OWASP
Page Module:Message box/ambox.css has no content.
Page Module:Infobox/styles.css has no content.
| Lua error in package.lua at line 80: module 'Module:InfoboxImage/data' not found. | |
| Script error: No such module "Infobox mapframe". | |
| Founded | 2001[1] |
|---|---|
| Founders | Mark Curphey[1] |
| Type | 501(c)(3) nonprofit organization |
| Purpose | Web security, application security, vulnerability assessment |
| Method | Industry standards, conferences, workshops |
| Members | approx. 13,000 volunteers (2017)[2] |
Key people | Andrew van der Stock, Executive Director; Kelly Santalucia, Director of Events and Corporate Support; Harold Blankenship, Director of Technology and Projects; Jason C. McDonald, Director of Community Development; Dawn Aitken, Operations Manager; Lauren Thomas, Event Coordinator[3] |
| Revenue | |
| Website | owasp |
Script error: No such module "Check for conflicting parameters".
OWASP, the Open Worldwide Application Security Project (formerly Open Web Application Security Project), is an online community that publishes open-source information and resources on IoT, system software and web application security.[5] It is led by a non-profit called The OWASP Foundation.
History
Mark Curphey started OWASP on September 9, 2001.[1] Jeff Williams served as the volunteer Chair of OWASP from late 2003 until September 2011. As of 2015[update], Matt Konda chaired the Board.[6] The OWASP Foundation, a 501(c)(3) non-profit organization in the US established in 2004, supports the OWASP infrastructure and projects. Since 2011, OWASP is also registered as a non-profit organization in Belgium under the name of OWASP Europe VZW.[7] In February 2023, it was reported by Bil Corry, a OWASP Foundation Global Board of Directors officer,[8] on Twitter that the board had voted for renaming from the Open Web Application Security Project to its current name, replacing Web with Worldwide.[9] In May 2023, the OWASP Gen AI Security Project was started to expand the scope of the OWASP Top 10 List to document the most critical risks associated with LLMs. [10]
Resources
Tools
- OWASP ZAP: a penetration testing tool.
- Webgoat: a deliberately insecure web application created by OWASP as a guide for secure programming practices.[1]
Publications
- OWASP Top Ten
- The "Top Ten", first published in 2003, is an annual listing of critical application security risks.[11][12][13][14][15] Many standards, books, tools, and many organizations reference the Top 10 project, including MITRE, PCI DSS,[16] the Defense Information Systems Agency (DISA-STIG), and the United States Federal Trade Commission.[17][18]
- OWASP Development Guide
- OWASP Testing Guide
- OWASP Code Review Guide
- OWASP Top 10 Incident Response Guidance.[19]
Models and standards
- OWASP Software Assurance Maturity Model[20]
- OWASP Application Security Verification Standard (ASVS): A standard for performing application-level security verifications.[21]
Other projects
- OWASP XML Security Gateway (XSG) Evaluation Criteria Project.[22]
- OWASP AppSec Pipeline[23]
- OWASP Automated Threats to Web Applications[24][25]
- OWASP API Security Project[26]
- OWASP AI Maturity Assessment Project (AIMA)[27]
Certifications
OWASP offers several professional security certifications focused on web application security, including the OWASP Top 10 certification which validates knowledge of the most critical web application security risks, the OWASP Application Security Verification Standard (ASVS) certification for secure coding practices, the OWASP Software Assurance Maturity Model (SAMM) certification for organizational security maturity assessment, and the OWASP Security Knowledge Framework (SKF) certification for security awareness training. These certifications help professionals demonstrate expertise in secure development, testing, and application security management across different organizational roles and technical disciplines.[28][29][30][31]
See also
References
Page Template:Reflist/styles.css has no content.
- ^ a b c d Page Module:Citation/CS1/styles.css has no content.Huseby, Sverre (2004). Innocent Code: A Security Wake-Up Call for Web Programmers. Wiley. p. 203. ISBN 0470857447.
- ^ Page Module:Citation/CS1/styles.css has no content."OWASP Foundation's Form 990 for fiscal year ending Dec. 2017". October 26, 2018. Retrieved January 8, 2020 – via ProPublica Nonprofit Explorer.
- ^ Page Module:Citation/CS1/styles.css has no content."OWASP Foundation Staff". OWASP. February 12, 2023. Retrieved May 3, 2022.
- ^ Page Module:Citation/CS1/styles.css has no content."OWASP FOUNDATION INC". Nonprofit Explorer. ProPublica. May 9, 2013. Retrieved January 8, 2020.
- ^ Page Module:Citation/CS1/styles.css has no content."OWASP Internet of Things". Retrieved December 26, 2023.
- ^ Page Module:Citation/CS1/styles.css has no content."Board". OWASP. Archived from the original on September 16, 2017. Retrieved February 27, 2015.
- ^ Page Module:Citation/CS1/styles.css has no content."OWASP Europe". OWASP. Archived from the original on April 17, 2016. Retrieved July 7, 2024.
