Releases: OWASP/owasp-masvs
Intermediate update 1.1.4 (Summit edition)
Intermediate update (1.1.4). See CHANGELOG.md for updates on intermediate update releases.
Intermediate update 1.1.3
Intermediate update (1.1.3). See CHANGELOG.md for updates on intermediate update releases.
Sponsorship and internationalization
This is the first international release of the OWASP MASVS! We support Chinese, English, French, German, Japanese, Spanish and Russian now.
See CHANGELOG.md for the actual changes.
OWASP Mobile Application Security Verification Standard v1.1 in Russian
This is the very first release of the MASVS in Russian!
Thanks Maxim Gall for the initiative to translate the English version into Russian and thanks to Oprya Egor, Chelnokov Vladislav, Tereshin Dmitrii, Bachevsky Artem, Mesheryakov Aleksey, Ratchenko Denis who supported in this project.
OWASP Mobile Application Security Verification Standard v1.1
The following changes are part of release 1.1:
- Requirement 2.6 "The clipboard is deactivated on text fields that may contain sensitive data." was removed. See also Issue #117.
- Requirement 2.2 "No sensitive data should be stored outside of the app container or system credential storage facilities." was added.
- Requirement 2.1 was reworded to "System credential storage facilities are used appropriately to store sensitive data, such as PII, user credentials or cryptographic keys.".
OWASP Mobile Application Security Verification Standard v1.0 in Spanish
This release contains the Spanish Translation of the MASVS. Thanks to Martin Marsicano for the initiative.
OWASP Mobile Application Security Verification Standard v1.0
Changelog:
- Releasing Version 1.0
- Delete 8.9 as the same as 8.12
- Made 4.6 more generic
- Minor fixes (typos etc.)
OWASP Mobile Application Security Verification Standard v0.9.4
Changelog:
- Update and re-organize security requirements
- Fix OWASP Mobile Top 10 links
OWASP Mobile Application Security Verification Standard v0.9.3
This release contains bugfixes and modifications to security requirements.
- Merged requirement 7.8 and 7.9 for simplification
- Removed Anti-RE controls 8.1 and 8.2
- Updated MSTG references
- Section "Environmental Interaction" renamed to "Platform Interaction"
- Removed To-dos
- Fixed wording & spelling issues
OWASP Mobile Application Security Verification Standard v0.9.2
- Redesign of the security model
- Simplification to two verification levels
- Many changes to requirements based on industry feedback