This is the official site of TSS-WEB, an open framework of ~200baseline requirements that you can use for your web development security standard, policy, or security concept. All of these requirements are based on common best practices (including those from OWASP, SAFECode, ISO/IEC 27002, NIST and BSI) plus our own experiences in this field.
For instance, TSS-WEB also meets 14.2.1 control ("Secure Development Policy") of ISO/IEC 27002. Detailed compliance mappings are provided in appendix B to E.
TSS-WEB 2.0 Online (November 2020)
We are currently working on the new release. The wiki content is currently undergoing full revision and will be updated regularly. The new release will be available shortly.
The objective of TSS-WEB is to provide a framework of language-independent application security requirements that can be used by organizations as a baseline to implement their own security standards or policies for their web development.
Secure Coding Guidelines
TSS-WEB provides high-level requirements that can be used to derive secure coding guidelines for specific languages and frameworks.
Secure Coding Guidelines for Confluence by Secodis
The document is licensed under Creative Commons By 4.0 and can therefore be used and changed to individual needs free of charge and without any other obligations than to name the document and author of the used template. Furthermore, any adapted version of this document does not have to be published under the same license.