HOW TO: Implement the OWASP Top 10 guidelines by playing Cornucopia, in numbers

The OWASP Top 10 list is an excellent guide for starting an Application Security improvement program inside a software development team. Still, many software development teams without access to a dedicated security professional or security team struggle to implement the OWASP Top 10 guidelines correctly.
For those teams, OWASP Cornucopia is well worth considering. Cornucopia covers the OWASP Top 10 quite well and offers a practical way to integrate a focused security improvement process into your Agile development process.
In this blog post, we look at the numbers behind the mapping between Cornucopia and the latest version of the OWASP Top 10.
A short introduction to the OWASP Top 10
The OWASP community collects data on the most important weaknesses found in applications. These weaknesses are identified using Common Weakness Enumeration, or CWE IDs. The OWASP community groups those CWE IDs into broader categories and then ranks those categories.
Each item in the Top 10 is such a category. For example, if you look deeper into 01-Broken Access Control, you find several CWE IDs underneath. Those CWE IDs can then be linked to defensive secure development techniques.
Building a deep understanding of how to correctly address one OWASP Top 10 category can be quite demanding. For most development teams, it is therefore more practical to use the Top 10 categories mainly as a tool to prioritize defensive actions. That is where Cornucopia comes in.
Playing Cornucopia produces usable non-functional requirements
Because of the relationship between OWASP Cornucopia, OWASP ASVS and the Common Weakness Enumeration, Cornucopia produces concrete, usable non-functional requirements that a team can easily add to the Product Backlog. The team identifies those requirements collaboratively and can prioritize them together.
That makes Cornucopia especially suitable for teams that develop software through an Agile process. Cornucopia helps a team discover together how to build safer software.
What is the overall relationship between Cornucopia and the OWASP Top 10?
At dotNET lab, we mapped every Cornucopia card to OWASP Top 10 items. We included the mapping from OWASP Top 10 to the corresponding Cornucopia cards in our overview of OWASP Top 10 items.
We mapped the coverage of the OWASP Top 10 guidelines by Cornucopia, counted the occurrences and created a heatmap. Here it is:

Based on our heatmap, we can draw a few conclusions:
- Overall, Cornucopia has solid coverage of all Top 10 items.
- Cornucopia provides detailed guidance for the general explanation of each Top 10 guideline.
- Once a team reaches a certain threshold of Cornucopia coverage, it can become interesting to look at ASVS.
In the next sections, we briefly look at each suit and its mappings.
- Data Validation & Encoding (DVE) suit
- Authentication (AT) suit
- Session Management (SM) suit
- Authorization (AZ) suit
- Cryptography (CR) suit
- Cornucopia (C) suit
The DVE suit has excellent overall coverage of the OWASP Top 10

My observations and opinion on the DVE suit
This suit has strong coverage of the OWASP Top 10 items.
That makes the DVE suit an ideal choice for teams that want to start their AppSec program by playing OWASP Cornucopia.
The AZ, Authorization, suit strongly focuses on #1 - Broken Access Control

My observations and opinion on the AZ, Authorization, suit
If you want to focus on the most important OWASP Top 10 category, the AZ suit is the best choice.
The CR, Cryptography, suit is pure play #02 - Cryptographic Failures

My observations and opinion on the CR suit
The cryptography suit revolves entirely around cryptography. That is no surprise.
Although the scope of this suit is fairly narrow, cryptography is category number 2 in the OWASP Top 10. That means the CR suit deserves a high place on your shortlist when deciding which suits to include in your Cornucopia game.
The AT, Authentication, suit closes weaknesses around authentication and authorization

My observations and opinion on the AT suit
Include this suit if your team wants to make sure possible weaknesses around authentication and authorization are addressed thoroughly.
The Cornucopia, C, suit helps your team focus on difficult security vulnerabilities often abused by attackers

My observations and opinion on the C suit
Although the C suit does not seem to have a strong correlation with specific OWASP Top 10 categories, it does focus strongly on unpleasant vulnerabilities. It mainly emphasizes 05-Security Misconfiguration and 06-Vulnerable and Outdated Components.
The Session Management, SM, suit helps prevent Security Misconfiguration and Data Integrity failures

My observations and opinion on the SM suit
The Session Management suit rounds out the Cornucopia game with a focus on Security Misconfiguration.
Conclusion
Implementing the OWASP Top 10 guidelines can start with something simple: playing the Cornucopia card game.
Cornucopia has solid coverage of the Top 10 categories, with each suit having its own focus. Depending on your team's priorities, you can choose which suit to focus on next.
Cornucopia also serves as an entry point to the broader OWASP ecosystem. It invites teams to look beyond Cornucopia or the Top 10 and explore other OWASP projects, such as ASVS.
Using Cornucopia helps your team strengthen security knowledge and improve its defence against cyber threats.
Good luck!

Order your Cornucopia deck
Accelerate your path to more security awareness as a developer with Cornucopia. It is more than a game. It is a new way to look at secure application development.

