Frameworks / OWASP ASVS / OWASPASVS-10 OWASP ASVS
V10 Malicious Code
OWASP ASVS OWASPASVS-10: Malicious Code Verification (V10) Per OWASP ASVS V10: protect against malicious code. Requirements include (a) integrate static + dynamic + interactive application security testing in CI/CD pipeline + (b) maintain dependency inventory + SBOM + scan for vulnerabilities + license issues + malicious packages + (c) verify package provenance + signing + (d) implement code signing for application code + scripts + container images + (e) protect against supply chain attacks via dependency confusion + typosquatting + repository compromise + (f) implement runtime application self-protection (RASP) + similar runtime protections where appropriate.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 53 controls across 38 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ASD37-06 Email content filtering (Excellent) ASD37-12 Antivirus software with heuristics (Very Good) ASD37-16 Antivirus software with signatures (Limited) 30111-1 Scope 30111-3 Terms and definitions 30111-8.1 Post-release monitoring FTC-Safeguards-IR-Plan-BoardReporting-FTC-Notification Written Incident Response Plan + Board Reporting + FTC Breach Notification (16 CFR 314.4(h), (i), (j)) FTC-Safeguards-ServiceProvider-Evaluation Service Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g)) 29147-5.6 Advisory Content and Quality 29147-7.8 Remediation information NISTSP115-3 Target Identification and Analysis - Network Discovery, Port and Service ID, Vuln Scanning NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material NISTSP137-5 Vulnerability + Patch + Configuration Status Monitoring NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring OSSFSC-2 Dependency Management, Pinning, Updates, Vulnerability Tracking OSSFSC-4 Security Policy, Vulnerability Disclosure, Responsible Reporting API1164-12 Incident Response FISMA-CIRCIA-ZTA-EO14028 CIRCIA, Zero Trust Architecture, EO 14028 + 14110 + OMB Memoranda FedRAMP-ConMon Continuous Monitoring (ConMon) and Significant Change Requests GhCSA-Implementation-Roadmap Implementation Roadmap - Organizational Roles, Tooling and Metrics HKMA-CRAF-Domain3-4-Protection-Detection HKMA C-RAF Domain 3 (Protection) + Domain 4 (Detection) - Access, Data, Infrastructure, Application, Monitoring, Testing, Threat Intel IEEE1686-Section5.5-5.6-5.7-5.8-Firmware-ConfigSW-TimeSync-DataAtRest IEEE 1686 Section 5.5-5.8 - Firmware Quality + Configuration Software Security + Time Synchronisation + Data Protection at Rest + Patch + Malware + Hardening + Vulnerability 27010-12.2 Protection from malware 27011-8.5 Vulnerability and malware management 29134-9.2 Report findings and recommendations JP-FSA-CYB-Cybersecurity-Exercises-Drills-Annual-Tabletop-Industry-Wide-Exercise-Delta-Wall-FSA-Coordinated-Sector Japan FSA Cybersecurity Exercises + Drills + Annual Tabletop + Industry-Wide Exercise + Delta Wall + FSA Coordinated Sector-Wide + FISC Drills + Cross-Sector Crisis Coordination + International Exercises + Cyber Range MTCS-Acquisition-Development-Maintenance-Supplier-Vulnerability-DevSecOps-SBOM-SDLC-SCA-API-Container MTCS Acquisition + Development + Maintenance + Supplier + Vulnerability + DevSecOps + SBOM + SDLC + SCA NERCCIP-5 System Security Management + Configuration Change Management and Vulnerability Assessments (CIP-007 + CIP-010) NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) NISTSP123-5 Server Operations - Patching, Malware, Logging, Backup NISTSP144-7 Cloud Workload Protection, Containers, Serverless, and Configuration NISTSP145-7 Cloud Procurement Standards Aligned to NIST SP 800-145 Definition NISTSP61-5 Containment, Eradication, and Recovery NISTSP63R4-8 Operational Audit, Session Management, Recovery, and Cross-cutting Controls NISTSP82-5 OT Configuration Management, Patching, Vulnerability Management, and Malware Protection NISTSP88-7 Verification, Audit, Training, and Environmental/Safety Controls NISTSP92-5 Log Analysis: Correlation, Baselining, Anomaly Detection, Alerting, Manual Review NRFCS-2 Risk Assessment, Customer Data Inventory, Classification, and Retail Threat Model NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation NZISM-5 Network Security, System Hardening, and Application Security ORANWG11-1 O-RAN Threat Model, Risk Management, and Security Architecture Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 53 it maps to, and the evidence behind each claim, over MCP and REST.