[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-173539-en":3,"doc-seo-173539-105":30,"detail-sidebar-cat-1-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":11,"category_id":12,"category_name":13,"doc_title":14,"doc_description":15,"doc_content":16,"file_id":17,"file_url":18,"file_type":19,"file_size":20,"view_count":4,"is_deleted":4,"is_public":11,"is_downloadable":11,"audit_status":11,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":15,"update_tm":28,"read_time":29},173539,687197100911,"Himbo","https://ap-avatar.wpscdn.com/avatar/a000239b6f1da00475?x-image-process=image/resize,m_fixed,w_180,h_180&k=1785132997149421697",1,158,"General","Application Security Verification Standard - 4.0.3 - November 2021","Application Security Verification Standard 4.0.3 defines a structured approach to assessing the security of applications through verification requirements and testing guidance. The standard explains how to apply ASVS across verification levels, from first steps and automated checks to high assurance use cases, and how to reference requirements during assessment and certification. It details architectural perspectives across areas such as authentication, session management, access control, input/output handling, cryptography, logging, privacy, and malicious software, with methods and additional uses to support secure development.","Application Security Verification Standard 4.0.3\nFinal\nOctober 2021\n\u0003Table of Contents\n\u0013TOC \\o \"1-3\" \\h \\z \\u\u0014\u0013 HYPERLINK \\l \"_Toc86348875\" \u0014Frontispiece\t\u0013 PAGEREF _Toc86348875 \\h \u00147\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc86348876\" \u0014About the Standard\t\u0013 PAGEREF _Toc86348876 \\h \u00147\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc86348877\" \u0014Copyright and License\t\u0013 PAGEREF _Toc86348877 \\h \u00147\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc86348878\" \u0014Project Leads\t\u0013 PAGEREF _Toc86348878 \\h \u00147\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc86348879\" \u0014Major Contributors\t\u0013 PAGEREF _Toc86348879 \\h \u00147\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc86348880\" \u0014Other Contributors and Reviewers\t\u0013 PAGEREF _Toc86348880 \\h \u00147\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc86348881\" \u0014Preface\t\u0013 PAGEREF _Toc86348881 \\h \u00149\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc86348882\" \u0014What's new in 4.0\t\u0013 PAGEREF _Toc86348882 \\h \u00149\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc86348883\" \u0014Using the ASVS\t\u0013 PAGEREF _Toc86348883 \\h \u001411\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc86348884\" \u0014Application Security Verification Levels\t\u0013 PAGEREF _Toc86348884 \\h \u001411\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc86348885\" \u0014How to use this standard\t\u0013 PAGEREF _Toc86348885 \\h \u001412\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc86348886\" \u0014Level 1 - First steps, automated, or whole of portfolio view\t\u0013 PAGEREF _Toc86348886 \\h \u001412\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc86348887\" \u0014Level 2 - Most applications\t\u0013 PAGEREF _Toc86348887 \\h \u001412\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc86348888\" \u0014Level 3 - High value, high assurance, or high safety\t\u0013 PAGEREF _Toc86348888 \\h \u001412\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc86348889\" \u0014Applying ASVS in Practice\t\u0013 PAGEREF _Toc86348889 \\h \u001413\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc86348890\" \u0014How to Reference ASVS Requirements\t\u0013 PAGEREF _Toc86348890 \\h \u001413\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc86348891\" \u0014Assessment and Certification\t\u0013 PAGEREF _Toc86348891 \\h \u001414\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc86348892\" \u0014OWASP's Stance on ASVS Certifications and Trust Marks\t\u0013 PAGEREF _Toc86348892 \\h \u001414\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc86348893\" \u0014Guidance for Certifying Organizations\t\u0013 PAGEREF _Toc86348893 \\h \u001414\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc86348894\" \u0014Testing Method\t\u0013 PAGEREF _Toc86348894 \\h \u001414\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc86348895\" \u0014Other uses for the ASVS\t\u0013 PAGEREF _Toc86348895 \\h \u001415\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc86348896\" \u0014As Detailed Security Architecture Guidance\t\u0013 PAGEREF _Toc86348896 \\h \u001415\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc86348897\" \u0014As a Replacement for Off-the-shelf Secure Coding Checklists\t\u0013 PAGEREF _Toc86348897 \\h \u001415\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc86348898\" \u0014As a Guide for Automated Unit and Integration Tests\t\u0013 PAGEREF _Toc86348898 \\h \u001415\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc86348899\" \u0014For Secure Development Training\t\u0013 PAGEREF _Toc86348899 \\h \u001415\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc86348900\" \u0014As a Driver for Agile Application Security\t\u0013 PAGEREF _Toc86348900 \\h \u001415\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc86348901\" \u0014As a Framework for Guiding the Procurement of Secure Software\t\u0013 PAGEREF _Toc86348901 \\h \u001416\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc86348902\" \u0014V1 Architecture, Design and Threat Modeling\t\u0013 PAGEREF _Toc86348902 \\h \u001417\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc86348903\" \u0014Control Objective\t\u0013 PAGEREF _Toc86348903 \\h \u001417\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc86348904\" \u0014V1.1 Secure Software Development Lifecycle\t\u0013 PAGEREF _Toc86348904 \\h \u001417\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc86348905\" \u0014V1.2 Authentication Architecture\t\u0013 PAGEREF _Toc86348905 \\h \u001418\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc86348906\" \u0014V1.3 