Application Security Verification Standard 4.0
Andrew van der Stock, co-leader ASVS Project March 2019 - NullCon
Verification Standard 4.0 Andrew van der Stock, co-leader ASVS - - PowerPoint PPT Presentation
Application Security Verification Standard 4.0 Andrew van der Stock, co-leader ASVS Project March 2019 - NullCon Andrew van der Stock Senior Principal Consultant, Synopsys Technical Leader of Managed Services Joined OWASP late ~2002
Andrew van der Stock, co-leader ASVS Project March 2019 - NullCon
(2016-2018)
Kisasondi, Serg Belokamen, Jason Axley, and Adam Caudill
sensitive personal identifying information
default software
Easter eggs
management
Secure code review Peer coding checklists Hybrid reviews Unit testing Integration testing Security architecture Developer training Consultant training DevSecOps automation Tool Benchmark Vulnerability programs Secure coding checklist Deployment checklist Penetration test Functional constraints Non-functional and functional features Planning Sprint Assistance Supplier Benchmarking
vanderaj@owasp.org (ASVS) | vander@synopsys.com ($dayjob) @vanderaj