Back to insights
Cybersecurity 30 April 2024

HOW TO: Implement the OWASP Top 10 guidelines by playing Cornucopia, in numbers

Featured image for implementing the OWASP Top 10 guidelines by playing Cornucopia

The OWASP Top 10 list is an excellent guide for starting an Application Security improvement program inside a software development team. Still, many software development teams without access to a dedicated security professional or security team struggle to implement the OWASP Top 10 guidelines correctly.

For those teams, OWASP Cornucopia is well worth considering. Cornucopia covers the OWASP Top 10 quite well and offers a practical way to integrate a focused security improvement process into your Agile development process.

In this blog post, we look at the numbers behind the mapping between Cornucopia and the latest version of the OWASP Top 10.

A short introduction to the OWASP Top 10

The OWASP community collects data on the most important weaknesses found in applications. These weaknesses are identified using Common Weakness Enumeration, or CWE IDs. The OWASP community groups those CWE IDs into broader categories and then ranks those categories.

Each item in the Top 10 is such a category. For example, if you look deeper into 01-Broken Access Control, you find several CWE IDs underneath. Those CWE IDs can then be linked to defensive secure development techniques.

Building a deep understanding of how to correctly address one OWASP Top 10 category can be quite demanding. For most development teams, it is therefore more practical to use the Top 10 categories mainly as a tool to prioritize defensive actions. That is where Cornucopia comes in.

Playing Cornucopia produces usable non-functional requirements

Because of the relationship between OWASP Cornucopia, OWASP ASVS and the Common Weakness Enumeration, Cornucopia produces concrete, usable non-functional requirements that a team can easily add to the Product Backlog. The team identifies those requirements collaboratively and can prioritize them together.

That makes Cornucopia especially suitable for teams that develop software through an Agile process. Cornucopia helps a team discover together how to build safer software.

What is the overall relationship between Cornucopia and the OWASP Top 10?

At dotNET lab, we mapped every Cornucopia card to OWASP Top 10 items. We included the mapping from OWASP Top 10 to the corresponding Cornucopia cards in our overview of OWASP Top 10 items.

We mapped the coverage of the OWASP Top 10 guidelines by Cornucopia, counted the occurrences and created a heatmap. Here it is:

Overall heatmap of the Cornucopia to OWASP Top 10 mapping

Based on our heatmap, we can draw a few conclusions:

  • Overall, Cornucopia has solid coverage of all Top 10 items.
  • Cornucopia provides detailed guidance for the general explanation of each Top 10 guideline.
  • Once a team reaches a certain threshold of Cornucopia coverage, it can become interesting to look at ASVS.

In the next sections, we briefly look at each suit and its mappings.

  • Data Validation & Encoding (DVE) suit
  • Authentication (AT) suit
  • Session Management (SM) suit
  • Authorization (AZ) suit
  • Cryptography (CR) suit
  • Cornucopia (C) suit

The DVE suit has excellent overall coverage of the OWASP Top 10

Heatmap for Data Validation & Encoding within the OWASP Top 10 mapping

My observations and opinion on the DVE suit

This suit has strong coverage of the OWASP Top 10 items.

That makes the DVE suit an ideal choice for teams that want to start their AppSec program by playing OWASP Cornucopia.

The AZ, Authorization, suit strongly focuses on #1 - Broken Access Control

Heatmap for Authorization within the OWASP Top 10 mapping

My observations and opinion on the AZ, Authorization, suit

If you want to focus on the most important OWASP Top 10 category, the AZ suit is the best choice.

The CR, Cryptography, suit is pure play #02 - Cryptographic Failures

Heatmap for Cryptography within the OWASP Top 10 mapping

My observations and opinion on the CR suit

The cryptography suit revolves entirely around cryptography. That is no surprise.

Although the scope of this suit is fairly narrow, cryptography is category number 2 in the OWASP Top 10. That means the CR suit deserves a high place on your shortlist when deciding which suits to include in your Cornucopia game.

The AT, Authentication, suit closes weaknesses around authentication and authorization

Heatmap for Authentication within the OWASP Top 10 mapping

My observations and opinion on the AT suit

Include this suit if your team wants to make sure possible weaknesses around authentication and authorization are addressed thoroughly.

The Cornucopia, C, suit helps your team focus on difficult security vulnerabilities often abused by attackers

Heatmap for the Cornucopia suit within the OWASP Top 10 mapping

My observations and opinion on the C suit

Although the C suit does not seem to have a strong correlation with specific OWASP Top 10 categories, it does focus strongly on unpleasant vulnerabilities. It mainly emphasizes 05-Security Misconfiguration and 06-Vulnerable and Outdated Components.

The Session Management, SM, suit helps prevent Security Misconfiguration and Data Integrity failures

Heatmap for Session Management within the OWASP Top 10 mapping

My observations and opinion on the SM suit

The Session Management suit rounds out the Cornucopia game with a focus on Security Misconfiguration.

Conclusion

Implementing the OWASP Top 10 guidelines can start with something simple: playing the Cornucopia card game.

Cornucopia has solid coverage of the Top 10 categories, with each suit having its own focus. Depending on your team's priorities, you can choose which suit to focus on next.

Cornucopia also serves as an entry point to the broader OWASP ecosystem. It invites teams to look beyond Cornucopia or the Top 10 and explore other OWASP projects, such as ASVS.

Using Cornucopia helps your team strengthen security knowledge and improve its defence against cyber threats.

Good luck!

Team playing OWASP Cornucopia with cards and reference website

Order your Cornucopia deck

Accelerate your path to more security awareness as a developer with Cornucopia. It is more than a game. It is a new way to look at secure application development.

Visit our webshop

Want to work with OWASP Cornucopia yourself?

Do you want to make security risks more concrete inside your development team? We can help you see how threat modeling and Cornucopia fit your software process.

Contact our security specialist