OWASP / ASVS

Application Security Verification Standard
Creative Commons Attribution Share Alike 4.0 International
2.77k stars 671 forks source link

recommendations chapter #1801

Closed elarlang closed 10 months ago

elarlang commented 12 months ago

Things that are processes and out of the scope of ASVS:

Things that can not be required, but can be recommended:

tghosth commented 11 months ago

I like this concept, I think it is good for the sorts of things that would be considered as valid ASVS requirements but do not have a strong enough security case to be compulsory.

Another example could be password strength meters.

I don't think that this list should include things which are out of scope by nature such as processes (threat modeling), things not in the control of developers (backup/CICD).

tghosth commented 10 months ago

Added to PR #1838

tghosth commented 10 months ago

I am going to close this but we should bear it in mind for future changes