OWASP Top 10 for LLM Applications 2025
Output Quality and Safety

OWASP Top 10 for LLM Applications 2025 OWASPLLM-2: Improper Output Handling and Misinformation (LLM05 + LLM09)

Address OWASP LLM05:2025 Improper Output Handling + LLM09:2025 Misinformation. Improper Output Handling occurs when LLM output is consumed by downstream systems (browsers + databases + code execution + tools) without validation + sanitisation enabling XSS + SQL injection + RCE + SSRF + CSRF. Misinformation occurs when LLM produces inaccurate + fabricated + hallucinated content that users + systems treat as authoritative including factual errors + unsafe code + made-up citations + and over-reliance on incorrect output. Mitigations for Improper Output Handling include (a) treat LLM output as untrusted input + apply context-appropriate encoding + escaping + (b) parameterise downstream queries + (c) sandbox code generation + execution. Mitigations for Misinformation include (a) implement retrieval augmented generation (RAG) with vetted sources + citation + (b) implement fact-checking + verification for high-stakes output + (c) maintain user education on limitations + appropriate use + (d) implement confidence + uncertainty signalling + (e) limit autonomous action on uncertain output.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 52 controls across 41 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ASD37-18 Restrict administrative privileges (Essential)
  • ASD37-20 Multi-factor authentication (Essential)
  • AWWA-1.3 Security Awareness and Training
  • AWWA-2.1 User Access Management
  • NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing
  • NISTPF-5 Protect-P Access Control (PR.AC-P)

OWASP Top 10:2025 · 2 controls

BSI IT-Grundschutz · 1 control

  • BSI-02 Access enforcement and least privilege
  • DSO-3 Data Access Management
  • CAT-IRP-4 Organizational characteristics
  • 62351-8 Role-based access control (RBAC)

ISO 27799:2025 · 1 control

  • ISO27799-01 ePHI access controls and authorization

ISO/IEC 27011:2024 · 1 control

  • 27011-8.1 User Endpoint Devices

ISO/IEC 27043:2015 · 1 control

  • ISO27043-14 Privileged access management

ISO/IEC 27400:2022 · 1 control

  • 27400-6.1 Secure Device Design

ISO/SAE 21434 · 1 control

  • ISO21434-14 Privileged access management

MARS-E · 1 control

  • MDS2-PHI-Data-Handling-DATA-Storage-STCF-Transmission-TXCF-TXIG-Encryption-FIPS MDS2 PHI Handling + DATA + STCF Storage + TXCF Transmission + TXIG Integrity + Encryption + FIPS

MITRE ATT&CK · 1 control

MTCS (Singapore) · 1 control

  • MTCS-Asset-IAM-Cryptography-Multi-Tier-Asset-Inventory-RBAC-MFA-PAM-FIPS-HSM-Quantum-Safe MTCS Asset Mgmt + IAM + Cryptography + Asset Inventory + RBAC + MFA + PAM + FIPS + HSM + Quantum-Safe
  • NAIC-6 Cybersecurity Event Investigation and Notification - Sections 6 and 7
  • NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material

NIST SP 800-123 · 1 control

  • NISTSP123-3 Authentication, Access Control, and Account Management

NIST SP 800-137 · 1 control

  • NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring

NIST SP 800-144 · 1 control

  • NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation

NIST SP 800-145 · 1 control

  • NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition

NIST SP 800-146 · 1 control

  • NISTSP61-5 Containment, Eradication, and Recovery

NIST SP 800-63-4 · 1 control

  • NISTSP63R4-3 Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators

NIST SP 800-66 · 1 control

  • NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication
  • NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access

NIST SP 800-88 · 1 control

  • NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework

NIST SP 800-92 · 1 control

  • NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control
  • ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul

OWASP MASVS · 1 control

OWASP SAMM · 1 control

  • OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture
  • OMANCS-3 Identity and Access Management, Authentication, Privileged Access

OpenSSF Scorecard · 1 control

  • OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns

South Korea ISMS-P · 1 control

  • ISMSP-AC-01 Access Control Policy
  • ACE-CR-4 Cargo Release Authorization

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 52 it maps to, and the evidence behind each claim, over MCP and REST.