Skip to content
arrow_back
search
ISM-0971 policy ASD Information Security Manual (ISM)

Use OWASP Standards in Web Application Development

Developers must use OWASP standards for building secure web applications.

record_voice_over

Plain language

Using the OWASP standards in web development means building your websites or online services in a way that protects them from being hacked or misused. If this isn't done, the risk is that attackers could steal sensitive information, damage your reputation, or disrupt your business operations.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The OWASP Application Security Verification Standard is used in the development of web applications.
policy ASD Information Security Manual (ISM) ISM-0971
priority_high

Why it matters

Without using OWASP ASVS, web apps are more exposed to common flaws, leading to data theft and loss of trust.

settings

Operational notes

Apply OWASP ASVS requirements in design and code reviews, and verify with testing before each release.

Mapping detail

Mapping

Direction

Controls