HomeStandards › OWASP ASVS

Framework

OWASP ASVS and mobile apps

What is OWASP ASVS?

The OWASP Application Security Verification Standard (ASVS) is a list of security requirements for applications in general. It is the broad, application-wide counterpart to the mobile-specific MASVS, covering areas such as authentication, access control, data handling and communications.

Teams use ASVS as a shared definition of what a secure application should do, much as MASVS does for mobile specifically.

ASVS and MASVS together

The two overlap and complement each other. A mobile product usually has both an app and a backend, so MASVS covers the app on the device while ASVS covers the wider application and its server side. Many requirements, such as sound authentication and proper data handling, appear in both.

How Mobexa relates

Mobexa focuses on the mobile app and maps findings to MASVS. For teams that verify the whole product against ASVS, the mobile testing and evidence Mobexa produces cover the app-side requirements that overlap with ASVS.

Common questions

What is the difference between ASVS and MASVS?
ASVS sets security requirements for applications in general, including web and backend. MASVS is the mobile-specific standard for Android and iOS apps. They share many ideas; MASVS goes deeper on mobile-only concerns such as on-device storage and platform interaction.

Mobexa maps every finding on your Android and iOS builds to OWASP ASVS and the other standards an auditor recognises.

Start Free Trial