EPISODE · Sep 17, 2021 · 29 MIN
OWASP Top 10 2021 Peer Review
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Chris and Robert conduct a practitioner peer review of the 2021 OWASP Top 10, examining what changed, what moved, and what the new structure communicates to development teams. They compare the list with the 2017 edition, discuss the broader treatment of injection, and unpack additions such as insecure design, software and data integrity failures, and server-side request forgery. The review also questions how categories map to real weaknesses, CVEs, and verification practices. Along the way, they connect the Top 10 to ASVS, threat modeling, dependency analysis, and the difficult balance between a widely recognized awareness document and actionable engineering guidance.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with OWASP:→ OWASP Top 10→ OWASP FoundationMentioned in this episode:→ OWASP Top 10:2021→ OWASP ASVS→ Threat Modeling Manifesto→ OWASP Dependency-Check→ CycloneDXFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Peer reviewing the OWASP Top 10:202103:00 Broken access control moves to number one04:52 Injection and cross-site scripting are consolidated07:46 Vulnerable and outdated components10:50 Software and data integrity failures12:42 Server-side request forgery joins the list15:00 Does the new structure help practitioners?18:00 Security logging and monitoring20:00 Mapping categories to weaknesses and CVEs21:52 Connecting the Top 10 to verification practices27:00 Final observations
Embed this episode
What this episode covers
Chris and Robert conduct a practitioner peer review of the 2021 OWASP Top 10, examining what changed, what moved, and what the new structure communicates to development teams. They compare the list with the 2017 edition, discuss the broader treatment of injection, and unpack additions such as insecure design, software and data integrity failures, and server-side request forgery. The review also questions how categories map to real weaknesses, CVEs, and verification practices. Along the way, t...
Ready to play
OWASP Top 10 2021 Peer Review
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.