About this Framework
The OWASP Application Security Verification Standard (ASVS) v4.0 provides a basis for testing web application technical security controls and a list of requirements for secure development. Three verification levels address escalating risk: L1 (minimum for all web apps — opportunistic attacker), L2 (most business applications — skilled attacker) and L3 (most critical assets — advanced targeted attacker). ASVS covers authentication, session management, access control, input validation, cryptography, API security and business logic — used globally as a specification, design standard and procurement requirement.
Key Control Domains
Who Needs This?
- Web application developers and security engineers
- Application security teams conducting code and architecture reviews
- Software development companies building secure web products
- Penetration testers assessing web application security
- Software procurement teams specifying vendor security requirements
Compliance Benefits
- Free, open standard with immediate applicability across web technologies
- Widely referenced in security assessments, pen tests and bug bounties
- Three verification tiers accommodate all organisational risk profiles
- Maps to NIST SSDF, ISO 27001 Annex A.14 and PCI DSS Requirement 6
Official Reference
Assessment Details
Share this Assessment
Share this permanent link with your team, clients or auditors.
https://grcopilot.app/frameworks/owasp-application-security-verification-standard-asvs