Info Security Memo
  • Blog
  • Sitemap
    • Categories
  • Contact
  • About
  • Resources
  • Tools
  • 51sec.org

Build Confidence

Focusing on Information Security 

Info Security Notes

OWASP Top 10 (2010 2013 20172021)

10/11/2021

0 Comments

 
OWASP Top 10 (2010, 2013, 2017,2021)
The Open Web Application Security Project (OWASP) is a non-profit organization dedicated to providing unbiased, practical information about application security. 
The OWASP Top 10 Web Application Security Risks was created  in 2010, 2013, 2017 and 2021 to provide guidance to developers and security professionals on the most critical vulnerabilities that are commonly found in web applications, which are also easy to exploit. These 10 application risks are dangerous because they may allow attackers to plant malware, steal data, or completely take over your computers or web servers.
Meeting OWASP Compliance Standards usually is the First Step Toward Secure Code.



2021

  1. A01:2021-Broken Access Control
  2. A02:2021-Cryptographic Failures
  3. A03:2021-Injection
  4. A04:2021-Insecure Design
  5. A05:2021-Security Misconfiguration
  6. A06:2021-Vulnerable and Outdated Components
  7. A07:2021-Identification and Authentication Failures
  8. A08:2021-Software and Data Integrity Failures
  9. A09:2021-Security Logging and Monitoring Failures
  10. A10:2021-Server-Side Request Forgery (SSRF)




                  The OWASP Top 10 Proactive Controls 
                  1. Define Security Requirements
                  2. Leverage Security Frameworks and Libraries
                  3. Secure Database Access
                  4. Encode and Escape Data
                  5. Validate All Inputs
                  6. Implement Digital Identity
                  7. Enforce Access Controls
                  8. Protect Data Everywhere
                  9. Implement Security Logging and Monitoring
                  10. Handle All Errors and Exceptions
                  (From OWASP Proactive Controls for Developers 2018 v3.0)

                  2017 


                  OWASP Top 10 Application Security Risks - 2017

                  1. A1. Injection
                  2. A2. Broken Authentication
                  3. A3. Sensitive Data Exposure
                  4. A4. XML External Entities (NEW)
                  5. A5. Broken Access Control (MERGED)
                  6. A6. Security Misconfiguration
                  7. A7. Cross-Site Scripting
                  8. A8. Insecure Deserialization (NEW)
                  9. A9. Using Components With Known Vulnerabilities
                  10. A10. Insufficient Logging and Monitoring (NEW)





                  2013


                  1. A1-Injection
                  2. A2-Broken Authentication and Session Management
                  3. A3-Cross-Site Scripting (XSS)
                  4. A4-Insecure Direct Object References
                  5. A5-Security Misconfiguration
                  6. A6-Sensitive Data Exposure
                  7. A7-Missing Function Level Access Control
                  8. A8-Cross-Site Request Forgery (CSRF)
                  9. A9-Using Components with Known Vulnerabilities
                  10. A10-Unvalidated Redirects and Forwards




                  2010


                  For 2010, the OWASP Top 10 Most Critical Web Application Security Risks are:
                  1. A1: Injection
                  2. A2: Cross-Site Scripting (XSS)
                  3. A3: Broken Authentication and Session Management
                  4. A4: Insecure Direct Object References
                  5. A5: Cross-Site Request Forgery (CSRF)
                  6. A6: Security Misconfiguration
                  7. A7: Insecure Cryptographic Storage
                  8. A8: Failure to Restrict URL Access
                  9. A9: Insufficient Transport Layer Protection
                  10. A10: Unvalidated Redirects and Forwards





                  References:

                  OWASP

                  ·         OWASP Risk Rating Methodology

                  ·         Article on Threat/Risk Modeling

                  External

                  ·         ISO 31000: Risk Management Std

                  ·         ISO 27001: ISMS

                  ·         NIST Cyber Framework (US)

                  ·         ASD Strategic Mitigations (AU)

                  ·         NIST CVSS 3.0

                  ·         Microsoft Threat Modelling Tool















                  via Blogger http://blog.51sec.org/2018/02/owasp-top-10-2010-2013-2017.html
                  October 11, 2021 at 10:22AM Architecture
                  0 Comments



                  Leave a Reply.

                    Categories

                    All
                    Architecture
                    Blog
                    Checkpoint
                    Cisco
                    Cloud
                    CyberArk
                    F5
                    Fortigate
                    Guardium
                    Juniper
                    Linux
                    Network
                    Others
                    Palo Alto
                    Qualys
                    Raspberry Pi
                    Security
                    SIEM
                    Software
                    Vmware
                    VPN
                    Wireless

                    Archives

                    March 2024
                    February 2024
                    January 2024
                    December 2023
                    November 2023
                    October 2023
                    September 2023
                    August 2023
                    July 2023
                    June 2023
                    May 2023
                    April 2023
                    March 2023
                    February 2023
                    January 2023
                    December 2022
                    November 2022
                    October 2022
                    September 2022
                    August 2022
                    July 2022
                    June 2022
                    May 2022
                    April 2022
                    March 2022
                    February 2022
                    January 2022
                    December 2021
                    November 2021
                    October 2021
                    September 2021
                    August 2021
                    July 2021
                    June 2021
                    May 2021
                    April 2021
                    March 2021
                    February 2021
                    January 2021
                    December 2020
                    November 2020
                    October 2020
                    September 2020
                    August 2020
                    July 2020
                    October 2019
                    September 2019
                    June 2019
                    July 2018
                    May 2018
                    December 2017
                    August 2017
                    April 2017
                    March 2017
                    January 2017
                    December 2016
                    November 2016
                    October 2016
                    September 2016
                    August 2016
                    July 2016
                    June 2016
                    May 2016
                    April 2016
                    March 2016
                    February 2016
                    January 2016
                    December 2015
                    November 2015
                    October 2015
                    September 2015
                    August 2015
                    July 2015
                    June 2015
                    May 2015
                    April 2015
                    March 2015

                    Print Page:

                    RSS Feed

                    Email Subscribe
                  Powered by Create your own unique website with customizable templates.
                  • Blog
                  • Sitemap
                    • Categories
                  • Contact
                  • About
                  • Resources
                  • Tools
                  • 51sec.org