OWASP ASVS
V11 Business Logic

OWASP ASVS OWASPASVS-11: Business Logic Verification (V11)

Per OWASP ASVS V11: verify business logic. Requirements include (a) identify + threat-model business logic flows including sensitive operations + multi-step workflows + (b) implement business logic security controls including step ordering + state validation + replay prevention + (c) protect against business flow abuse via automation + scalping + scraping + fake transaction generation + (d) implement transaction limits + velocity controls + anomaly detection + (e) test business logic via negative testing + abuse case modelling + (f) maintain monitoring + alerting for business logic abuse.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.