Web Security and the OWASP Top Ten

Security in the Software Development Life Cycle (SDLC)

  • Security Integration: Security must be integrated across building, verifying, and hosting phases.

  • Key Activities: Includes threat modeling, security training, SAST, DAST, IAST, vulnerability scanning, and manual penetration testing.

  • Operational Security: Infrastructure involves Patch Management, OS Hardening, File integrity monitoring, and the use of Web Application Firewalls (WAF).

  • Economic Impact: Approximate estimated cost for building and securing applications can reach $4.2m\$4.2\text{m}.

OWASP Frameworks and Standards

  • Application Security Verification Standard (ASVS): A basis for testing technical security controls and providing developers with list of requirements for secure development.

  • Software Assurance Maturity Model (SAMM): Provides a measurable way for organizations to analyze and improve their software security posture.

  • OWASP WAF Projects: Includes ModSecurity, Coraza, and the OWASP Core Rule Set (CRS).

  • Specialized Guidance: Includes the OWASP AI Exchange and GenAI Security resources for securing AI and Generative AI systems.

The OWASP Top 10 (2025)

  1. Broken Access Control: Unauthorized access to data or functions.

  2. Security Misconfiguration: Incorrectly configured systems, applications, or cloud services.

  3. Software Supply Chain Failures: Use of insecure libraries or components.

  4. Cryptographic Failures: Inadequate encryption of sensitive data.

  5. Injection: Failure to prevent users from executing malicious code (e.g., SQL injection).

  6. Insecure Design: Fundamental security flaws in architectural design.

  7. Authentication Failures: Weaknesses in user login and identity management.

  8. Software or Data Integrity Failures: Lack of validation for code and data validity.

  9. Security Logging & Alerting Failures: Inability to identify or respond to active threats.

  10. Mishandling of Exceptional Conditions: Insecure handling of errors and exceptions.

Security Professional Skills and Community

  • Foundational Disciplines: Requires knowledge in Web Dev (HTTP, Javascript, CSS, Same Origin Policy), Database/NoSQL, and Networking (Protocols, Zero Trust).

  • Cloud Security: Understanding core concepts in AWS, Azure, and Google Cloud.

  • NZ Ecosystem: Key local resources include OWASP Wellington, OWASP NZ Conference (Auckland), and the CyberTech NZ ecosystem map.

  • Career Resources: "Getting Started as a Penetration Tester in NZ" by Simon Howard from Bastion Security Group.