OWASP / OWASP/ASVS

Clarification request regarding ASVS 5.0 control scope

Open
#3,321 2 comments 0 reactions 1 assignee View on GitHub

@tghosth is already working on this.

Since Jan 5, 2026.

_5.0 - Not blocker 2) Awaiting response
Dominant language
HTML
Stars
3.6k
Forks
831
Avg merge
7h 55m
Merged PRs (30d)
4

Description

Hello ASVS team,

I am reviewing ASVS 5.0 for research and practical alignment with other security frameworks.

I would appreciate clarification on how the ASVS requirements are intended to be interpreted when used as a baseline versus a target maturity level, especially in environments with mixed legacy and modern components.

Thank you for maintaining this important standard.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.