OWASP ASVS
V14 Configuration

OWASP ASVS OWASPASVS-14: Configuration and Hardening (V14)

Per OWASP ASVS V14: implement secure configuration. Requirements include (a) maintain hardened baseline configurations across application + middleware + runtime + container + cloud infrastructure + (b) implement configuration management with drift detection + remediation + (c) disable unnecessary features + services + endpoints + debug + verbose error messages + (d) implement secure deployment pipeline with infrastructure as code + signed artefacts + (e) apply security headers (HSTS + CSP + X-Content-Type-Options + Referrer-Policy + Permissions-Policy + similar where applicable) + (f) protect secrets via dedicated secret store + (g) maintain CI/CD security including pipeline isolation + artifact integrity + deployment approvals.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.