OWASP logo
Store Donate Join

This website uses cookies to analyze our traffic and only share that information with our analytics partners.

Accept
x
Store
Donate
Join
OWASP Secure Coding Practices - Quick Reference Guide

Secure Coding Practices

Home > Stable-en > 02-checklist

Secure Coding Practices Checklist

2.1 Input validation

2.2 Output encoding

2.3 Authentication and password management

2.4 Session management

2.5 Access control

2.6 Cryptographic practices

2.7 Error handling and logging

2.8 Data protection

2.9 Communication security

2.10 System configuration

2.11 Database security

2.12 File management

2.13 Memory management

2.14 General coding practices


Watch Star
The OWASP® Foundation works to improve the security of software through its community-led open source software projects, hundreds of chapters worldwide, tens of thousands of members, and by hosting local and global conferences.

Secure Coding Practice Quick-reference Guide

  • 1. Introduction
  • 2. Checklist
  • 2.1 Input validation
  • 2.2 Output encoding
  • 2.3 Authentication and password management
  • 2.4 Session management
  • 2.5 Access control
  • 2.6 Cryptographic practices
  • 2.7 Error handling and logging
  • 2.8 Data protection
  • 2.9 Communication security
  • 2.10 System configuration
  • 2.11 Database security
  • 2.12 File management
  • 2.13 Memory management
  • 2.14 General coding practices
  • Appendix A. Overview
  • Appendix B. Glossary
  • Appendix C. External references

Upcoming OWASP Global Events

Corporate Supporters

Become a corporate supporter
  • HOME
  • PROJECTS
  • CHAPTERS
  • EVENTS
  • ABOUT
  • PRIVACY
  • SITEMAP
  • CONTACT

OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, and LASCON are trademarks of the OWASP Foundation, Inc. Unless otherwise specified, all content on the site is Creative Commons Attribution-ShareAlike v4.0 and provided without warranty of service or accuracy. For more information, please refer to our General Disclaimer. OWASP does not endorse or recommend commercial products or services, allowing our community to remain vendor neutral with the collective wisdom of the best minds in software security worldwide. Copyright 2024, OWASP Foundation, Inc.