Maturing Your Application Security Program with ASVS-Driven Development - Aram Hovsepyan @OWASPGLOBAL
Maturing Your Application Security Program with ASVS-Driven Development - Aram Hovsepyan  @OWASPGLOBAL
Uploaded March 2025 | Updated September 2026, 2 weeks ago
Application security requires a systematic and holistic approach. However, organizations typically struggle in creating an effective application security (AppSec) program. They often end up in the rabbit hole of fixing security tool-generated vulnerabilities. We believe that leveraging ASVS as a security requirements framework as well as a guide to unit and integration testing is amongst the highest added value security practices. By turning security requirements into “just requirements” organizations can enable a common language shared by all stakeholders involved in the SDLC.

In this talk, we would like to present the case of ASVS-driven development. Firstly, we have analyzed the completed ASVS to determine how much of it could be transformed into security test cases. Our analysis indicates that 162 ASVS requirements (58%) can be automatically verified using unit, integration and acceptance tests. Secondly, we have designed an empirical study where we have added 98 ASVS requirements to the sprint planning of a relatively large web application. We have implemented unit and integration tests for 90 ASVS requirements in 10 man-days that are now part of the security regression test suites.

Our study demonstrates that leveraging ASVS for deriving security test cases can create a common theme across all stages of the software development lifecycle making security everyone’s responsibility.

-

Managed by the OWASP® Foundation
owasp.org
Maturing Your Application Security Program with ASVS-Driven Development - Aram HovsepyanEvolving Your Security Champions Program: Introducing the OWASP Security Champions Maturity ModelAI Code Generation - Benefits, Risks and Mitigation Controls - Aruneesh SalhotraThe OWASP Events Committee Presents Vienna 26Keynote: Thriving in the Age of AI - Aanchal GuptaHidden Chains: Revealing High-Impact Bugs from Bounty submissions - Vinay & MuraliOWASP Global Board of Directors Meeting - February 2025Under the Radar: How we found 0-days in the Build Pipeline of OSS Packages - François Proulx202009 September 2020 Global Board MeetingThe SCA Balancing ActHow Three Threat Modelers Can Influence an Entire Organization - Léandre Forget-B., Laurent BouchardThe Broken State of DevSecOps and Its Maturity Model - Eitan Worcel, Dustin Lehr
OWASP Foundation |

Maturing Your Application Security Program with ASVS-Driven Development - Aram Hovsepyan

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER