Skip to main content

Selective Reading Guide

Full-book reading is not required. Start with the guide; use OWASP ASVS for requirements, WSTG for testing, Cheat Sheets for implementation, and NIST SSDF for lifecycle questions. Record the decision changed by reading.

Required evidence

Submit authorized reproduction, request and response evidence with secrets removed, code and configuration repair, bypass variants, deterministic regression, ASVS mapping, scope analysis, and residual risk. Raw scanner severity is not accepted without triage.

Oral defense

Demonstrate the violated invariant, explain why the repair generalizes, run a bypass attempt, and identify adjacent routes or versions included in scope.

Source backbone

Use OWASP ASVS, OWASP WSTG, OWASP Cheat Sheets, and NIST SSDF.