Printing

The primary source document is a Word document. You can find it named under owasp_cornucopia_webapp_n.nn_guide_bridge_(lang).docx as part of the latest release.

Pre-printed card decks may, however, be more useful. To get this, click on webshop in the upper right corner.

There are links to the source design files for the cards themselves on this page so that you can print them out yourself with your own design if you want to.

You can also choose to play the OWASP Cornucopia Website App Edition and Mobile App Edition online at copi.owasp.org.

OWASP no longer has a stock of printed decks.

OWASP does not endorse or recommend commercial products or services. However, Agile Stationary offer large print (v2.0) web app decks and large print (v1.0) mobile app decks. They also offer a croupier to help you distribute cards to team members. Also, dotNET lab sell a printed deck which complements their online references.

For each deck bought, a small donation is made to the OWASP Foundation.

Current printable version

Here is the current version of Cornucopia Website App and Mobile App Edition guides, decks and leaflets (v2.00 with updated mapping to ASVS v4.0.3):

Printing instructions

The latest printable files are released under the pre-release. Please download final printable files from there to ensure you get the latest updates and fixes done to the decks.

The docx/pdf files can be easily printed by any desktop printer, but for the best quality use the idml InDesign files. When sending the files to a printing facility you may have to supply the fonts that has been used in order to create the work.

In case the printing facility doesn't have the fonts at hand you'll find the installable fonts under resources/templates/Fonts in this repository. They are both open source and free for commercial use.

The fonts can also be downloaded from the web.

The following fonts are used:

  • Deck: Fivo Sans and Atkinson Hyperlegible
  • Leaflet: Fivo Sans
  • Cases:
    • Noto Sans Condensed Bold
    • Noto Sans Condensed Extra Bold
    • Noto Sans Condensed Medium
    • Noto Sans ExtraCondensed Extra Bold
    • Noto Sans ExtraCondensed Extra Medium
  • Logos:
    • Noto Sans Condensed Bold
    • Noto Sans Condensed Extra Bold
    • Noto Sans Extra Condensed Extra Bold

Dimensions

Card decks:

The "bridge" files are (2.25 x 3.5" or 57mm x 88.8mm) standard playing cards.

The "tarot" files are (2.75 x 4.75" or 71mm x 121 mm) standard playing cards.

Cases:

the boxes has standard dimensions used by Agile Stationary to print their OWASP Cornucopia decks.

The "bridge" is 60 x 89.25 mm x 27.15 mm

The "tarot" is 122.2 x 73.1 x 29.1 mm

Leaflets:

The "bridge" and "tarot" version is a 16-20 page spread depending on which language you print it in.

The "bridge" files are 55mm x 87mm

The "tarot" files are (2.75 x 4.75")

Please be aware, that the table of content for the Indesign leaflet has to be adjusted for all language versions before printing except for the English version!!

This is because Indesign does not support auto adjusting the TOC.

You may need to adjust the font size to fit either a 16 or a 20 page leaflet spread.

DO NOT PRINT an 18 Page leaflet! It won't look good.

Blead:

A standard blead set to 3mm for all 4 sides.

Paper:

Use 300gsm for both the bridge cards and the tarot cards.

For the case, we would recommend folding box board with anti-scuff lamination and 100gsm uncoated stock for the leaflet. The leaflets could also be laminated, but it might make them springy.

OWASP Cornucopia

  • OWASP Cornucopia is a mechanism in the form of a card game to assist software development teams identify security requirements in Agile, conventional and formal development processes. It is language, platform and technology-agnostic, and is free to use.
  • OWASP Cornucopia is licensed under the Creative Commons Attribution-ShareAlike 3.0 license, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar licence to this one.
  • © 2012-2025 OWASP Foundation. The Open Worldwide Application Security Project (OWASP) is a nonprofit foundation that works to improve the security of software.