2026](https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/)
- [OWASP AI Testing Guide](https://owasp.org/www-project-ai-testing-guide/)
Expand Down
Loading
Loading