OWASP ASVS
OWASP Application Security Verification Standard
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
OWASP content is used under the Creative Commons Attribution-ShareAlike 4.0 International License (CC BY-SA 4.0). Original material © OWASP Foundation. See owasp.org for the authoritative source.
Framework Domains (21)
API Security
| Code | Title |
|---|---|
| ASVS-V13 | API and Web Service Verification Requirements |
Architecture
| Code | Title |
|---|---|
| ASVS-V1 | Architecture, Design and Threat Modelling |
Authentication
| Code | Title |
|---|---|
| ASVS-V2 | Authentication Verification Requirements |
| ASVS-V2.4 | Credential Storage Requirements |
Authorization
| Code | Title |
|---|---|
| ASVS-V4 | Access Control Verification Requirements |
| ASVS-V4.3 | Other Access Control Considerations |
Business Logic
| Code | Title |
|---|---|
| ASVS-V11 | Business Logic Verification Requirements |
Communications
| Code | Title |
|---|---|
| ASVS-V9 | Communication Verification Requirements |
Configuration
| Code | Title |
|---|---|
| ASVS-V14 | Configuration Verification Requirements |
Cryptography
| Code | Title |
|---|---|
| ASVS-V6 | Stored Cryptography Verification Requirements |
Data Protection
| Code | Title |
|---|---|
| ASVS-V8 | Data Protection Verification Requirements |
| ASVS-V8.3 | Sensitive Private Data Protection |
File Handling
| Code | Title |
|---|---|
| ASVS-V12 | File and Resources Verification Requirements |
Input Validation
| Code | Title |
|---|---|
| ASVS-V5 | Validation, Sanitization and Encoding |
Logging
| Code | Title |
|---|---|
| ASVS-V7 | Error Handling and Logging |
Malicious Code
| Code | Title |
|---|---|
| ASVS-V10 | Malicious Code Verification Requirements |
OWASP ASVS: Access Control
Logical and physical access controls (OWASP ASVS)
| Code | Title |
|---|---|
| ASVS-11 | Access control policy and enforcement |
| ASVS-12 | User access management and provisioning |
| ASVS-13 | Authentication and password management |
| ASVS-14 | Privileged access management |
| ASVS-15 | Access review and recertification |
OWASP ASVS: Asset Management
Information asset management (OWASP ASVS)
| Code | Title |
|---|---|
| ASVS-06 | Asset inventory and ownership |
| ASVS-07 | Acceptable use of assets |
| ASVS-08 | Information classification and labeling |
| ASVS-09 | Asset handling procedures |
| ASVS-10 | Media management and disposal |
OWASP ASVS: Communications Security
Network and communications security (OWASP ASVS)
| Code | Title |
|---|---|
| ASVS-27 | Network security management |
| ASVS-28 | Network service security |
| ASVS-29 | Segregation in networks |
| ASVS-30 | Information transfer policies |
| ASVS-31 | Secure messaging |
OWASP ASVS: Cryptography
Cryptographic controls (OWASP ASVS)
| Code | Title |
|---|---|
| ASVS-16 | Cryptographic policy and key management |
| ASVS-17 | Encryption of data at rest |
| ASVS-18 | Encryption of data in transit |
| ASVS-19 | Certificate management |
| ASVS-20 | Key lifecycle management |
OWASP ASVS: Information Security Policies
Organizational information security policies (OWASP ASVS)
| Code | Title |
|---|---|
| ASVS-01 | Information security policy framework |
| ASVS-02 | Management direction and commitment |
| ASVS-03 | Policy review and update procedures |
| ASVS-04 | Roles and responsibilities definition |
| ASVS-05 | Contact with authorities and special interest groups |
OWASP ASVS: Operations Security
Secure operations and monitoring (OWASP ASVS)
| Code | Title |
|---|---|
| ASVS-21 | Operational procedures and responsibilities |
| ASVS-22 | Protection from malware |
| ASVS-23 | Backup and recovery procedures |
| ASVS-24 | Logging and monitoring |
| ASVS-25 | Technical vulnerability management |
| ASVS-26 | Audit considerations |
Output Encoding
| Code | Title |
|---|---|
| ASVS-V5.3 | Output Encoding and Injection Prevention |
Session Management
| Code | Title |
|---|---|
| ASVS-V3 | Session Management Verification Requirements |
Your Compliance Coverage
If you comply with OWASP ASVS, you already cover:
3GPP Security
35%
17 controls mapped
Compare →ISO 27002:2022
35%
17 controls mapped
Compare →OpenSSF Scorecard
35%
17 controls mapped
Compare →+ 607 more: MITRE D3FEND (35%), OWASP SAMM (35%)
See all 610 mapped frameworks ↓Maps to 610 other frameworks
Frequently Asked Questions
What is OWASP ASVS?
OWASP ASVS is a compliance framework from International with 21 domains and 49 controls. OWASP Application Security Verification Standard It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does OWASP ASVS have?
OWASP ASVS has 49 controls organised across 21 domains. The largest domains are OWASP ASVS: Operations Security (6 controls), OWASP ASVS: Access Control (5 controls), OWASP ASVS: Asset Management (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does OWASP ASVS map to?
OWASP ASVS maps to 610 other compliance frameworks. The top mapping partners are 3GPP Security (35% coverage), ISO 27002:2022 (35% coverage), OpenSSF Scorecard (35% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with OWASP ASVS compliance?
Start your OWASP ASVS compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about OWASP ASVS requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 49 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required