The findings indicate that while the OWASP Top Ten serves as a strategic reference, the WSTG is superior as a primary technical auditing framework, which enhances audit consistency, precision, and efficiency in evaluating modern web environments.
Abstract
This study evaluates the comparative effectiveness of two widely adopted cybersecurity frameworks, the OWASP Top Ten (2021) and the OWASP Web Security Testing Guide (WSTG), in the context of web application security auditing. While the OWASP Top Ten is a standard for risk awareness, it lacks the technical granularity required for comprehensive testing, creating a gap between high-level risk identification and practical verification. To bridge this gap, this study proposes a structured integration through comparative mapping and empirical validation using real-world mitigation data. A procedural analysis combined with granularity evaluation was employed to map the ten OWASP risk categories to 102 technical verification units in the WSTG. The results reveal a 920% increase in testing granularity compared to the baseline Top Ten framework. Empirical validation conducted on a government subdomain (Instansi X) demonstrated that this integrated approach identified critical vulnerabilities, including Broken Access Control and Cryptographic Failures, which are often overlooked in high-level assessments. By implementing specific WSTG-based mitigation procedures, such as middleware authorization and secure communication protocols, identified risks were successfully remediated without disrupting production stability. This study contributes a validated framework that bridges the gap between conceptual risk and actionable technical verification. The findings indicate that while the OWASP Top Ten serves as a strategic reference, the WSTG is superior as a primary technical auditing framework. This integration enhances audit consistency, precision, and efficiency in evaluating modern web environments.
The study aims to integrate OWASP Top 10 categories, controlled practical testing, and CVSS-based risk assessment into a single methodological sequence and to evaluate its practical effectiveness in identifying critical web application vulnerabilities.
It is concluded that web application security requires continuous assessment and proactive security practices throughout the software development lifecycle, and adopting OWASP guidelines and implementing effective security controls can significantly enhance the protection and resilience of modern web applications.
S. Banu, H. Shanmatha, Mehdi Gheisari et al.· BOHR International Journal o...· 0 citations
The e-commerce platform was declared sufficiently secure against direct penetration attacks on the database but remains vulnerable to end-user access manipulation, providing an objective overview of security in large-scale digital retail systems.
Sari Prabandari, Ahmad Fadilah Nur Fitrah, A. Zulfikar· IC-BESTS: International Conf...· 0 citations
This review's results show that penetration testing is an important part of improving cybersecurity because it helps identify weaknesses before they become problems and reduces risk.
Shruti Agarwal, S. Sharma· DMPedia Lecture Notes in Com...· 1 citation
It is found that regular, authorized penetration testing can support vulnerability identification, risk assessment, and the implementation of appropriate remediation measures, and the study concludes that regular, authorized penetration testing can support vulnerability identification, risk assessment, and the implemen...
Bibi Iqra· International Journal of Dig...· 0 citations
A comparative assessment of two Dexcom software platforms: the Dexcom Clarity web portal and the Dexcom ONE+ iPhone application is conducted, and a re-producible evaluation procedure is presented and applicable, standards-compliant mitigation recommendations for each identified issue.
A. Alshammari, Shouki A. Ebad· International Journal of Adv...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.