GithubHelp home page GithubHelp logo

Mapping 1.0->2.0->2.1 table required about asvs HOT 2 CLOSED

owasp avatar owasp commented on June 22, 2024
Mapping 1.0->2.0->2.1 table required

from asvs.

Comments (2)

relaxnow avatar relaxnow commented on June 22, 2024

Very much agree that the numbering is odd. It's a new major version, the whole point is to break with the old and introduce the new.

The reply I got at the time from @vanderaj was:

I think the missing gaps are v1.0 -> 2.0 mapping related - i.e. issues that are no longer inspected. I originally had "Deleted" or something there, but I think it may be important to declare why there are gaps (it makes translating v1.0 reports to ASVS 2.0 requirements much easier!).

My reply still stands I think:

Don't really agree with the reason, ASVS 2014 shouldn't be saddled with the burden of 2009 to make a one time thing easier for a few 2009 users IMHO.
Now I can no longer easily verify if a verification contains everything required for that level (instead of checking is 1.1 through 1.7 there, I have to memorise all the numbers per level). Making it easier for an auditor to sneakily leave off 'difficult' requirements or simply forget.

from asvs.

vanderaj avatar vanderaj commented on June 22, 2024

We are adding the missing requirements back, and then putting in a small amount of detail as to what happened to them including when the issues were retired. This will hopefully answer this issue and make it easier for tool users to keep faith with ASVS as we don't change the numbering scheme.

from asvs.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.