The OWASP ASVS focuses on web-application verification. It is free and recognised worldwide as a good reference to build upon, or simply reuse. It is useful to use it when outsourcing web development.
However OWASP does not provide similar documentation for non-web developments (like heavy client applications, services / daemons etc).
Ofcourse companies like Gartner provide similar documentation related to the non-web world, but those are not free.
I'm looking for standards similar to OWASP ASVS that would cover non-web developments - are there such good free standards available ? If yes, which ones ?
Thanks !