OWASP ASVS is a complete list of security requirements for web applications used by architects, developers, testers and auditors.
| Level | Name | Target |
|---|---|---|
| 1 | Opportunistic | All software. Defends against easy-to-find vulnerabilities. |
| 2 | Standard | Apps with sensitive data. Most security risks addressed. |
| 3 | Advanced | Critical apps requiring the highest level of trust. |