Are there any web application security standards that I can use as a baseline for the security related requirements for a web application, web service, and for applications supported/hosted by third parties?
How is security risk managed for web application and what are the preventive and corrective controls that I should expect to see?
Additionally, how can we provide security compliance for web applications?
From my findings I found that most organizations have developed their own standards/guidelines like
Am I mistaken in that there is no universal standard?