MASVS-NETWORK
Temporary Checklist
This checklist contains the old MASVS v1 verification levels (L1, L2 and R) which we are currently reworking into "security testing profiles". The levels were assigned according to the MASVS v1 ID that the test was previously covering and might differ in the upcoming version of the MASTG and MAS Checklist.
For the upcoming of the MASTG version we will progressively split the MASTG tests into smaller tests, the so-called "atomic tests" and assign the new MAS profiles to their respective MASWE weaknesses.
MASVS-ID | Platform | Control / MASTG Test | L1 | L2 | R |
---|---|---|---|---|---|
MASVS-NETWORK-1 | The app secures all network traffic according to the current best practices. | ||||
Testing the Security Provider | |||||
Testing the TLS Settings | |||||
Testing Data Encryption on the Network | |||||
Testing Endpoint Identify Verification | |||||
Testing the TLS Settings | |||||
Testing Endpoint Identity Verification | |||||
Testing Data Encryption on the Network | |||||
MASVS-NETWORK-2 | The app performs identity pinning for all remote endpoints under the developer's control. | ||||
Testing Custom Certificate Stores and Certificate Pinning | |||||
Testing Custom Certificate Stores and Certificate Pinning |