OWASP Common Numbering Project

Common OWASP Numbering
''An exciting development, a new numbering scheme that will be common across OWASP Guides and References has been developed. The numbering is based on the OWASP ASVS section and detailed requirement numbering. The effort to develop the numbering was a team effort, led by Mike Boberski (ASVS project lead and co-author). OWASP Top Ten, Guide, and Reference project leads and contributors as well as the OWASP leadership worked together to develop numbering that would allow for easy mapping between OWASP Guides and References, and that would allow for a period of transition as Guides and References are updated to reflect the new numbering. For more information about the new numbering, please see http://www.owasp.org/index.php?title=Common_OWASP_Numbering A new OWASP project is in the process of being created to manage the new numbering scheme, for example as numbers are retired. The new project will be led by Brad Causey.''

Common OWASP Numbering
Below is the generally agreed-upon new numbering scheme.

Questions/Comments? Email [mailto:mike.boberski@owasp.org Mike] or [mailto:brad.causey@owasp.org Brad].

OWASP-0600 OWASP-0600-DEPRECATED OWASP-0604 OWASP-0604-DEPRECATED OWASP-0604-DG OWASP-0604-DG-01 OWASP-0604-TG OWASP-0604-TG-DV-005 OWASP-0604-TG-DV-005-DEPRECATED

0123456789012345678901234567890123456789          1         2         3


 * 0-4 OWASP
 * 6-7 Detailed requirement identifier (major)
 * 8-9 Detailed requirement identifier (minor)
 * 11-12 Document code (DG=Development Guide, TG=Testing Guide, CG=Code Review Guide, AR, ED, RM, OR, others reserved)
 * 14-40 (Optional: DEPRECATED, or # for iterations, or legacy identifiers)

Legacy Numbering Mappings
Coming soon!

Users/Contributors
Coming soon!