
OWASP Top 10 2021 Peer Review
Om avsnittet
Chris and Robert conduct a practitioner peer review of the 2021 OWASP Top 10, examining what changed, what moved, and what the new structure communicates to development teams. They compare the list with the 2017 edition, discuss the broader treatment of injection, and unpack additions such as insecure design, software and data integrity failures, and server-side request forgery. The review also questions how categories map to real weaknesses, CVEs, and verification practices. Along the way, they connect the Top 10 to ASVS, threat modeling, dependency analysis, and the difficult balance between a widely recognized awareness document and actionable engineering guidance.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with OWASP:
→ OWASP Top 10
→ OWASP Foundation
Mentioned in this episode:
→ OWASP Top 10:2021
→ OWASP ASVS
→ Threat Modeling Manifesto
→ OWASP Dependency-Check
→ CycloneDX
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Peer reviewing the OWASP Top 10:2021
03:00 Broken access control moves to number one
04:52 Injection and cross-site scripting are consolidated
07:46 Vulnerable and outdated components
10:50 Software and data integrity failures
12:42 Server-side request forgery joins the list
15:00 Does the new structure help practitioners?
18:00 Security logging and monitoring
20:00 Mapping categories to weaknesses and CVEs
21:52 Connecting the Top 10 to verification practices
27:00 Final observations
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.