57% of OWASP ASVS you already have
SSAE 18 already covers about 57% of OWASP ASVS, leaving
6 of 14 controls as genuinely new work.
Already covered 0
Likely covered 8
New work 6
No control in SSAE 18
maps directly to one in OWASP ASVS. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in SSAE 18 reaches these. This is the list to scope.
OWASPASVS-11Business Logic Verification (V11)
OWASPASVS-12File and Resources (V12)
OWASPASVS-13API and Web Service Security (V13)
OWASPASVS-14Configuration and Hardening (V14)
OWASPASVS-3Session Management (V3)
OWASPASVS-5Validation, Sanitization and Encoding (V5 + V5.3)
Show the 8 you already have
OWASPASVS-1Architecture, Design and Threat Modelling (V1)
OWASPASVS-10Malicious Code Verification (V10)
OWASPASVS-2Authentication and Credential Storage (V2 + V2.4)
OWASPASVS-4Access Control (V4 + V4.3)
OWASPASVS-6Stored Cryptography (V6)
OWASPASVS-7Error Handling and Logging (V7)
OWASPASVS-8Data Protection (V8 + V8.3)
OWASPASVS-9Communication Security (V9)
How this is calculated
Already covered means a mapping runs from a control in SSAE 18 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition