Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security How do organisations decide whether to use OWASP…
Cyber Security

How do organisations decide whether to use OWASP Top 10 2025, SAMM, DSOMM, or ASVS in an application security program?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 24, 2026 Domain: Cyber Security

Use the OWASP Top 10 for awareness and prioritization, then add maturity and verification models to operationalize the program. SAMM and DSOMM help assess process maturity and continuous improvement, while ASVS provides testable security requirements. Together they turn risk awareness into measurable controls, making it easier to track progress and verify whether safeguards actually work.

Why This Matters for Security Teams

Choosing between OWASP Top 10 2025, SAMM, DSOMM, and ASVS is not a branding exercise. It determines whether an application security program is only describing risk, or actually improving how teams build, test, and govern software. The OWASP Top 10 is useful for awareness and executive communication, while OWASP Non-Human Identity Top 10 and the OWASP Agentic AI Top 10 show how OWASP-style risk framing now extends into identity and autonomous systems. But security leaders still need something more operational than a risk list.

SAMM and DSOMM answer the question of whether the organisation has repeatable secure development practices, governance, and feedback loops. ASVS answers a different question: what exactly should be verified in an application, and at what depth. In practice, many programs fail because they pick one model and expect it to do all three jobs: educate, mature the process, and define testable controls. The result is usually a programme that looks complete on paper but leaves engineering teams without clear implementation criteria. In practice, many security teams encounter control gaps only after a failed assessment or production incident has already exposed them, rather than through intentional verification.

How It Works in Practice

The cleanest way to decide is to treat the four models as complementary, not competing. The OWASP Top 10 is the entry point when a programme needs a common language for risk themes such as injection, broken access control, or insecure design. SAMM and DSOMM are then used to measure whether the organisation has the operating model to prevent, detect, and respond to those issues consistently. ASVS is used when the team needs a security requirements baseline that developers, testers, and auditors can actually verify.

That usually maps to different operational questions:

  • What are the most important application risks that stakeholders should understand? Use OWASP Top 10.

  • How mature is the secure software lifecycle, and where should the programme improve next? Use SAMM or DSOMM.

  • What exact security capabilities must this application implement and prove? Use ASVS.

For modern programs, the scope often needs extension beyond classic web applications. Identity-heavy services, service-to-service authentication, and autonomous workflows can introduce NHI and agentic control issues that are not captured well by a generic web risk list alone. That is why the OWASP Non-Human Identity Top 10 and the OWASP Agentic AI Top 10 are increasingly relevant as companion references when applications depend on machine identities, tokens, tool use, or delegated execution. For baseline governance and secure-by-design alignment, teams often anchor their control mapping to NIST AI Risk Management Framework only where AI-enabled functionality is in scope, and to OWASP ASVS for verifiable requirements in the application layer.

In operational terms, the framework choice should follow the audience: executives need OWASP Top 10 style prioritization, engineering leaders need SAMM or DSOMM maturity targets, and delivery teams need ASVS-level requirements that can be embedded into build, review, and test workflows. These controls tend to break down when a single framework is forced across mixed portfolios that include legacy apps, APIs, machine-to-machine services, and AI-enabled workflows because the evidence and testing depth required are not the same.

Common Variations and Edge Cases

Tighter security governance often increases delivery overhead, requiring organisations to balance consistency against engineering capacity. That tradeoff is especially visible when a portfolio includes both low-risk internal tools and customer-facing platforms with regulated data. There is no universal standard for which OWASP model should dominate in every environment; current guidance suggests using the lightest model that still produces measurable change, then layering depth as risk increases.

One common edge case is when teams try to use the OWASP Top 10 as a policy standard. It is not designed to be a complete control catalogue, so it works best as a communication and prioritization tool. Another is when SAMM or DSOMM are adopted as assessment checklists without executive ownership of remediation outcomes. Maturity scores then become reporting artifacts instead of drivers of improvement. ASVS can also be misapplied if teams select a level without considering whether the application handles authentication, sensitive transactions, or identity delegation. Higher assurance should be reserved for higher risk, not applied mechanically.

For identity-rich systems, the bridge to NHI matters. If applications issue API keys, OAuth tokens, workload credentials, or AI agent permissions, then app security decisions affect identity governance as much as code quality. In those cases, the most useful pattern is often Top 10 for awareness, SAMM or DSOMM for lifecycle maturity, and ASVS for verifiable controls, with the OWASP Non-Human Identity Top 10 used to capture machine-identity abuse paths that generic app standards miss.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and OWASP-ASVS set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10Agentic apps need dedicated risk coverage beyond standard web app checks.
OWASP Non-Human Identity Top 10Machine identities and tokens create app security risks this question touches.
NIST AI RMFGOVERNAI-enabled applications need governance and accountability for risk decisions.
NIST CSF 2.0PR.IPSecure development practices and verification fit the Protect function.
OWASP-ASVSV1ASVS provides testable application security requirements for validation.

Assign owners, document risk tolerance, and track AI-related controls through governance processes.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org