OWASP Application Security Verification Standard (ASVS)

Application Security Requirements and Verification Standard

What is the OWASP Application Security Verification Standard (ASVS)?

The OWASP Application Security Verification Standard (ASVS) is an open standard for defining and verifying technical security requirements for web applications and services. Maintained by OWASP, stable version 5.0.0 organizes testable requirements across areas such as architecture, authentication, access control, cryptography, secure communications, data protection, and API security. It offers three assurance levels so organizations can match verification depth to application risk, while requiring documented security decisions where requirements do not apply.

Unlike the OWASP Top 10, which communicates common web application risks, ASVS provides detailed requirements that can serve as a security control and measurable acceptance criteria. It is voluntary guidance, not a certification or automatic proof of regulatory compliance.

What is the OWASP Application Security Verification Standard (ASVS) used for?

Organizations use ASVS across the SDLC to translate policy and threat models into development requirements, architecture reviews, test cases, security control validation, and release gates. Product owners and procurement teams can reference versioned ASVS requirements in contracts and supplier assurance, reducing ambiguity about what secure software means.

Verification teams may use ASVS to scope code review, automated testing, or a web application penetration test; the OWASP Web Security Testing Guide offers complementary testing methodology. The selected assurance level and requirements should reflect data sensitivity, exposure, threat context, and business impact. ASVS does not replace secure design, risk assessment, or skilled testing; instead, it creates common, traceable criteria for developers, assessors, and governance stakeholders.

Continue reading

NIST SP 800-160
Systems Security Engineering Framework Guide
NIST SP 800-53
Enterprise Security Controls Framework Reference
INCOSE Systems Engineering Handbook
Systems Engineering Body of Knowledge

Please note!
Any use of this website requires prior agreement to our Terms of Use, Privacy Policy, and Cookie Policy.
If you do not fully agree to all of them, do not use this website.