OWASP has officially released Version 5.0 of the Application Security Verification Standard (ASVS), marking the most substantial revision in its history.
Originally launched in 2008 (and updated in 2019 and 2021), the ASVS is a valuable resource for development teams and security professionals alike. It defines a comprehensive set of approximately 350 security requirements across 17 categories for designing, developing, and testing modern web applications and services, covering areas such as authentication, file handling, error management, cryptography, and injection prevention.
ASVS Version 5.0 represents a comprehensive restructure of the standard, featuring a revised layout, refined requirements and the introduction of entirely new components. These updates enhance its clarity and usability, and better reflect how modern applications are built, deployed, maintained and security tested.
Instead of acting as a static checklist, the ASVS is intended to provide a structured, measurable framework, whilst offering the flexibility to adapt and employ the standard based on the application security maturity, the functionality of the application and the sensitivity of the data being handled.
For more information visit: https://www.intertek.com/iot/cybersecurity/apps-pci-payments/