OWASP Top 10:2025
Configuration and Hardening

OWASP Top 10:2025 OWASPTOP10-5: A05:2025 Security Misconfiguration

Address OWASP Top 10 A05 Security Misconfiguration per OWASP Top 10:2025. Security Misconfiguration occurs across application + middleware + runtime + infrastructure including default credentials + unnecessary features enabled + verbose error messages + missing security headers + cloud + container + Kubernetes misconfigurations + and CORS issues. Mitigations include (a) maintain hardened baseline configurations across stack + (b) implement configuration management with drift detection + remediation + (c) disable unnecessary features + endpoints + debug + verbose errors + (d) apply security headers (HSTS + CSP + X-Content-Type-Options + Referrer-Policy + Permissions-Policy + similar) + (e) implement Content Security Policy + browser hardening + (f) maintain secure cloud + container + orchestration configurations.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.