Security Baseline36 controls·
Web Application & API Security Baseline
A comprehensive set of foundational security controls required across a web application and API surface: secure development and dependency management, authentication and session management, authorization (IDOR/BOLA), input validation and injection defense (SQLi/XSS/SSRF/deserialization), API hardening, transport/configuration hardening, and security logging. Framework: OWASP ASVS 5.0; specific items are compiled from OWASP Top 10, API Security Top 10, and NIST SSDF.
Beta
This section is not open yet
Titles and summaries are free. The detail of this section is not published yet. You can request the offline comparison tool for the open environments with a company email.
If you have access, sign in to unlock.
Sign in →