Standards · Knowledge base
Mobile Security Standards & Frameworks
Plain-English explainers of the standards that define mobile app security, from OWASP MASVS to PCI DSS and GDPR, and how Mobexa maps findings to each one. Written and maintained by the Mobexa research team.
Every Mobexa finding maps to a recognised control. These explainers describe the standards behind those mappings. Select any one for the full write-up.
| Standard | Type |
|---|---|
|
OWASP MASVS
The OWASP standard that defines what a secure mobile app should do, grouped into control areas. |
Mobile standard |
|
OWASP MASTG
The OWASP guide that explains how to test each MASVS requirement on a real app. |
Mobile standard |
|
OWASP Mobile Top 10
The ten most common mobile app security risk categories, used as a checklist. |
Mobile standard |
|
PCI DSS (mobile)
The payment-card security standard, applied to apps that handle card or payment data. |
Regulation |
|
GDPR (mobile)
The EU data-protection regulation, applied to apps that handle personal data. |
Regulation |
|
ISO 27001 (mobile)
The information-security management standard, and where mobile app testing fits. |
Framework |
|
NIST SSDF
The NIST framework of practices for building software securely. |
Framework |
|
HIPAA (mobile)
The US health-data rule, applied to apps that handle protected health information. |
Regulation |
|
KVKK (mobile)
Turkey data-protection law, applied to apps that handle personal data. |
Regulation |
|
DORA (mobile)
The EU operational-resilience regulation for financial firms, and where mobile testing fits. |
Regulation |
|
SOC 2
The trust-services criteria used to show a service handles data securely. |
Framework |
|
NIST 800-163 (App Vetting)
NIST guidance for vetting a mobile app before it is approved for use. |
Framework |
|
CCPA (mobile)
California privacy law, applied to apps that handle personal information. |
Regulation |
|
PSD2 (mobile)
EU payment rules, including strong customer authentication, applied to banking apps. |
Regulation |
|
OWASP ASVS
The general application security verification standard, alongside the mobile MASVS. |
Framework |
|
App Store & Play requirements
The security and privacy rules the app stores enforce, including data safety and privacy labels. |
Store requirement |
|
ISO 27034
The standard for building security into the application lifecycle. |
Framework |
New to the terms? Start with the glossary. See how mapping works in framework coverage.