OWASP ASVS Panjabi Translation — Review Hub
Your feedback matters. You do not need a GitHub account to review this translation. Read the content below, then email your feedback to gurvinder@securityleader.ai with the subject line "ASVS Panjabi Review". Even a single correction or suggestion is valuable.
What Is This?
The OWASP Application Security Verification Standard (ASVS) is the global benchmark for application security requirements — 350 requirements across 17 chapters that architects, developers, and security teams use to build and verify secure software.
This is the first-ever translation of ASVS into Panjabi (ਪੰਜਾਬੀ), reaching 130+ million speakers worldwide. The translation uses a bilingual format — English first, Panjabi (Gurmukhi script) immediately below — so readers can cross-reference for technical precision.
The translation is being submitted to the official OWASP ASVS repository as a proposed contribution (PR #3254 on GitHub).
What to Review
All twenty-seven bilingual documents are ready for review — every chapter and every appendix — plus the glossary. Read them in any order:
| Document | What It Contains | Link |
|---|---|---|
| Title Page (ਮੁੱਖ ਪੰਨਾ) | Project credits, copyright, license, contributors | Read |
| Introduction (ਮੁਖਬੰਧ) | ASVS 5.0 introduction, principles, levels, scope | Read |
| What is the ASVS? (ASVS ਕੀ ਹੈ?) | What the ASVS covers, its three levels, and how to use it | Read |
| Assessment and Certification (ਮੁਲਾਂਕਣ ਅਤੇ ਸਰਟੀਫ਼ਿਕੇਸ਼ਨ) | How ASVS is assessed and certified | Read |
| Changes Compared to v4.x (v4.x ਦੇ ਮੁਕਾਬਲੇ ਤਬਦੀਲੀਆਂ) | What changed for users of ASVS 4.0 | Read |
| V1 Encoding and Sanitization (V1 ਏਨਕੋਡਿੰਗ ਅਤੇ ਸੈਨੀਟਾਈਜ਼ੇਸ਼ਨ) | Output encoding and input sanitization requirements (injection defence) | Read |
| V2 Validation and Business Logic (V2 ਪ੍ਰਮਾਣਿਕਤਾ ਅਤੇ ਕਾਰੋਬਾਰੀ ਤਰਕ) | Input validation and business logic requirements | Read |
| V3 Web Frontend Security (V3 ਵੈੱਬ ਫਰੰਟਐਂਡ ਸੁਰੱਖਿਆ) | Browser security headers, cookies, and frontend protections | Read |
| V4 API and Web Service (V4 API ਅਤੇ ਵੈੱਬ ਸੇਵਾ) | REST, GraphQL, and WebSocket API security requirements | Read |
| V5 File Handling (V5 ਫ਼ਾਈਲ ਪ੍ਰਬੰਧਨ) | File upload, storage, and download requirements | Read |
| V6 Authentication (V6 ਪ੍ਰਮਾਣੀਕਰਨ) | Passwords, multi-factor, and credential lifecycle requirements | Read |
| V7 Session Management (V7 ਸੈਸ਼ਨ ਪ੍ਰਬੰਧਨ) | Session creation, timeout, and termination requirements | Read |
| V8 Authorization (V8 ਅਧਿਕਾਰੀਕਰਨ) | Access control and authorization requirements | Read |
| V9 Self-contained Tokens (V9 ਸਵੈ-ਨਿਰਭਰ ਟੋਕਨ) | JWT / self-contained token validation requirements | Read |
| V10 OAuth and OIDC (V10 OAuth ਅਤੇ OIDC) | OAuth 2.0 and OpenID Connect client, server, and token requirements | Read |
| V11 Cryptography (V11 ਕ੍ਰਿਪਟੋਗ੍ਰਾਫ਼ੀ) | Algorithms, key management, and randomness requirements | Read |
| V12 Secure Communication (V12 ਸੁਰੱਖਿਅਤ ਸੰਚਾਰ) | TLS and secure communication requirements | Read |
| V13 Configuration (V13 ਸੰਰਚਨਾ) | Secure configuration, secrets, and dependency requirements | Read |
| V14 Data Protection (V14 ਡਾਟਾ ਸੁਰੱਖਿਆ) | Sensitive-data classification, storage, and caching requirements | Read |
| V15 Secure Coding and Architecture (V15 ਸੁਰੱਖਿਅਤ ਕੋਡਿੰਗ ਅਤੇ ਆਰਕੀਟੈਕਚਰ) | Architecture, safe coding, and defensive-design requirements | Read |
