CheatSheetSeries icon indicating copy to clipboard operation
CheatSheetSeries copied to clipboard

Update: Suggestion to Modernize "Abuse Case Cheat Sheet"

Open ajayojha opened this issue 5 months ago • 6 comments

First of all — thank you for the OWASP Cheat Sheet Abuse Case resource, it’s been a good starting point for onboarding teams into abuse case modeling.

As a Chief Software Architect with hands-on experience in modern technology stacks (Cloud-Native, Microservices, Micro-Frontend, and DevSecOps), particularly in designing large-scale secure enterprise architectures, I’ve noticed that some of the content are outdated and there are few gaps as per the latest technology trends. I would like to know if there are any plan to improve or modernize the abuse case cheat sheet which covers the following areas in future updates.

  1. OWASP Top 10 2021 alignment
  2. Cloud-Native & Containerized environment,
  3. API, and microservice context
  4. DevSecOps & Toolchain integration
  5. Real-World Examples & Specific Abuse.

I propose updating the abuse cases with examples and relevant references.

I would be happy to contribute to such an update if there is interest.

ajayojha avatar Jul 02 '25 06:07 ajayojha

This would be greatly appreciated. We'd be happy to review your PRs to improve the cheat sheet. My only request is that you try to do smaller incremental PRs rather than one all-containing one in order to allow easier reviewing and therefore quicker republishing of each improvement.

szh avatar Jul 02 '25 13:07 szh

Thanks for this response.

As per your suggestion I will start with smaller, Incremental PRs to ensure clarity and ease of review.

Here is the order I am planning to create PRs for review

  1. API & Microservices
  2. Cloud Native & Containerized Environment
  3. DevSecOps & Toolchain integration
  4. Real-World examples and specific abuse
  5. OWASP Top 2021 Alignment

I listed OWASP Top 10 (2021) last because it’s going to be a bigger update than the others.

Please suggest if I need to change the order of PR for review.

ajayojha avatar Jul 02 '25 16:07 ajayojha

This looks great. Looking forward to reviewing!

szh avatar Jul 02 '25 17:07 szh

Thanks for jumping in here @ajayojha :) Big fan of your contributions to ASVS so far.

jmanico avatar Jul 29 '25 18:07 jmanico

Thanks for jumping in here @ajayojha :) Big fan of your contributions to ASVS so far.

Thank you @jmanico

ajayojha avatar Jul 31 '25 01:07 ajayojha

Good idea!

mackowski avatar Aug 01 '25 13:08 mackowski