The analog in the title is a real, current object, not a vibe. OWASP published Top 10:2025 as its eighth installment. Official list:
A01 Broken Access Control; A02 Security Misconfiguration; A03 Software Supply Chain Failures; A04 Cryptographic Failures; A05 Injection; A06 Insecure Design; A07 Authentication Failures; A08 Software or Data Integrity Failures; A09 Security Logging and Alerting Failures; A10 Mishandling of Exceptional Conditions.
It is data-informed, not a brainstorm. Contributors handed over testing data on more than 2.8 million applications. Eight categories are ranked from that data; two are promoted from a practitioner survey because some holes never show up in scanners. A01 maps 40 Common Weakness Enumerations, showed up in 100% of applications tested, and has about 1.84 million recorded occurrences. A05 Injection is the most tested category and the one with the most CVEs. Each row names the hole, describes an exploit, and tells you how to change the running program — deny by default on the server, keep data separate from commands, parameterized queries.
OWASP's own project page calls the Top 10 "a standard awareness document." That is the analog the essay reaches for. It is not the whole OWASP stack.
Four rows transfer, and each one breaks in the same place: software has a running object a team can change. A sentence does not.
A01: access control is only effective in trusted server-side code the attacker cannot edit. Deny by default; log failures; put the check in unit tests. The language analog is "we" on a departmental letterhead — anyone with the header can speak as the institution. There is no server-side check. The white paper is both the app and the attacker.
A05: an injection flaw lets untrusted input reach an interpreter and be executed as a command. Prevention is keep data separate from commands; use a parameterized API. Suitcase words do the same job to a policy term: "well-being," "fairness," "levelling up" arrive as data and get executed as a goal. You cannot parameterize a statute. Positive input validation has no equivalent when the vocabulary is the product.
A09 was renamed to put alerting in the title. The authors say great logging with no alerting is of minimal value; the category has been voted in from the community survey three times because scanners undercount it. A 332-page white paper is a log. Nothing pages a named owner when a mission sentence has no who, no floor, and no miss.
A10 is new in 2025: improper error handling, logical errors, failing open (CWE-636). Prevention is catch the error where it happens, roll the transaction back, fail closed, and keep a global handler for what you missed. A 2030 mission with no consequence slot fails open by construction. 2031 arrives; the sentence is still true as a wish.
The break underneath all four: OWASP also ships ASVS 5.0 (May 2025, Global AppSec EU Barcelona) — testable requirements, not a poster. The Top 10 tells you what to worry about. ASVS tells you what must be true of the running app, with a pass or a fail. The essay analogizes to the awareness document and ships questions a reader might ask. That is the Top 10. It is not ASVS.