Clarification request regarding ASVS 5.0 control scope
Open
@tghosth is already working on this.
Since Jan 5, 2026.
_5.0 - Not blocker
2) Awaiting response
- Dominant language
- HTML
- Stars
- 3.6k
- Forks
- 831
- Avg merge
- 7h 55m
- Merged PRs (30d)
- 4
Description
Hello ASVS team,
I am reviewing ASVS 5.0 for research and practical alignment with other security frameworks.
I would appreciate clarification on how the ASVS requirements are intended to be interpreted when used as a baseline versus a target maturity level, especially in environments with mixed legacy and modern components.
Thank you for maintaining this important standard.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.