Archives

NowSecure Announces New Pen Testing Service and Software for OWASP MASVS Compliance

NowSecure Announces New Pen Testing Service and Software for OWASP MASVS Compliance logo/IT digest
NowSecure Announces New Pen Testing Service and Software for OWASP MASVS Compliance logo/IT digest

NowSecure, the leading standards-based mobile app security and privacy software company,  announced the world’s most comprehensive mobile app pen testing service for the OWASP Mobile Application Security Verification Standard (MASVS) and the addition of automated MASVS testing to NowSecure Platform. Now mobile organizations, mobile app developers and security teams can turn to NowSecure experts for the gold standard of mobile app testing to ensure proper compliance with the OWASP MASVS.

Mobile apps drive the global economy and 200 billion downloaded mobile apps generated over $170 billion in revenue in 2021. With more than 70% of all digital time spent in mobile apps vs. web apps, mobile is the preferred interface for customers and employees alike. But attacks and breaches also grew alarmingly in the past year with Amazon Ring, Apple iMessage, Park Mobile, Slack and U.S. Customs and Border Protection all experiencing major mobile app security incidents. Overall 85% of tested apps have security vulnerabilities and 70% leak private data as shown in the NowSecure MobileRiskTracker™. Organizations need to be vigilant about building security into their mobile apps and testing rigorously to ensure safety.

Launched in 2013, the OWASP mobile project has driven standards-based security requirements and testing strategies for nearly a decade. Used by mobile app developers, architects, security teams and security researchers, the OWASP mobile project combines three critical resources last updated in January 2022 to provide the best risk reduction approach for mobile app teams:

OWASP Mobile Application Security Verification Standard (MASVS) establishes a baseline of security requirements for mobile apps
OWASP Mobile Security Testing Guide (MSTG) outlines how to test the MASVS requirements
OWASP Mobile App Security Checklist tracks security assessment tasks
NowSecure has contributed to the OWASP mobile project since its inception with NowSecure practitioners collaborating on spec evolution and tooling while the company serves as an OWASP “god mode” sponsor for the OWASP MASVS.

Also Read: Privacy-Preserving Computation Network PlatON Launches Version 3.0, Leading New Direction in Universal AI

The OWASP MASVS and MSTG are the foundation of a mobile appsec program,” said Carlos Holguera, OWASP project lead and NowSecure Security Researcher. “The MASVS guides developers and security analysts on architecture, threat modeling and proper techniques to secure mobile data. The MSTG has hundreds of tests you should perform and there are many nuances and edge cases to consider. Without the right expertise it can be tough to effectively achieve full MASVS compliance. The MSTG encourages the use of automated tools to leverage static and dynamic analysis but also emphasizes that having security professionals you can trust is essential.”

Over the past decade, NowSecure Services has performed more than 10,000 mobile app pen tests across a broad variety of mobile apps and industries. NowSecure offers a full slate of pen testing services including rapid, targeted, full-scope and certifications. NowSecure offers services and software for ioXt certification for IoT-connected mobile apps as an authorized ioXt certification lab and National Information Assurance Partnership (NIAP) compliance for the mobile app protection profile. Today NowSecure adds OWASP MASVS pen testing services to the list of available expert-led certifications. Built up over years of experience, NowSecure pen testing services follow a rigorous methodology partnering with mobile app development and security teams including assessment kickoff,