Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

OWASP Top 10 2021 Peer Review

30 min17 september 2021

Om avsnittet

Chris and Robert conduct a practitioner peer review of the 2021 OWASP Top 10, examining what changed, what moved, and what the new structure communicates to development teams. They compare the list with the 2017 edition, discuss the broader treatment of injection, and unpack additions such as insecure design, software and data integrity failures, and server-side request forgery. The review also questions how categories map to real weaknesses, CVEs, and verification practices. Along the way, they connect the Top 10 to ASVS, threat modeling, dependency analysis, and the difficult balance between a widely recognized awareness document and actionable engineering guidance.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with OWASP:
OWASP Top 10
OWASP Foundation

Mentioned in this episode:
OWASP Top 10:2021
OWASP ASVS
Threat Modeling Manifesto
OWASP Dependency-Check
CycloneDX

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Peer reviewing the OWASP Top 10:2021
03:00 Broken access control moves to number one
04:52 Injection and cross-site scripting are consolidated
07:46 Vulnerable and outdated components
10:50 Software and data integrity failures
12:42 Server-side request forgery joins the list
15:00 Does the new structure help practitioners?
18:00 Security logging and monitoring
20:00 Mapping categories to weaknesses and CVEs
21:52 Connecting the Top 10 to verification practices
27:00 Final observations

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.