ASVS vs MASVS levels #577
Closed
roelstorms
started this conversation in
Ideas
Replies: 1 comment 2 replies
-
Hi @roelstorms, we're very sorry about the late response! We cannot promise anything for now but, to let you know, we're considering your proposal as part of the new MASVS refactoring. Thanks a lot for posting your idea, we'll keep you informed! |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hi,
My organisations wants to use (M)ASVS for new developments. We would require a project to adhere to ASVS level 1 mostly. For mobile applications, we would prefer to use MASVS as it is more specific. However, MASVS has no level 1 that corresponds to ASVS level 1. It seems like MASVS grouped ASVS level 1 and 2 together into MASVS level 1.
For example:
MASVS:
ASVS:
If we would require a web app to comply with ASVS level 1 and a mobile app with MASVS level 1, they would have a more strict set of requirements for the mobile applications.
My proposal is to introduce a level 1 in MASVS which is aligned with ASVS. ASVS also explains that level 1 controls are fully testable using a black box approach.
Beta Was this translation helpful? Give feedback.
All reactions