Skip to main content
OpenConf small logo

Providing all your submission and review needs
Abstract and paper submission, peer-review, discussion, shepherding, program, proceedings, and much more

Worldwide & Multilingual
OpenConf has powered thousands of events and journals in over 100 countries and more than a dozen languages.

Auditing web application vulnerabilities using the OWASP framework

Web application vulnerabilities represent a significant source of organizational cybersecurity risk, particularly in systems that support financial transactions and operational processes. The Open Web Application Security Project (OWASP) Top Ten identifies the most critical categories of these vulnerabilities, including broken access control, injection, insecure design, authentication failures, and deficiencies in logging and monitoring. While these categories are widely recognized, they are often not systematically incorporated into audit procedures or control evaluations. This paper develops an audit-oriented framework that maps OWASP Top Ten vulnerability categories to specific control considerations and audit activities. For each category, the framework links common root causes—such as inadequate input validation, weak access control enforcement, insecure configurations, and insufficient monitoring—to relevant audit procedures, including access control testing, configuration reviews, input validation assessments, and evaluation of logging and alerting mechanisms. The approach also incorporates practical tools and techniques, such as vulnerability scanning, configuration testing, and log analysis, to support evidence-based audit conclusions. This study contributes a structured, audit-oriented approach for evaluating application security controls using OWASP categories. This structure is designed for use in both professional audit environments and educational settings, supporting improved identification of application-layer risks and more effective assessment of cybersecurity controls.

Jose Lineros
University of North Texas
United States