DFIELDSOLUTIONS

Security

GlossaryOWASP Top 10

The long-standing community list of the most critical web application security risks, revised every few years.

It is the common vocabulary of web security: broken access control, cryptographic failures, injection, insecure design, misconfiguration and the rest. Its value is less the ranking than the shared language — it lets a developer, a tester and a client describe the same problem without three different names for it.

It is a floor, not a ceiling. Covering all ten means the obvious ways in are closed, which is genuinely worth doing and is not the same as being secure; the interesting findings in most engagements are business-logic flaws that no generic list can anticipate because they depend on what the application is for.

Related terms

The bench this belongs to

Cybersecurity

Purple Team: the same person writes the exploit and closes the hole. Most agencies only harden, which means hardening against a threat nobody tested.

All termsStart a conversationMarkdown version

DField Bt. · Dunakeszi · dezso@dfieldsolutions.com
5.0
“From LinkedIn DM to live site. Two tiny tweaks, then shipped.”Michael J Ringer · Vilya ProtectionFounder · Spain