Define Common MASTG Mitigations #2026
cpholguera
started this conversation in
Ideas
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
If we'd have common mitigations defined we could always refer back to specific MASTG Mitigation which would have a certain ID and suggest those on pentest reports.
We could get some ideas from here (note that these are mobile device specific and we need app specific): https://attack.mitre.org/mitigations/mobile/
When testing for a specific MASVS ID, we'd perform one or more MASTG tests (also have ID) and suggest a mitigation (also clearly identified with an ID) or at least a mitigation based on / related to a MSTG one.
Example for "Testing MASVS-NETWORK-1", mitigations include:
As of now we offer mitigation sometimes and each time a new one (merged in the text, each time new text). We could reduce work by having a list of mitigations and extending it if needed. Many tests will need the same one such as "Application Developer Guidance" or "User Guidance".
Beta Was this translation helpful? Give feedback.
All reactions