Skip to content

Latest commit

 

History

History
53 lines (36 loc) · 4.8 KB

File metadata and controls

53 lines (36 loc) · 4.8 KB
layout col-sidebar
title OWASP Citizen Development Top 10
tags citzdev
level 3
type documentation
pitch The primary goal of the "OWASP Citizen Development Top 10" document is to provide assistance and education for organizations looking to adopt a culture of security for their Citizen Development environments. The guide provides information about what the most prominent security risks are for such applications, the challenges involved, and how to overcome them.

OWASP Citizen Development Top 10

stars slack

Overview

Since Gartner introduced the term “Citizen Developer” in 2009, advances in platforms such as Microsoft Power Platform, SAP, ServiceNow, and Salesforce, along with AI assisted tools like Base44, Cursor, and Replit, have enabled people across all backgrounds to build sophisticated software at scale.

This movement has accelerated innovation but also raised new concerns around security and governance. The OWASP Citizen Development Top 10 Project addresses these challenges by identifying the most pressing risks that arise from citizen development of software built with Low Code No Code, AI assisted coding, and AI agent technologies.

Scope

Citizen developers can be business users improving efficiency in their daily work or hobbyists creating entirely new applications. By lowering barriers to entry, business innovation platforms and AI assisted technologies have redefined how software is created, removing long standing resource constraints from traditional development teams.

This expanded ability to create at scale introduces unique risks for organizations. Originally focused on Low Code No Code platforms, this OWASP project broadened its scope to reflect the wider landscape of citizen development and the technologies that enable it. The Top 10 risks therefore cover threats introduced through business innovation platforms, AI assisted coding, and AI agents.

Audience

The OWASP Top 10 Security Risks for Citizen Development is primarily aimed at security professionals who are tasked with enabling safe adoption of these technologies. They provide the critical guardrails that balance rapid innovation with secure practices.

The project also speaks directly to citizen developers, giving them an understanding of how their work may create risks and how to avoid common pitfalls. Governance bodies gain structured recommendations to align oversight with organizational goals and regulatory requirements, strengthening accountability across citizen development initiatives.

The key crossover focus for this document is to facilitate collaboration between the business and security and governance.

Mission

The mission of the OWASP Citizen Development Top 10 Project is to help organizations identify, prioritize, and mitigate risks tied to citizen development. The list explains how these risks manifest across various technologies and offers concrete mitigations to reduce them.

By providing accessible examples and guidance, the project equips both technical and non technical creators to make secure by default choices. Its goal is to establish the foundations that allow innovation to thrive while maintaining strong security practices.

The List

  1. CD-SEC-01: Blind Trust
  2. CD-SEC-02: Account Impersonation
  3. CD-SEC-03: Authorization Misuse
  4. CD-SEC-04: Sensitive Data Leakage and Handling Failures
  5. CD-SEC-05: Authentication and Secure Communication Failures
  6. CD-SEC-06: Vulnerable and Untrusted Components
  7. CD-SEC-07: Security Misconfiguration
  8. CD-SEC-08: Injection Handling Failures
  9. CD-SEC-09: Asset Management Failures
  10. CD-SEC-10: Security Logging and Monitoring Failures

View the PDF