Clarify that the scope is web applications in "Scope of the ASVS"
Nobody has claimed this yet.
- Dominant language
- HTML
- Stars
- 3.6k
- Forks
- 831
- Avg merge
- 7h 55m
- Merged PRs (30d)
- 4
Description
In "What is the ASVS?" we have (emphasis mine):
The Application Security Verification Standard (ASVS) defines security requirements for web appli‑
cations and services, and it is a valuable resource for anyone aiming to design, develop, and maintain
secure applications or evaluate their security.
The scope if web applications (i.e. not mobile, not CLI, not desktop).
This is not maybe (?) the only place in the document where this is states and it is quite easy to miss this single word.
For example, the "Scope of the ASVS" section (and the "Application" subsection) never mentions this:
ASVS defines an “application” as the software product being developed, into which security controls
must be integrated. ASVS does not prescribe development lifecycle activities or dictate how the ap‑
plication should be built via a CI/CD pipeline; instead, it specifies the security outcomes that must
be achieved within the product itself.
I think it would be worthwhile to start the "Application" subsection" with a paragraph stating:
- which types of applications are in scope;
- which type of application are not;
- maybe clarify in what extent the document is applicable/useful for applications outside of the scope;
- maybe reference other documents (such as the MAST) in here.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by comparing the “What is the ASVS?”, “Scope of the ASVS”, and “Application” sections named in the issue. Review the existing wording and any project guidance before deciding how the scope and out-of-scope applications should be explained. Done means the Application subsection clearly states the scope and any relevant limitations or references.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation
- Issue type
- Documentation
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100