Skip to main content

OWASP (Open Worldwide Application Security Project)

OWASP is the Open Worldwide Application Security Project.

What is OWASP (Open Worldwide Application Security Project)?

OWASP is the Open Worldwide Application Security Project. The OWASP Foundation is a nonprofit that supports open software-security projects, education, tools, and community work. The OWASP Top 10 is an awareness document for major web-application security risks. The OWASP Top 10:2025 categories are Broken Access Control, Security Misconfiguration, Software Supply Chain Failures, Cryptographic Failures, Injection, Insecure Design, Authentication Failures, Software or Data Integrity Failures, Security Logging and Alerting Failures, and Mishandling of Exceptional Conditions.

Why it matters

OWASP gives software teams open guidance, tools, and shared terms for common application-security problems. The Top 10 helps teams start a risk discussion, but it is not a complete security program.

How it works

  1. OWASP community projects create and maintain security guidance, tools, standards, and training material.
  2. The Top 10 project combines data analysis and community input to select broad web-application risk categories.
  3. Teams use the material to inform threat models, design reviews, coding practice, verification, and security education.

Example

A team uses the Broken Access Control category to review whether its API checks object ownership on the server for every request.

Pomerium boundary

Pomerium can authenticate users and enforce identity- and context-aware policy before a request reaches a protected web application. This can reduce unauthorized access to that route. It does not find or repair the application's OWASP risks.

Limits and non-claims

  • The OWASP Top 10 is an awareness document and does not cover every application-security risk.
  • A Top 10 checklist is not proof that an application is secure or compliant.
  • Broad categories do not replace a threat model, secure design, code review, testing, and operational monitoring.

Evaluation checklist

  • Which OWASP project, version, requirement, or risk entry supports the current claim?
  • Has the team mapped it to a system-specific control, owner, test, and evidence source?
  • Is anyone treating a community list as a standard, certification, or substitute for a threat model?

Sources and further reading

Keep learning

Security Operations and Risk

Attack Surface

An attack surface is the set of boundary points where an attacker can try to enter a system, cause an effect, or extract data.

Learn this term
Authorization and Policy

Access Control

Combine policy, reliable decision inputs, enforcement, and evidence to control actions on protected resources.

Learn this term
Security Operations and Risk

Data Breach

A data breach is the loss of control, compromise, unauthorized disclosure, acquisition, or access to sensitive information.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo