This cheatsheet will help users of the OWASP Proactive Controls identify which cheatsheets map to each proactive controls item. This mapping is based the OWASP Proactive Controls version 3.0 (2018).
Attack Surface Analysis Cheat Sheet
Clickjacking Defense Cheat Sheet
DotNet Security Cheat Sheet (A3 Cross Site Scripting)
Ruby on Rails Cheat Sheet (Tools)
Ruby on Rails Cheat Sheet (XSS)
Vulnerable Dependency Management Cheat Sheet
DotNet Security Cheat Sheet (Data Access)
DotNet Security Cheat Sheet (A1 SQL Injection)
Query Parameterization Cheat Sheet
Ruby on Rails Cheat Sheet (SQL Injection)
SQL Injection Prevention Cheat Sheet
AJAX Security Cheat Sheet (Client Side)
Cross Site Scripting Prevention Cheat Sheet
DOM based XSS Prevention Cheat Sheet
Injection Prevention Cheat Sheet
Injection Prevention Cheat Sheet in Java
LDAP Injection Prevention Cheat Sheet
DotNet Security Cheat Sheet (HTTP Validation and Encoding)
DotNet Security Cheat Sheet (A8 Cross site request forgery)
DotNet Security Cheat Sheet (A10 Unvalidated redirects and forwards)
Injection Prevention Cheat Sheet
Injection Prevention Cheat Sheet in Java
OS Command Injection Defense Cheat Sheet
REST Security Cheat Sheet (Input Validation)
Ruby on Rails Cheat Sheet (Command Injection)
Ruby on Rails Cheat Sheet (Mass Assignment and Strong Parameters)
Unvalidated Redirects and Forwards Cheat Sheet
XML External Entity Prevention Cheat Sheet
Server Side Request Forgery Prevention Cheat Sheet
Choosing and Using Security Questions Cheat Sheet
DotNet Security Cheat Sheet (Forms authentication)
DotNet Security Cheat Sheet (A2 Weak Account management)
JSON Web Token Cheat Sheet for Java
REST Security Cheat Sheet (JWT)
Ruby on Rails Cheat Sheet (Sessions)
Ruby on Rails Cheat Sheet (Authentication)
Session Management Cheat Sheet
Authorization Testing Automation
Credential Stuffing Prevention Cheat Sheet
Cross-Site_Request_Forgery_Prevention_Cheat_Sheet
DotNet Security Cheat Sheet (A4 Insecure Direct object references)
DotNet Security Cheat Sheet (A7 Missing function level access control)
REST Security Cheat Sheet (Access Control)
Ruby on Rails Cheat Sheet (Insecure Direct Object Reference or Forceful Browsing)
Ruby on Rails Cheat Sheet (CSRF)
Insecure Direct Object Reference Prevention Cheat Sheet
Transaction Authorization Cheat Sheet
Cryptographic Storage Cheat Sheet
DotNet Security Cheat Sheet (Encryption)
DotNet Security Cheat Sheet (A6 Sensitive data exposure)
Transport Layer Protection Cheat Sheet
HTTP Strict Transport Security Cheat Sheet
REST Security Cheat Sheet (HTTPS)
Ruby on Rails Cheat Sheet (Encryption)
User Privacy Protection Cheat Sheet
REST Security Cheat Sheet (Audit Logs)