2/ We've done a bunch this year with CIS 20 and NIST CSF. I'm finding both very helpful in organizing my thinking around security controls in our org, and how we plan and prioritize or roadmap.
1
1
3/ However, these seem to focus on Enterprise Security, and don't account very well, for example, for the work our Product Security teams do. Almost all of what they work on (AuthN, AuthZ, encryption, input/output scrubbing, etc.) doesn't map very well onto CIS or NIST.
1
2
4/ The best we seem to have for Prod Sec or App Sec, as far as security frameworks, are OWASP Top 10 and CWE. But these strike me as lists of threats to mitigate, rather than lists of controls/countermeasures to deploy.
1
3
5/ Do we need to combine OWASP Top 10, CWE 25 (others?), invert them to create the superset of relevant countermeasures, and organize them into a comprehensive Application Security controls framework?
5
3
You're correct in that OWASP top 10 is a list of prevalent threats. But OWASP also has numerous other docs. The OWASP secure coding checklist is probably what you're looking for. owasp.org/index.php/OWASP_Se…
1
NIST 800-53 is a near comprehensive collection of all security controls. However, you're right that it doesn't spell out exactly how to handle those controls from an appsec perspective.
1
Hey @bsterne have you looked at the product (web) security requirements in the ASVS 4.0 standard, or the mobile security MASVS standard? I believe these requirements are what you are looking for.
1
1
Hey, Jim! Indeed, @bilcorry pointed me to ASVS last night, and that looks pretty close to what I'm looking for. Thanks for replying.
1
2
It’s awesome that resources such as ASVS exist, and that there’s a friendly community of us that share this knowledge, and all of it is free. I’m personally grateful and thankful.

Sep 27, 2019 · 3:06 PM UTC

1
2
Thank @vanderaj @JoshCGrossman and @dcuthbert 🤙🏼 for all of their hard work on ASVS
1
6