- ^ Page Module:Citation/CS1/styles.css has no content."Global Board". owasp.org. Archived from the original on April 29, 2024. Retrieved July 7, 2024.
- ^ Script error: No such module "cite tweet".
- ^ Page Module:Citation/CS1/styles.css has no content."Introduction, Project Background - OWASP Gen AI Security Project". OWASP GenAI Security Project. Retrieved January 10, 2026.
{{cite web}}: CS1 maint: url-status (link) - ^ Page Module:Citation/CS1/styles.css has no content."OWASP Top Ten". owasp.org. Archived from the original on July 6, 2024. Retrieved July 7, 2024.
- ^ Page Module:Citation/CS1/styles.css has no content.Trevathan, Matt (October 1, 2015). "Seven Best Practices for Internet of Things". Database and Network Journal. Archived from the original on November 28, 2015.
- ^ Page Module:Citation/CS1/styles.css has no content.Crosman, Penny (July 24, 2015). "Leaky Bank Websites Let Clickjacking, Other Threats Seep In". American Banker. Archived from the original on November 28, 2015.
- ^ Page Module:Citation/CS1/styles.css has no content.Pauli, Darren (December 4, 2015). "Infosec bods rate app languages; find Java 'king', put PHP in bin". The Register. Retrieved December 4, 2015.
- ^ Page Module:Citation/CS1/styles.css has no content."OWASP top 10 vulnerabilities". developerWorks. IBM. April 20, 2015. Retrieved November 28, 2015.
- ^ Page Module:Citation/CS1/styles.css has no content."Payment Card Industry (PCI) Data Security Standard" (PDF). PCI Security Standards Council. November 2013. p. 55. Retrieved December 3, 2015.
- ^
Page Module:Citation/CS1/styles.css has no content."Open Web Application Security Project Top 10 (OWASP Top 10)". Knowledge Database. Synopsys. Synopsys, Inc. 2017. Retrieved July 20, 2017.
Many entities including the PCI Security Standards Council, National Institute of Standards and Technology (NIST), and the Federal Trade Commission (FTC) regularly reference the OWASP Top 10 as an integral guide for mitigating Web application vulnerabilities and meeting compliance initiatives.
- ^ Page Module:Citation/CS1/styles.css has no content."Authorization remains #1 issue – OWASP 2023 Top 10 List". Cerbos. Retrieved September 2, 2024.
- ^ Page Module:Citation/CS1/styles.css has no content."OWASP Incident Response Project – OWASP". Archived from the original on April 6, 2019. Retrieved December 12, 2015.
- ^ Page Module:Citation/CS1/styles.css has no content."What is OWASP SAMM?". OWASP SAMM. Retrieved November 6, 2022.
- ^ Page Module:Citation/CS1/styles.css has no content.Baar, Hans; Smulters, Andre; Hintzbergen, Juls; Hintzbergen, Kees (2015). Foundations of Information Security Based on ISO27001 and ISO27002 (3 ed.). Van Haren. p. 144. ISBN 9789401800129.
- ^ Page Module:Citation/CS1/styles.css has no content."Category:OWASP XML Security Gateway Evaluation Criteria Project Latest". Owasp.org. Archived from the original on November 3, 2014. Retrieved November 3, 2014.
- ^ Page Module:Citation/CS1/styles.css has no content."OWASP AppSec Pipeline". Open Web Application Security Project (OWASP). Archived from the original on January 18, 2020. Retrieved February 26, 2017.
- ^ Page Module:Citation/CS1/styles.css has no content."AUTOMATED THREATS to Web applications" (PDF). OWASP. July 2015.
- ^ Page Module:Citation/CS1/styles.css has no content."OWASP Automated Threats to Web Applications". owasp.org. Archived from the original on June 29, 2024. Retrieved July 7, 2024.
- ^ Page Module:Citation/CS1/styles.css has no content."OWASP API Security Project – OWASP Foundation". OWASP.
- ^ Page Module:Citation/CS1/styles.css has no content."OWASP AI Maturity Assessment Project – OWASP Foundation". OWASP.
- ^ Page Module:Citation/CS1/styles.css has no content."qa.com | Certified OWASP Security Fundamentals (QAOWASPF)". www.qa.com. Retrieved October 25, 2024.
- ^ Page Module:Citation/CS1/styles.css has no content."A01 Broken Access Control – OWASP Top 10:2021". owasp.org. Retrieved October 25, 2024.
- ^ Page Module:Citation/CS1/styles.css has no content."A02 Cryptographic Failures – OWASP Top 10:2021". owasp.org. Retrieved October 25, 2024.
- ^ Page Module:Citation/CS1/styles.css has no content."Assessment and Certification". scvs.owasp.org. Retrieved April 17, 2026.
External links
Lua error in package.lua at line 80: module 'Module:Authority control/config' not found.