From f6ca63a9f8b3d030097135e096c1041e09c29fd9 Mon Sep 17 00:00:00 2001 From: Tim Graham Date: Wed, 6 Apr 2016 13:00:38 -0400 Subject: [PATCH] Refs #26464 -- Added a link to OWASP Top 10 in security topic guide. --- docs/topics/security.txt | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/docs/topics/security.txt b/docs/topics/security.txt index 324e198410..eb1172e7e8 100644 --- a/docs/topics/security.txt +++ b/docs/topics/security.txt @@ -273,5 +273,10 @@ security protection of the Web server, operating system and other components. * Keep your :setting:`SECRET_KEY` a secret. * It is a good idea to limit the accessibility of your caching system and database using a firewall. +* Take a look at the Open Web Application Security Project (OWASP) `Top 10 + list`_ which identifies some common vulnerabilities in web applications. While + Django has tools to address some of the issues, other issues must be + accounted for in the design of your project. .. _LimitRequestBody: https://httpd.apache.org/docs/2.4/mod/core.html#limitrequestbody +.. _Top 10 list: https://www.owasp.org/index.php/Top_10_2013-Top_10