# What the OWASP Top 10 Is — OWASP Top 10

Source: https://www.skillbyai.com/en/owasp-top-10/i-what

> Awareness, not a complete standard.

## Ranked categories built from data

The **Open Worldwide Application Security Project (OWASP)** is a non-profit community that publishes free security resources. The **Top 10** is its best-known document: ten categories of web application risk, ranked using vulnerability data contributed by organisations plus a community survey, and updated every few years. Each category groups related weaknesses (CWEs) and gives prevention guidance. It is an **awareness** baseline, not a complete security standard; for detailed requirements, OWASP publishes the Application Security Verification Standard (**ASVS**) and the Cheat Sheet Series.

## A shared language for web risks

The OWASP Top 10 is an awareness document that ranks the most critical categories of web application security risk.

![Three ideas: what the list is, the categories, thinking like a defender.](assets/figures/owasp-top-10/section-1-map.svg) — Figure 1.1 — The list, its categories and threat modelling.

## The most common causes of road accidents

A list of the most common accident causes helps drivers focus their attention, but it is not the whole highway code.

## Use ASVS for requirements

Teams that need testable security requirements should adopt an ASVS level rather than treating the Top 10 as a checklist.

**Quiz:** What is the OWASP Top 10 best described as?

- [ ] A firewall product
- [ ] A complete security certification
- [x] An awareness document of the most critical web application risk categories
- [ ] A programming language standard

*Answer:* An awareness document of the most critical web application risk categories. ASVS provides detailed requirements.
