OWASP / OWASP/ASVS

Section and requirement relevance questions

Open
#1,797 25 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

_5.0 - Not blocker 1) Discussion ongoing Community wanted
Dominant language
HTML
Stars
3.6k
Forks
831
Avg merge
7h 55m
Merged PRs (30d)
4

Description

Something which comes up constantly is how do we know which requirement/sections of ASVS are relevant to an application.

(Most recently in discussions with the ADA.)

I think it would be good to have a set of questions at the start of each chapter/section to guide someone in whether they need to consider the requirements in that chapter/section.

What do people think?

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reading the existing ASVS chapter and section structure, then review the discussion on this issue for any agreed direction. Done means the relevant chapters and sections have a consistent set of questions that helps readers decide whether their requirements apply.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.