OWASP / owasp-masvs

The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.
https://mas.owasp.org/
Creative Commons Attribution Share Alike 4.0 International
1.97k stars 424 forks source link

Should 1.10 be required already on L1? #631

Closed mascotter closed 2 years ago

mascotter commented 2 years ago

The requirement "1.10 MSTG-ARCH-10 Security is addressed within all parts of the software development lifecycle." is currently a L2 requirement. Addressing security in the whole SDL process should IMO be the very basics of any requirement set or framework.

In addition, the requirement 1.12 stipulates compliancy with privacy laws and regulations already on L1. I cannot imagine how e.g. compliancy against GDPR's privacy and security by design and default can be demonstrated if security is not addressed within all parts of the SDL.