OWASP Top 10 2021 Peer Review episode artwork

EPISODE · Sep 17, 2021 · 29 MIN

OWASP Top 10 2021 Peer Review

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Chris and Robert conduct a practitioner peer review of the 2021 OWASP Top 10, examining what changed, what moved, and what the new structure communicates to development teams. They compare the list with the 2017 edition, discuss the broader treatment of injection, and unpack additions such as insecure design, software and data integrity failures, and server-side request forgery. The review also questions how categories map to real weaknesses, CVEs, and verification practices. Along the way, they connect the Top 10 to ASVS, threat modeling, dependency analysis, and the difficult balance between a widely recognized awareness document and actionable engineering guidance.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with OWASP:→ OWASP Top 10→ OWASP FoundationMentioned in this episode:→ OWASP Top 10:2021→ OWASP ASVS→ Threat Modeling Manifesto→ OWASP Dependency-Check→ CycloneDXFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Peer reviewing the OWASP Top 10:202103:00 Broken access control moves to number one04:52 Injection and cross-site scripting are consolidated07:46 Vulnerable and outdated components10:50 Software and data integrity failures12:42 Server-side request forgery joins the list15:00 Does the new structure help practitioners?18:00 Security logging and monitoring20:00 Mapping categories to weaknesses and CVEs21:52 Connecting the Top 10 to verification practices27:00 Final observations

Episode metadata supplied by the publisher feed · Published Sep 17, 2021

Embed this episode

Chris and Robert conduct a practitioner peer review of the 2021 OWASP Top 10, examining what changed, what moved, and what the new structure communicates to development teams. They compare the list with the 2017 edition, discuss the broader treatment of injection, and unpack additions such as insecure design, software and data integrity failures, and server-side request forgery. The review also questions how categories map to real weaknesses, CVEs, and verification practices. Along the way, t...

Distinct summary based on available episode metadata or transcript content.

Ready to play

OWASP Top 10 2021 Peer Review

0:00 29:40

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 29 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on September 17, 2021.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!