What has changed in OWASP TOP Ten 2010?

04 June 2010 11:23 am , Jaykishan Nirmal

Sponsored By: Aujas

It is almost 8 years now, since OWASP has become the de-facto standard for developers, architects and designers to develop secure applications. Security Professionals use OWASP testing guide as a bible to ensure a comprehensive assessment. This article highlights some of the key changes derived from the 22 pages of OWASP TOP Ten 2010 release document.

Highlights from OWASP TOP TEN 2010

On 19th April 2010 OWASP Top Ten 2010 release, Dave Wichers (OWASP Board Member and COO Aspect Security) who has managed the OWASP project since inception, says “This year we have revamped the Top 10 to make it clear that we are talking about Risks, not just Vulnerabilities. Attempts to prioritize vulnerabilities without context just don’t make sense. You cannot make proper business decisions without understanding the threat and its impact to your business”

 

 

These are Risks, not just Vulnerabilities!

OWASP Top Ten always wanted to emphasize on risks rather than listing the most common vulnerabilities. This time it is clearly highlighted in the document that how threat agents, attack vectors, weaknesses, lack of security controls, technical and business impact can help understand the risk for the organization. The following diagram depicts how the overall risk should be determined



Related Content
Readers Feedback