Skip to content

OWASP/www-project-secure-by-design-framework

Repository files navigation

OWASP Secure-by-Design Framework

The OWASP Secure-by-Design (SbD) Framework provides structured, design-time guidance for embedding security into architecture before code is written. It bridges high-level security requirements and implementation-time verification (ASVS), and includes a condensed review checklist plus a living catalog of reference architectures and reusable patterns. See the owasp page for more information.

◽ Status & Versioning

This is the initial draft release – version v0.5.0 (Draft) – August 2025. The framework is evolving; contributions are welcome!

◽ Quick links:

see website and relevant tabs for:

  • SbD Process
  • SbD Principles & Recommendations
  • SbD Review Checklist
  • Catalog

Download PDF: OWASP-Secure-by-Design-Framework-v0.5.pdf

◽ Contributing:

Read CONTRIBUTING.md for the full contribution process.

Changelog

For a detailed history of updates, improvements, and milestones, please see the CHANGELOG.md

About

OWASP Foundation web repository

Resources

License

Contributing

Security policy

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Contributors 3

  •  
  •  
  •