This document discusses improving web application security and provides threats and countermeasures. It is authored by J.D. Meier, Alex Mackman, Srinath Vasireddy, Michael Dunner, Ray Escamilla, and Anandha Murukan and includes forewords by Mark Curphey, Joel Scambray, and Erik Olson. The document contains information about securing web applications that is subject to change.