# OWASP Mobile Application Security Verification Standard v2.1

Framework id: `owasp_masvs_v2`. Security Standard. Publisher: OWASP Foundation. Version: 2.1 (2024). Region: Global. Mapping licence: CC BY-SA 4.0.
Source text: https://mas.owasp.org/MASVS/

Each line is a clause, the NIST SP 800-53 controls OSA maps to it, and OSA's estimate of how far those controls cover it.
Clause titles and coverage figures are OSA's own summaries and estimates. No line-by-line check against the source text is recorded for this framework, so quote the source, not this card.

## Clauses (24, average coverage 73%)
- MASVS-AUTH-1 The app uses secure authentication and authorization protocols and follows the relevant best practices: IA-02, IA-05, AC-03, IA-08, SC-23 (85%)
- MASVS-AUTH-2 The app performs local authentication securely: IA-02, IA-05, IA-07, SC-13, AC-07 (75%)
- MASVS-AUTH-3 The app secures sensitive operations with additional authentication: IA-10, AC-03, IA-02, IA-11, SC-23 (80%)
- MASVS-CODE-1 The app requires an up-to-date platform version: SI-02, CM-06, SA-22, CM-02 (80%)
- MASVS-CODE-2 The app has a mechanism for enforcing app updates: SI-02, CM-03, SA-22, CM-02 (75%)
- MASVS-CODE-3 The app only uses software components without known vulnerabilities: RA-05, SI-02, SA-11, SR-03, CM-08 (85%)
- MASVS-CODE-4 The app validates and sanitizes all untrusted inputs: SI-10, SI-16, SA-11, SC-18 (85%)
- MASVS-CRYPTO-1 The app employs current strong cryptography and uses it according to industry best practices: SC-13, SC-12, SA-08, CM-06 (90%)
- MASVS-CRYPTO-2 The app performs key management according to industry best practices: SC-12, SC-17, SA-08, CM-06 (90%)
- MASVS-NETWORK-1 The app secures all network traffic according to the current best practices: SC-08, SC-13, SC-23, AC-17, SC-07 (90%)
- MASVS-NETWORK-2 The app performs identity pinning for all remote endpoints under the developer's control: SC-08, SC-17, SC-23, IA-05 (70%)
- MASVS-PLATFORM-1 The app uses IPC mechanisms securely: AC-04, SC-07, AC-03, CM-07, SI-10 (75%)
- MASVS-PLATFORM-2 The app uses WebViews securely: SI-10, SC-07, CM-07, SA-11, AC-04 (70%)
- MASVS-PLATFORM-3 The app uses the user interface securely: SC-04, AC-04, SI-11, PE-18 (60%)
- MASVS-PRIVACY-1 The app minimizes access to sensitive data and resources: PT-02, PM-25, AC-06, AC-03, PT-03 (80%)
- MASVS-PRIVACY-2 The app prevents identification of the user: PT-02, PT-06, PM-25, SA-08 (65%)
- MASVS-PRIVACY-3 The app is transparent about the collection and use of data: PT-04, PT-05, PT-03, PL-04 (70%)
- MASVS-PRIVACY-4 The app offers user control over their data: PT-04, PT-05, PT-06, AC-03, PT-03 (70%)
- MASVS-RESILIENCE-1 The app validates the integrity of the platform: SI-07, SI-06, SA-11, CM-14 (65%)
- MASVS-RESILIENCE-2 The app implements anti-tampering mechanisms: SI-07, SA-08, CM-14, SC-13 (55%)
- MASVS-RESILIENCE-3 The app implements anti-static analysis mechanisms: SA-08, SI-07, SC-13 (40%)
- MASVS-RESILIENCE-4 The app implements anti-dynamic analysis mechanisms: SA-08, SI-07, SC-13, SI-04 (40%)
- MASVS-STORAGE-1 The app securely stores sensitive data: SC-28, SC-12, SC-13, MP-06, AC-03 (85%)
- MASVS-STORAGE-2 The app prevents leakage of sensitive data: SC-04, SI-11, AU-02, AC-04, SC-28 (80%)

## More
- A pattern's controls with their clauses in this framework: /api/v1/patterns/{id}/crosswalk?framework=owasp_masvs_v2
- Control-to-clause mappings as JSON: /api/v1/frameworks/owasp_masvs_v2?fields=mappings&per_page=100
- Rationale and gaps for each clause, as JSON: https://raw.githubusercontent.com/opensecurityarchitecture/osa-data/main/data/framework-coverage/owasp-masvs-v2.json
- Page for people: /frameworks/owasp-masvs-v2/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
