OWASP projects such as the Application Security Verification Standard (ASVS) and the OWASP Top 10 have provided strong guidance for traditional software and web applications. However, modern games introduce additional challenges that require more domain-specific guidance. Games are no longer simple standalone applications. They are complex ecosystems that may include multiplayer services, live operations, player accounts, social systems, virtual economies, game clients, launchers, backend APIs, and third-party integrations. These environments pose unique security risks, including cheating, account compromise, fraud, abuse, service disruption, and gameplay integrity.
The mission of OGSF is to provide a technical, practical, and verifiable security framework for building and maintaining secure games. It is intended to support security throughout the game development lifecycle and to help teams move from general security advice to specific, testable requirements.
OGSF is designed to be useful for multiple stakeholders across the game development lifecycle:
Architects and designers can use it to build security into core game architecture, trust boundaries, and game systems.
Developers can use it as a secure development and implementation reference.
Security testers and assessors can use it as a structured verification and testing guide.
Studios, publishers, and service providers can use it as a measurable standard for security posture, internal baselines, and third-party expectations.
OGSF follows a three-level verification model, inspired by the ASVS, so teams can apply a level of rigor that matches the risk profile of their game:
Level 1 provides a baseline for all games, including offline and single-player titles with limited online features.
Level 2 is intended for most online and multiplayer games, especially games with player accounts, online features, or in-game purchases.
Level 3 is designed for games that require the highest degree of assurance, such as titles with high-value virtual economies, major competitive integrity requirements, sensitive player data, or significant financial exposure.
OGSF focuses on game product security. This includes areas such as:
secure game architecture and design
identity and access management
game client security
server and network security
in-game systems security
anti-cheat and runtime protection
data protection and privacy
The framework is intended to address both traditional application security concerns and game-specific concerns, such as authoritative server design, client trust boundaries, gameplay manipulation, economic abuse, botting, runtime tampering, and multiplayer fairness.
OGSF is not a replacement for other OWASP standards. It is a domain-specific framework that builds on them. In particular, it is structurally aligned with the OWASP ASVS, should be used alongside MASVS for mobile games where relevant, and complements the OWASP Top 10 and OWASP API Security Top 10 for web and API-driven game services.
In games, security is not only about confidentiality and availability. It is also about fairness, trust, integrity, resilience, and protecting player experience. A single weakness can affect competitive balance, player confidence, virtual economies, or platform reputation. OGSF exists to help the industry create a common, practical, and testable approach to securing games and their supporting systems.
The OWASP Game Security Framework is a community-driven project. Contributions, peer review, use cases, and feedback are welcome from game developers, security engineers, testers, researchers, and publishers who want to improve security in the game industry.
Recognizing key contributors who have made significant impact on this project.