Home/Compliance
owasp-web-2021

owasp-web-2021. Security Controls

10 controls · cross-mapped to ATT&CK techniques
Translate between regulatory language and what attackers actually do. Each control maps to MITRE ATT&CK techniques; open a control to see those techniques and whether we hold detection coverage for them.
10
Total controls
0%
Detection coverage
0
Covered controls
10
Coverage gaps
▤ Export audit (CSV) Coverage report Self-assessment Show gaps only
▶ Check your own detection coverage

Paste the ATT&CK technique IDs you have Sigma/YARA rules for (one per line, e.g. T1059, T1190). The controls below will update to show YOUR coverage instead of ours.

Red team insight A owasp-web-2021 compliant org should have detection for the green-tagged techniques below. Controls showing no technique coverage are likely blind spots. Use gaps view to enumerate unmonitored attack paths.

Controls

10 shown of 10
Access control enforces policy such that users cannot act outside of their intended permissions. Failures typically lead to unauthorized information disclosure, modification, or destruction of all data or performing a business function outside the user’s limits.
family A framework owasp-web-2021
Failures related to cryptography (or lack thereof) which often lead to exposure of sensitive data. Previously known as Sensitive Data Exposure.
family A framework owasp-web-2021
An application is vulnerable to attack when user-supplied data is not validated, filtered, or sanitized by the application. Includes SQL, NoSQL, OS command, LDAP injection.
family A framework owasp-web-2021
A broad category representing different weaknesses, expressed as "missing or ineffective control design." Focuses on risks related to design and architectural flaws.
family A framework owasp-web-2021
Applications missing appropriate security hardening across any part of the application stack, or improperly configured permissions on cloud services.
family A framework owasp-web-2021
You are likely vulnerable if you do not know the versions of all components you use; if software is vulnerable, unsupported, or out of date.
family A framework owasp-web-2021
Confirmation of the user’s identity, authentication, and session management is critical to protect against authentication-related attacks.
family A framework owasp-web-2021
Code and infrastructure that does not protect against integrity violations. CI/CD pipelines without proper integrity verification, auto-update without verification.
family A framework owasp-web-2021
This category is to help detect, escalate, and respond to active breaches. Without logging and monitoring, breaches cannot be detected.
family A framework owasp-web-2021
SSRF flaws occur whenever a web application is fetching a remote resource without validating the user-supplied URL.
family A framework owasp-web-2021
Showing 1-10 of 10
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin