OWASP / owasp-mastg

The Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes the technical processes for verifying the controls listed in the OWASP Mobile Application Security Verification Standard (MASVS).
https://mas.owasp.org/
Creative Commons Attribution Share Alike 4.0 International
11.6k stars 2.29k forks source link

Create new checklist file #1001

Closed commjoen closed 5 years ago

commjoen commented 5 years ago

The checklist (XLS) needs updating right before going to 1.2.0 of the MASVS.

meetinthemiddle-be commented 5 years ago

I can help on this one. If nobody is taking that up, feel free to assign to me.

commjoen commented 5 years ago

Done

meetinthemiddle-be commented 5 years ago

Just an idea : Would it be a good idea to work with intermediary "permalinks"? This keeps the flexibility in altering the URL's without breaking the links in the Excel checklist.

commjoen commented 5 years ago

Let's create links to github with the tags :D (e.g. https://github.com/OWASP/owasp-mstg/blob/1.1.0/Document/0x04a-Mobile-App-Taxonomy.md#mobile-app-taxonomy) and let's make sure that the excel has metadata which shows which version this is.

A-AFTAHI commented 5 years ago

I checked the checklist and found that some sentences are expressed diffrently from the MASVS and i'm not sure if these has to be changed. please check these examples to make sure everything is alright: 4.2, 4.7 and 5.2 and resilience section. thanks

commjoen commented 5 years ago

Beautifully done, all seems to make sense now.