Session Management Architecture\t\u0013 PAGEREF _Toc86348906 \\h \u001418\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc86348907\" \u0014V1.4 Access Control Architecture\t\u0013 PAGEREF _Toc86348907 \\h \u001418\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc86348908\" \u0014V1.5 Input and Output Architecture\t\u0013 PAGEREF _Toc86348908 \\h \u001419\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc86348909\" \u0014V1.6 Cryptographic Architecture\t\u0013 PAGEREF _Toc86348909 \\h \u001419\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc86348910\" \u0014V1.7 Errors, Logging and Auditing Architecture\t\u0013 PAGEREF _Toc86348910 \\h \u001420\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc86348911\" \u0014V1.8 Data Protection and Privacy Architecture\t\u0013 PAGEREF _Toc86348911 \\h \u001420\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc86348912\" \u0014V1.9 Communications Architecture\t\u0013 PAGEREF _Toc86348912 \\h \u001420\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc86348913\" \u0014V1.10 Malicious Software Architecture\t\u0013 PAGEREF _Toc86348913 \\h \u001420\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc86348914\" \u0014V1.11 Business Logic Architecture\t\u0013 PAGEREF _Toc86348914 \\h \u001420\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc863","cbCaiohEftGK0uQ1","https://ap.wps.com/l/cbCaiohEftGK0uQ1","docx",530624,75,"English","en",105,"# About the Standard\n# Using the ASVS\n## Application Security Verification Levels\n# Applying ASVS in Practice\n# Assessment and Certification\n# V1 Architecture, Design and Threat Modeling\n## Secure Software Development Lifecycle\n# V2 Authentication\n## Password Security\n# V3 Session Management","[{\"question\":\"What is ASVS 4.0.3 used for?\",\"answer\":\"ASVS 4.0.3 provides verification requirements and guidance to assess application security. It supports assessment and certification activities as well as related uses such as training and automated testing.\"},{\"question\":\"How does the standard organize verification requirements?\",\"answer\":\"The standard defines multiple application security verification levels. These levels range from automated or portfolio-wide first steps to high value, high assurance, or high safety scenarios.\"},{\"question\":\"Which architecture areas are covered in the standard?\",\"answer\":\"The table of contents indicates coverage across authentication, session management, access control, input/output, cryptographic architecture, errors/logging/auditing, data protection and privacy, communications, malicious software, business logic, and more.\"}]","Application Security Verification Standard - 4.0.3 - November 2021 | DOCX",1788304451,26,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":14,"keywords":34,"description":15,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"application-security-verification-standard-403-november-2021","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":11},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/template/","Template",2,{"item":49,"name":13,"@type":43,"position":50},"https://docshare.wps.com/template/general/",3,{"item":52,"name":14,"@type":43,"position":53},"https://docshare.wps.com/template/application-security-verification-standard-403-november-2021/173539/",4,{"url":52,"name":14,"@type":55,"author":56,"headline":14,"publisher":58,"fileFormat":61,"inLanguage":23,"description":15,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/vnd.openxmlformats-officedocument.wordprocessingml.document","2026-09-05","2026-09-01",true,{"@type":66,"interactionType":67,"userInteractionCount":50},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What is ASVS 4.0.3 used for?","Question",{"text":76,"@type":77},"ASVS 4.0.3 provides verification requirements and guidance to assess application security. It supports assessment and certification activities as well as related uses such as training and automated testing.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"How does the standard organize verification requirements?",{"text":81,"@type":77},"The standard defines multiple application security verification levels. These levels range from automated or portfolio-wide first steps to high value, high assurance, or high safety scenarios.",{"name":83,"@type":74,"acceptedAnswer":84},"Which architecture areas are covered in the standard?",{"text":85,"@type":77},"The table of contents indicates coverage across authentication, session management, access control, input/output, cryptographic architecture, errors/logging/auditing, data protection and privacy, communications, malicious software, business logic, and more.","https://schema.org",{"og:url":52,"og:type":88,"og:title":14,"og:site_name":59,"og:description":15},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":93},[94,99,104,109,114,119,124,129,134],{"id":95,"doc_module":11,"doc_module_name":46,"category_name":96,"show_sort_weight":97,"slug":98},11,"Presentations",90,"presentations",{"id":100,"doc_module":11,"doc_module_name":46,"category_name":101,"show_sort_weight":102,"slug":103},12,"Resumes",80,"resumes",{"id":105,"doc_module":11,"doc_module_name":46,"category_name":106,"show_sort_weight":107,"slug":108},14,"Invoices",70,"invoices",{"id":110,"doc_module":11,"doc_module_name":46,"category_name":111,"show_sort_weight":112,"slug":113},15,"Posters",60,"posters",{"id":115,"doc_module":11,"doc_module_name":46,"category_name":116,"show_sort_weight":117,"slug":118},16,"Social Media",50,"social-media",{"id":120,"doc_module":11,"doc_module_name":46,"category_name":121,"show_sort_weight":122,"slug":123},17,"Forms",40,"forms",{"id":125,"doc_module":11,"doc_module_name":46,"category_name":126,"show_sort_weight":127,"slug":128},18,"Letters",30,"letters",{"id":130,"doc_module":11,"doc_module_name":46,"category_name":131,"show_sort_weight":132,"slug":133},21,"Paper Templates",5,"papers-templates",{"id":12,"doc_module":11,"doc_module_name":46,"category_name":13,"show_sort_weight":4,"slug":135},"general-158"]