ASVS vs MASVS levels #577
Closed
roelstorms
started this conversation in
Ideas
Replies: 1 comment 2 replies
-
Hi @roelstorms, we're very sorry about the late response! We cannot promise anything for now but, to let you know, we're considering your proposal as part of the new MASVS refactoring. Thanks a lot for posting your idea, we'll keep you informed! |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Hi,
My organisations wants to use (M)ASVS for new developments. We would require a project to adhere to ASVS level 1 mostly. For mobile applications, we would prefer to use MASVS as it is more specific. However, MASVS has no level 1 that corresponds to ASVS level 1. It seems like MASVS grouped ASVS level 1 and 2 together into MASVS level 1.
For example:
MASVS:
ASVS:
If we would require a web app to comply with ASVS level 1 and a mobile app with MASVS level 1, they would have a more strict set of requirements for the mobile applications.
My proposal is to introduce a level 1 in MASVS which is aligned with ASVS. ASVS also explains that level 1 controls are fully testable using a black box approach.
Beta Was this translation helpful? Give feedback.
All reactions