- Objective
- V1: Encoding and Sanitization
- V2: Validation and Business Logic
- V3: Web Frontend Security
- V4: API and Web Service
- V5: File Handling
- V6: Authentication
- V6.1 Authentication Documentation
- V6.2 Password Security
- V6.3 General Authentication Security
- V6.4 Authentication Factor Lifecycle and Recovery
- V6.5 General Multi-factor authentication requirements
- V6.6 Out-of-Band authentication mechanisms
- V6.7 Cryptographic authentication mechanism
- V6.8 Authentication with an Identity Provider
- V7: Session Management
- V8: Authorization
- V9: Self-contained Tokens
- V10: OAuth and OIDC
- V11: Cryptography
- V12: Secure Communication
- V13: Configuration
- V14: Data Protection
- V15: Secure Coding and Architecture
- V16: Security Logging and Error Handling
- V17: WebRTC
The objective of this index is to help an OWASP Application Security Verification Standard (ASVS) user clearly identify which cheat sheets are useful for each section during his or her usage of the ASVS.
This index is based on the version 5.0.x of the ASVS.
Cross Site Scripting Prevention Cheat Sheet
Cross Site Scripting Prevention Cheat Sheet
DOM based XSS Prevention Cheat Sheet
Injection Prevention Cheat Sheet
Query Parameterization Cheat Sheet
XSS Filter Evasion Cheat Sheet
XML External Entity Prevention Cheat Sheet
Cross-Site Request Forgery Prevention Cheat Sheet
Cross Site Scripting Prevention Cheat Sheet
DOM based XSS Prevention Cheat Sheet
Injection Prevention Cheat Sheet
Injection Prevention Cheat Sheet in Java
Server Side Request Forgery Prevention Cheat Sheet
XML External Entity Prevention Cheat Sheet
None.
Server Side Request Forgery Prevention Cheat Sheet
XML External Entity Prevention Cheat Sheet
Microservices Security Cheat Sheet
Web Service Security Cheat Sheet
Content Security Policy Cheat Sheet
Cross-Site Request Forgery Prevention Cheat Sheet
HTTP Strict Transport Security Cheat Sheet
Cross-Site Request Forgery Prevention Cheat Sheet
DOM Clobbering Prevention Cheat Sheet
Third Party Javascript Management Cheat Sheet
Cross-Site Request Forgery Prevention Cheat Sheet
Session Management Cheat Sheet
Transport Layer Security Cheat Sheet
Cross-Site Request Forgery Prevention Cheat Sheet
HTTP Strict Transport Security Cheat Sheet
Cross-Site Request Forgery Prevention Cheat Sheet
Third Party Javascript Management Cheat Sheet
Cross-Site Request Forgery Prevention Cheat Sheet
HTTP Strict Transport Security Cheat Sheet
Third Party Javascript Management Cheat Sheet
Unvalidated Redirects and Forwards Cheat Sheet
Cross-Site Request Forgery Prevention Cheat Sheet
Transport Layer Security Cheat Sheet
Web Service Security Cheat Sheet
Web Service Security Cheat Sheet
Transport Layer Security Cheat Sheet
Server Side Request Forgery Prevention Cheat Sheet
Credential Stuffing Prevention Cheat Sheet
Credential Stuffing Prevention Cheat Sheet
Choosing and Using Security Questions Cheat Sheet
Multifactor Authentication Cheat Sheet
Multifactor Authentication Cheat Sheet
Transaction Authorization Cheat Sheet
Multifactor Authentication Cheat Sheet
Multifactor Authentication Cheat Sheet
Session Management Cheat Sheet
Session Management Cheat Sheet
Session Management Cheat Sheet
Session Management Cheat Sheet
Session Management Cheat Sheet
Session Management Cheat Sheet
Session Management Cheat Sheet
Authorization Testing Automation
Insecure Direct Object Reference Prevention Cheat Sheet
Session Management Cheat Sheet
Transaction Authorization Cheat Sheet
Multi-Tenant Application Security Cheat Sheet
JSON Web Token Cheat Sheet for Java
Transport Layer Security Cheat Sheet
Transport Layer Security Cheat Sheet
Unvalidated Redirects and Forwards Cheat Sheet
Browser Extension Security Vulnerabilities
Cryptographic Storage Cheat Sheet
Cryptographic Storage Cheat Sheet
Cryptographic Storage Cheat Sheet
Cryptographic Storage Cheat Sheet
Transport Layer Security Cheat Sheet
Microservices Security Cheat Sheet
Secrets Management Cheat Sheet
Transport Layer Security Cheat Sheet
Transport Layer Security Cheat Sheet
Transport Layer Security Cheat Sheet
Server Side Request Forgery Prevention Cheat Sheet
Server Side Request Forgery Prevention Cheat Sheet
Cryptographic Storage Cheat Sheet
Cryptographic Storage Cheat Sheet
User Privacy Protection Cheat Sheet
User Privacy Protection Cheat Sheet
Attack Surface Analysis Cheat Sheet
Dependency Graph & SBOM Best Practices Cheat Sheet
Software Supply Chain Security
Third Party Javascript Management Cheat Sheet
Software Supply Chain Security
Third Party Javascript Management Cheat Sheet
Vulnerable Dependency Management Cheat Sheet
Prototype Pollution Prevention Cheat Sheet
Unvalidated Redirects and Forwards Cheat Sheet
Secure Code Review Cheat Sheet
Transaction Authorization Cheat Sheet
Logging Vocabulary Cheat Sheet
Session Management Cheat Sheet
Logging Vocabulary Cheat Sheet
None.
Transport Layer Security Cheat Sheet
None.