OWASP Integration Standards

The goal of the Integration Standards project is to facilitate technical interaction between software security initiatives inside OWASP and outside: links between documents and exchange between tools. More interaction reduces fragmentation and complexity of the standard landscape which has been making it hard for developers, testers, and procurement to set and apply appropriate standards and attain a shared understanding.

This project produced three results:

  • The Open Common Requirement Enumeration or OpenCRE: a revolutionary mechanism to link standards and guidelines together on multiple levels of topics, providing a harmonized resource for requirements, testing strategies, tool rules, countermeasures, and links to existing repositories of threats and weaknesses. OpenCRE is live at opencre.org. Where all standards come together.
  • The Security wayfinder (see below): an interactive overview of OWASP projects and how they are related
  • A study of OWASP in the SDLC (see report)

The Security wayfinder

We mapped OWASP projects in a diagram of the Software Development LifeCycle, summarized in the interactive WayFinder below, which is featured on multiple key locations on the OWASP website:

Requirements
Design
Docs
Implementation
Guides
After N Iterations
Verification
Metrics
Training/Education
Iterate
Culture Building & Process Maturing
Guides
Policy Gap Evaluation
Tools
Frameworks
Threat Modeling
CheatSheet Series
Proactive Controls
Go SCP
ZAP
Amass
Nettacker
OWTF
Secure
Libraries
Dependency Track
Dependency Check
ESAPI
CSRFGuard
Vulnerability
Management
Glue
Dracon
Defect Dojo
ASVS
MASVS
Threat Dragon
Threat Modeling Talks
PyTM
Security Champions Playbook
SAMM
Code Pulse
Operation
Mod Security CRS
Cornucopia
SecurityRAT
Top 10
Juice Shop
Security Shepherd
API Top 10
Mobile Top 10
WebGoat
PyGoat
Snakes & Ladders
WSTG
MSTG
SAMM
ASVS
MASVS
ASVS
MASVS
SKF
Application Security Wayfinder
Brought to you by the Integration standards project
Linking requirements and guidance across standards through the Common Requirement Enumeration.
Dependencies
secureCodeBox