OWASP ASVS 5.0
Answer what the Application Security Verification Standard 5.0 requires: each verification requirement by chapter and number, which level it applies to, and what changed from 4.0.
451 notes · updated 2026-08-04 · trained 21%
Ask it things like
answers 6/28 on its latest examWhat are the three verification levels defined in ASVS 5.0 and their general purposes?✓
What changes were made to API and web service security (V4) between v4.0 and v5.0?✓
How many total requirements does ASVS 5.0 contain across all chapters and levels?✓
Were any requirements removed or marked as deprecated in v5.0 compared to v4.0?✓
What is the official title and control objective of V1?✓
What mapping files or transition documents are available to map requirements from ASVS v4.0 to v5.0?✓
# sign in to get a token
$ claude mcp add --transport http mozg \
https://mozg.sh/mcp --header "Authorization: Bearer …"
> use mozg/owasp-asvs — …
Get a tokenUse this brain
Sign in and add it, and every agent you have connected can read it — nothing to download, and it stays current as the author updates it.
Sign in to add itWhat it can answer
28 checks21%
▲Changes from v4.02 / 5
▲Chapter Coverage & Structure1 / 6
▲Metadata & Mapping1 / 3
▲Requirement Numbering & Completeness1 / 5
▲Verification Levels & Scope1 / 4
✕Critical Gaps in Coverage0 / 5
Inside
- AES cipher modes approval status and restrictions · asvs/v11-cryptography
- Approved hash functions for general use cases · asvs/v11-cryptography
- Cryptographic parameter security strength equivalencies · asvs/v11-cryptography
- Approved symmetric cipher algorithms in preference order · asvs/v11-cryptography
- Authenticated encryption requirement and schemes · asvs/v11-cryptography
- Approved AEAD mechanisms · asvs/v11-cryptography
- Cryptographic mechanism approval levels · asvs/v11-cryptography
- V11.1 cryptographic inventory tools for Level 3 · asvs/v11-cryptography
- Approved random value generation mechanisms · asvs/v11-cryptography
- HMAC-DRBG and Hash-DRBG underlying hash function requirement · asvs/v11-cryptography
- CBC mode encryption and authentication requirements · asvs/v11-cryptography
- AES key wrapping requirements · asvs/v11-cryptography
- CBC mode padding verification requirement · asvs/v11-cryptography
- Approved general key derivation functions · asvs/v11-cryptography
Licence
CC BY-NC-SA 4.0
Use it, copy it, build on it, with credit. Selling it is not allowed.