The OWASP Mobile Application Security Verification Standard provides a common reference for evaluating Android and iOS security controls.
An assessment is useful when your engineering, security or procurement team needs evidence against defined requirements, rather than a list of vulnerabilities alone. We agree the applicable requirements, application versions, platforms and available access before testing.
The MASVS control groups cover:
- Storage of sensitive data and use of cryptography.
- Authentication and secure network communication.
- Platform interaction and code security.
- Resilience to reverse engineering and tampering, and user privacy.