Three ways to read a standard, two of them wrong
ASVS has over 350 requirements across 17 chapters. How you read it decides whether it helps.
| How you read it | Outcome |
|---|---|
| Front to back | You stop at chapter 3. Nobody reads a 350-line checklist through |
| To tick boxes | An all-green table reflects nothing. Any hard box gets read as "not applicable" |
| As an audit of yourself | Useful — but only if you allow yourself to answer "no" |
The third differs from the second in exactly one respect, and that respect is the entire value: a "fail" is a useful result, whereas "not applicable" is usually an evasion.
ASVS's three levels, and picking the right one is step one:
| Level | For | Requirement count |
|---|---|---|
| L1 | Every application. Externally verifiable | ~130 |
| L2 | Applications handling real data. The right default for almost every product | ~270 |
| L3 | Healthcare, finance, critical infrastructure | ~350 |
For a B2B SaaS product L2 is the answer, and setting L3 as a target is a way to guarantee never completing anything.
The practical reading — not by chapter, by feature. ASVS is organised by topic (V6 Authentication, V8 Authorization…) but you do not build by topic. So the way to use it: take one feature, find the requirements that apply, and work through them. A "share a report by link" feature touches V6, V7, V8 and V16 — four chapters, about twenty requirements, and twenty requirements is an hour's reading.
And this is what makes a coverage report more valuable than a certificate: it states what is missing. A line reading "V8 passes, V5 unassessed, V11 fails on three requirements" is usable for planning; a line reading "security assessment completed" is usable for nothing.
Comments
Commenting needs an account with at least one completed lesson. That condition is what keeps this thread worth reading: every point belongs to someone who can be asked back, and reputation accrues over time.
You can still read every comment below without an account. Signing in brings you back to this exact spot, not to the top of the page.
Loading comments…