| V16 Security Logging and Error Handling (V16 ਸੁਰੱਖਿਆ ਲੌਗਿੰਗ ਅਤੇ ਗਲਤੀ ਪ੍ਰਬੰਧਨ) | Security logging, log protection, and error-handling requirements | Read |
| V17 WebRTC (ਵੈੱਬਆਰਟੀਸੀ) | WebRTC signaling, TURN, and media-security requirements | Read |
| Appendix A: Glossary (ਅੰਤਿਕਾ A: ਸ਼ਬਦਾਵਲੀ) | Glossary of ASVS terms in English and Gurmukhi | Read |
| Appendix B: References (ਅੰਤਿਕਾ B: ਹਵਾਲੇ) | Related OWASP projects and external references | Read |
| Appendix C: Cryptography Standards (ਅੰਤਿਕਾ C: ਕ੍ਰਿਪਟੋਗ੍ਰਾਫ਼ੀ ਮਿਆਰ) | Cryptographic algorithm and key-strength recommendations | Read |
| Appendix D: Recommendations (ਅੰਤਿਕਾ D: ਸਿਫ਼ਾਰਸ਼ਾਂ) | Further recommendations for verifiers and implementers | Read |
| Appendix E - Contributors (ਅੰਤਿਕਾ E - ਯੋਗਦਾਨੀ) | Contributors since the ASVS 4.0.0 release | Read |
| Glossary (ਸ਼ਬਦਾਵਲੀ) | 70 security terms with Gurmukhi translations | Read |
Who Should Review
You do not need to be both a Panjabi speaker AND a security expert — either qualification helps:
- Panjabi speakers: Does the translation read naturally, or does it feel like a forced word-for-word conversion? Are there better Gurmukhi equivalents for any term?
- Security researchers: Is the English source meaning preserved? Do any translations introduce ambiguity that could affect a developer's implementation?
- Gurmukhi linguists: Any Devanagari script contamination? Proper vowel signs (ਮਾਤਰਾ)? Clean Unicode?
Understanding the Glossary — Translation Approaches
Every translated term in the glossary is classified by its translation approach (T/L/R/H):
| Category | When Used | Example |
|---|---|---|
| T — Translated | Concept has a natural Panjabi equivalent | Authentication → ਪ੍ਰਮਾਣੀਕਰਨ |
| L — Loan Word | Term is universally used in English | API → ਏ.ਪੀ.ਆਈ. |
| R — Retained | Acronym or proper noun, kept as-is | OWASP, SQL, XSS |
| H — Hybrid | Part translates, part stays in English | SQL Injection → SQL ਇੰਜੈਕਸ਼ਨ |
Timeline
| Phase | Content | Target |
|---|---|---|
| A (Complete) | Title Page, Introduction, Glossary, Translation Notes, Review Plan | February 2026 |
| B (Complete) | Assessment & Certification, Changes from v4.x, V5 File Handling, V8 Authorization, V9 Self-contained Tokens, V12 Secure Communication — now bilingual | June 2026 |
| C (Complete) | All 17 security-requirement chapters (V1–V17) and What is the ASVS? are bilingual | August 2026 |
| D (Complete) | Appendix A: Glossary, Appendix B: References, Appendix C: Cryptography Standards, Appendix D: Recommendations, Appendix E: Contributors — now bilingual. The full ASVS 5.0 translation (27 documents) is ready for sangat review. | August 2026 |
How to Send Feedback
Email (easiest): Send to gurvinder@securityleader.ai with subject "ASVS Panjabi Review"
Include any of the following:
- A term you think should be translated differently (e.g., "I think ਕਮਜ਼ੋਰੀ works better as ਖ਼ਾਮੀ for Vulnerability")
- A Gurmukhi spelling or vowel sign correction
- A sentence that reads unnaturally and a suggested alternative
- General impressions of the bilingual format
GitHub (for Git-comfortable reviewers): Open PR #3254 and leave inline comments on any file in 5.0/pa-IN/.
Source Material
- Translation submission — PR #3254 on GitHub
- GeeksikhSecurity working copy
- Full blog post: Why I'm Translating OWASP's Security Standard Into Panjabi
- AISVS Panjabi Review Hub — the sibling AI-security translation, same bilingual methodology
ਸੁਰੱਖਿਆ ਗਿਆਨ ਸਭ ਲਈ ਹੋਣਾ ਚਾਹੀਦਾ ਹੈ. — Security knowledge should be accessible to all.