A complete, structured audit program covering all 12 critical web application security domains — aligned to OWASP Top 10, OWASP API Top 10, NIST, and ISO 27001. Built for auditors who need to test, document, and report with confidence.
SQL injection, XSS reflected and stored, command injection, HTTP parameter pollution, file upload validation, and special character filtering.
9 procedures · OWASP ASVS V5
Session timeout, login attempt limits, unnecessary resource access, business parameter configuration, and threat model documentation.
5 procedures · NIST SP 800-53
Unnecessary pages, cookie attributes (HttpOnly, Secure, SameSite), HTTP security headers, generic error messages, and free tool review.
8 procedures · OWASP ASVS V14
Patch management policy, component version scanning, CVE checks, unused dependencies, and software composition analysis tooling.
5 procedures · OWASP ASVS V1
Brute force lockout, password strength, account expiry, password recovery, MFA bypass, session ID complexity, and session invalidation.
9 procedures · NIST SP 800-63b
Automatic update controls, data privacy statements, plugin verification, code signing, and CI/CD pipeline security review.
5 procedures · NIST SP 800-53
Login event logging, privilege escalation logging, admin activity, log backup, alert thresholds, real-time attack detection, and log integrity.
7 procedures · ISO 27001 A.8.15, A.16
Audit trail existence, field adequacy, event coverage, retention period, access controls, and periodic review process.
6 procedures · OWASP ASVS V7
API authentication, broken object and function level auth, excessive data exposure, rate limiting, mass assignment, CORS, API versioning, and sensitive data in logs.
10 procedures · OWASP API Top 10 (2023)
URL parameter SSRF testing, file fetch abuse, DNS rebinding, outbound allowlists, cloud metadata endpoint testing, and error message leakage.
6 procedures · OWASP Top 10 A10





