Application Security Verification Standard
Abbreviation: ASVS
Pronunciation: a-pluh-KAY-shun sih-KYOOR-ih-tee vair-ih-fih-KAY-shun STAN-durd
Also known as: ASVS
Definition
The Application Security Verification Standard is OWASP's structured set of requirements for evaluating and specifying technical security controls in applications. Application Security Verification Standard must define its objective, scope, criteria, system or control population, evidence period, test method, assessor independence, exceptions, and required remediation or reporting. Reliable results for Application Security Verification Standard depend on representative evidence, reproducible sampling, qualified judgment, traceable findings, named owners, deadlines, and verification that corrective actions work.
Overview
The OWASP Application Security Verification Standard, known as ASVS, provides a catalog of verifiable security requirements for web applications and services. It supports secure development, testing, procurement, and consistent communication about the expected depth of security assurance.
Requirements cover areas such as architecture, authentication, session management, access control, validation, cryptography, data protection, communications, and configuration. ASVS versions and levels organize expectations, so teams should identify the exact edition and assurance target they use.
ASVS can guide acceptance criteria, code review, penetration testing, and vendor contracts, but evidence must show that selected requirements are actually satisfied. Merely claiming alignment without scope, version, level, testing method, and findings does not establish meaningful assurance.
An auditable record of Application Security Verification Standard should link requests, deployments, configuration changes, logs, and service responses to the governing policy or model version, source evidence, decision, approver, exception, action, and final outcome.
The Application Security Verification Standard is OWASP’s structured set of requirements for evaluating and specifying technical security controls in applications. Application Security Verification Standard must define its objective, scope, criteria, system or control population, evidence period, test method, assessor independence, exceptions, and required remediation or reporting. Reliable results for Application Security Verification Standard depend on representative evidence, reproducible sampling, qualified judgment, traceable findings, named owners, deadlines, and verification that corrective actions work. ASVS turns broad security goals into testable requirements, provided the organization states the edition, scope, assurance level, and supporting evidence.
A production treatment of Application Security Verification Standard should test OWASP’s structured set of requirements for evaluating and specifying technical security controls in applications within the relevant asset, decision, or service state. The Application Security Verification context record for OWASP’s structured set of requirements for should preserve source data, configuration or policy version, responsible actor, exception, and outcome. Review of Application Security Verification Standard should determine whether safeguards addressing OWASP’s structured set of requirements for changed exposure in practice, not merely whether a document or setting existed.
Key Takeaway
ASVS turns broad security goals into testable requirements, provided the organization states the edition, scope, assurance level, and supporting evidence.
Sources
- NIST Documentation: Cyberframework — NIST (2026-07-30)
- OWASP Documentation: Www Project Api Security — OWASP (2026-07-30)
- OWASP Official Documentation — OWASP (2026-07-30)