Skip to content

Latest commit

 

History

History
7 lines (4 loc) · 503 Bytes

requirement-5.19.rst

File metadata and controls

7 lines (4 loc) · 503 Bytes

5.19 Output encoding/escaping has a single security control per type

Verify that all input data is validated, not only HTML form fields but all sources of input such as REST calls, query parameters, HTTP headers, cookies, batch files, RSS feeds, etc; using positive validation (whitelisting), then lesser forms of validation such as greylisting (eliminating known bad strings), or rejecting bad inputs (blacklisting).

Levels: 2, 3