पाठ 25 / 25

An OWASP Top 10 Checklist

Review before release.

One question per risk area

Is access checked on the server for every object and function? Is sensitive data encrypted in transit and at rest, with passwords hashed by Argon2id or bcrypt? Are all queries parameterised and outputs encoded? Was the feature threat-modelled? Are production settings hardened with security headers? Are dependencies scanned and pinned, and the pipeline protected? Is authentication protected with MFA and rate limits, and are sessions secure? Are security events logged and alerted? Are server-side URL fetches restricted, and do errors fail closed?

The checklist

Use it before releases and in reviews.

[ ] access control: deny by default; object- and function-level checks on the server
[ ] crypto: TLS + HSTS; Argon2id/bcrypt passwords; secrets in a manager, rotated
[ ] injection: parameterised queries; auto-escaping templates; no shell with user input
[ ] design: threat model + abuse cases; rate limits; server-side prices/totals
[ ] configuration: debug off; hardened baseline; CSP and security headers
[ ] components: SBOM; SCA in CI; regular updates
[ ] integrity: signed artefacts; pinned actions; no unsafe deserialisation
[ ] authentication: MFA/passkeys; breached-password checks; secure sessions/JWTs
[ ] logging: security events logged centrally; alerts; no secrets in logs
[ ] SSRF + errors: URL allow-lists, egress limits; fail closed; generic error messages

Revisit after incidents and new editions

Update your checklist when OWASP publishes a new Top 10 and after every security incident.

त्वरित जाँच: Which item belongs on an OWASP Top 10 release checklist?

  • Passwords hashed with MD5
  • Debug mode on in production for easier support
  • Every endpoint checks object-level authorisation on the server
  • Secrets committed for convenience
Answer

Every endpoint checks object-level authorisation on the server — Deny by default.