INTEGRAÇÃO DE MODELOS OWASP: UMA ABORDAGEM COMPLEMENTAR PARA SEGURANÇA NO DESENVOLVIMENTO DE SOFTWARE
Resumo
Security in software development has established itself as a central concern given the growing sophistication of vulnerabilities exploited in corporate environments. In this context, three OWASP frameworks offer complementary approaches. The OWASP Top 10 (2021) serves as a normative and awareness guide, classifying critical risks, but lacks technical mitigation guidelines. ASVS 4.0.3 (2021), in turn, provides verifiable requirements organized by criticality levels, enabling detailed technical validations. SAMM 2.0 (2020) structures organizational maturity into domains such as governance, verification, and construction, guiding process evolution. The integration of these three perspectives offers a more comprehensive path to institutionalizing security in the software lifecycle.
