Cyver core supports the OWASP Mobile Application Security Testing Guide (MASTG) Checklist, including:
- Version 1.7.0 for both Android and iOS platforms.
The OWASP MASTG serves as the essential practical guide for security professionals who are actively involved in mobile application security analysis, testing, and reverse engineering.
General Information on the OWASP MASTG
The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual that is part of the flagship OWASP Mobile Application Security (MAS) project.
What is the MASTG?
The MASTG is designed to be a detailed, hands-on resource covering the entire spectrum of mobile application security analysis:
- Processes, Techniques, and Tools: It describes the technical procedures and methodologies necessary for conducting thorough security assessments.
- Verification of MASVS Controls: The MASTG provides an exhaustive set of test cases specifically designed for verifying the security requirements listed in its companion document, the OWASP Mobile Application Security Verification Standard (MASVS).
- Mapping to Weaknesses: It describes the technical processes for verifying the MASVS controls through the weaknesses defined by the OWASP Mobile Application Security Weakness Enumeration (MASWE).
Purpose and Value
By providing a baseline for complete and consistent security tests, the MASTG ensures that security analysis is rigorous and repeatable. It is the perfect manual for turning the verification standards defined in the MASVS into practical, actionable testing steps.
Both the OWASP MASVS and MASTG are widely trusted and referenced by major platform providers, standardization bodies, governmental organizations, and educational institutions worldwide.
Download
You can directly download the latest OWASP MASTG Checklists from our GitHub repository:
MASTG Android 1.7.0 L1
MASTG Android 1.7.0 L2
MASTG Android 1.7.0 P
MASTG Android 1.7.0 R
MASTG iOS 1.7.0 L1
MASTG iOS 1.7.0 L2
MASTG iOS 1.7.0 P
MASTG iOS 1.7.0 R