
ASVS
Application Security Verification Standard

Application Security Verification Standard

OWASP-maintained Top 10 API security risks document and documentation portal with best practices for building, breaking, and defending APIs.

The AI Security Verification Standard (AISVS) focuses on providing developers, architects, and security professionals with a structured checklist to…

Interactive platform linking security standards and guidelines for designing, developing, testing, and procuring secure software. Provides a unified…

Repo to hold mapping of user-security-stories

Project focused on governance and risk in application security, providing resources and frameworks for security maturity and risk management.

Vendor-neutral cloud security testing guide with structured phases for enumeration, privilege escalation, lateral movement, and post-exploitation…

A documentation and tracking project with the goal of making package management systems more secure.

Structured playbook for integrating threat modeling into product security, covering stakeholder buy-in, organizational embedding, training, process…

Structured curriculum for learning application security, covering secure coding, threat modeling, and DevSecOps practices. Designed for self-paced…

Coordination structure for AI security standards and guidelines, reducing fragmentation and providing clear guidance for securing AI systems across…

VULCONHUB provides access to files to build your own hands-on vulnerable container image to learn and practice security




A curated library of security prompts for AI-assisted security testing, threat modeling, and educational exercises.

A practical framework identifying and prioritizing the top security risks in AI datacenter infrastructure, covering hardware, networking, management…

Open standard for documenting security-relevant metadata of AI models, including training data provenance, PII risk, known vulnerabilities, and…