Web Security Standards
OWASP (Open Web Application Security Project) provides guidelines to improve software security.
1. Broken Access Control 2. Cryptographic Failures 3. Injection 4. Insecure Design 5. Security Misconfiguration 6. Vulnerable Components 7. Authentication Failures 8. Software Integrity Failures 9. Logging & Monitoring Failures 10. Server-Side Request Forgery (SSRF)
Injection → SQL/XSS attacks Auth Failure → Weak login system Misconfiguration → Open ports/settings
- Validate inputs - Use HTTPS - Secure authentication - Update software
OWASP ZAP → Security testing Dependency Check → Library scan WebGoat → Practice app
Used by companies Industry standard Improves security