OWASP ASVS
V10 Malicious Code

OWASP ASVS OWASPASVS-10: Malicious Code Verification (V10)

Per OWASP ASVS V10: protect against malicious code. Requirements include (a) integrate static + dynamic + interactive application security testing in CI/CD pipeline + (b) maintain dependency inventory + SBOM + scan for vulnerabilities + license issues + malicious packages + (c) verify package provenance + signing + (d) implement code signing for application code + scripts + container images + (e) protect against supply chain attacks via dependency confusion + typosquatting + repository compromise + (f) implement runtime application self-protection (RASP) + similar runtime protections where appropriate.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 53 controls across 38 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ASD37-06 Email content filtering (Excellent)
  • ASD37-12 Antivirus software with heuristics (Very Good)
  • ASD37-16 Antivirus software with signatures (Limited)

ISO/IEC 30111:2019 · 3 controls

  • 30111-1 Scope
  • 30111-3 Terms and definitions
  • 30111-8.1 Post-release monitoring
  • FTC-Safeguards-IR-Plan-BoardReporting-FTC-Notification Written Incident Response Plan + Board Reporting + FTC Breach Notification (16 CFR 314.4(h), (i), (j))
  • FTC-Safeguards-ServiceProvider-Evaluation Service Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g))

ISO/IEC 29147:2018 · 2 controls

  • 29147-5.6 Advisory Content and Quality
  • 29147-7.8 Remediation information
  • NISTSP115-3 Target Identification and Analysis - Network Discovery, Port and Service ID, Vuln Scanning
  • NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material

NIST SP 800-137 · 2 controls

  • NISTSP137-5 Vulnerability + Patch + Configuration Status Monitoring
  • NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring

OpenSSF Scorecard · 2 controls

  • OSSFSC-2 Dependency Management, Pinning, Updates, Vulnerability Tracking
  • OSSFSC-4 Security Policy, Vulnerability Disclosure, Responsible Reporting

API 1164 · 1 control

  • API1164-12 Incident Response

FISMA · 1 control

  • FISMA-CIRCIA-ZTA-EO14028 CIRCIA, Zero Trust Architecture, EO 14028 + 14110 + OMB Memoranda

FedRAMP Rev 5 · 1 control

  • FedRAMP-ConMon Continuous Monitoring (ConMon) and Significant Change Requests
  • GhCSA-Implementation-Roadmap Implementation Roadmap - Organizational Roles, Tooling and Metrics
  • HKMA-CRAF-Domain3-4-Protection-Detection HKMA C-RAF Domain 3 (Protection) + Domain 4 (Detection) - Access, Data, Infrastructure, Application, Monitoring, Testing, Threat Intel

IEEE 1686 · 1 control

  • IEEE1686-Section5.5-5.6-5.7-5.8-Firmware-ConfigSW-TimeSync-DataAtRest IEEE 1686 Section 5.5-5.8 - Firmware Quality + Configuration Software Security + Time Synchronisation + Data Protection at Rest + Patch + Malware + Hardening + Vulnerability

ISMAP (Japan) · 1 control

ISO/IEC 27010:2015 · 1 control

  • 27010-12.2 Protection from malware

ISO/IEC 27011:2024 · 1 control

  • 27011-8.5 Vulnerability and malware management

ISO/IEC 29134:2023 · 1 control

  • 29134-9.2 Report findings and recommendations
  • JP-FSA-CYB-Cybersecurity-Exercises-Drills-Annual-Tabletop-Industry-Wide-Exercise-Delta-Wall-FSA-Coordinated-Sector Japan FSA Cybersecurity Exercises + Drills + Annual Tabletop + Industry-Wide Exercise + Delta Wall + FSA Coordinated Sector-Wide + FISC Drills + Cross-Sector Crisis Coordination + International Exercises + Cyber Range

MITRE ATT&CK · 1 control

MITRE D3FEND · 1 control

MTCS (Singapore) · 1 control

  • MTCS-Acquisition-Development-Maintenance-Supplier-Vulnerability-DevSecOps-SBOM-SDLC-SCA-API-Container MTCS Acquisition + Development + Maintenance + Supplier + Vulnerability + DevSecOps + SBOM + SDLC + SCA

NERC CIP · 1 control

  • NERCCIP-5 System Security Management + Configuration Change Management and Vulnerability Assessments (CIP-007 + CIP-010)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 800-123 · 1 control

  • NISTSP123-5 Server Operations - Patching, Malware, Logging, Backup

NIST SP 800-144 · 1 control

  • NISTSP144-7 Cloud Workload Protection, Containers, Serverless, and Configuration

NIST SP 800-145 · 1 control

  • NISTSP145-7 Cloud Procurement Standards Aligned to NIST SP 800-145 Definition

NIST SP 800-146 · 1 control

  • NISTSP61-5 Containment, Eradication, and Recovery

NIST SP 800-63-4 · 1 control

  • NISTSP63R4-8 Operational Audit, Session Management, Recovery, and Cross-cutting Controls
  • NISTSP82-5 OT Configuration Management, Patching, Vulnerability Management, and Malware Protection

NIST SP 800-88 · 1 control

  • NISTSP88-7 Verification, Audit, Training, and Environmental/Safety Controls

NIST SP 800-92 · 1 control

  • NISTSP92-5 Log Analysis: Correlation, Baselining, Anomaly Detection, Alerting, Manual Review
  • NRFCS-2 Risk Assessment, Customer Data Inventory, Classification, and Retail Threat Model
  • NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation
  • NZISM-5 Network Security, System Hardening, and Application Security
  • ORANWG11-1 O-RAN Threat Model, Risk Management, and Security Architecture

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 53 it maps to, and the evidence behind each claim, over MCP and REST.