Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Sync MASVS with OWASP Mobile Security project #189

Closed
27 tasks done
sushi2k opened this issue Dec 11, 2018 · 28 comments
Closed
27 tasks done

Sync MASVS with OWASP Mobile Security project #189

sushi2k opened this issue Dec 11, 2018 · 28 comments

Comments

@sushi2k
Copy link
Collaborator

sushi2k commented Dec 11, 2018

Check the requirements listed here and verify if covered or should be added to MASVS:

Actionlist based on top 10 mobile controls:

Actionlist based on Mobile top 10 2016:

@A-AFTAHI
Copy link
Contributor

A-AFTAHI commented Jul 7, 2019

I'm working on this

@commjoen
Copy link
Collaborator

commjoen commented Jul 8, 2019

Great! What is your current status /planning on this subject @A-AFTAHI ? We want to reshape the current owasp wiki and this issue will have to be fixed in order to make everything a bit more consequent ^^.

@commjoen
Copy link
Collaborator

Mobile-Sec-Project_Syn_MASVS.xlsx
First analysis as done by @A-AFTAHI . Will be discussed upcoming tuesday in a call.

@sushi2k
Copy link
Collaborator Author

sushi2k commented Jul 21, 2019

Great work @A-AFTAHI. Let me have a look at it. I might be able to join the call also.

@sushi2k
Copy link
Collaborator Author

sushi2k commented Jul 21, 2019

Mobile-Sec-Project_Syn_MASVS-Sven.xlsx

Please find my feedback here. @commjoen let me know when you have the call. Cheers

@commjoen
Copy link
Collaborator

Tuesday 19:00 dutch time :-)

@commjoen
Copy link
Collaborator

Mobile-Sec-Project_Syn_MASVS-Sven_remarks_aftahi_jeroen.xlsx
Updated feedback with @A-AFTAHI , will compile actionlist.

@A-AFTAHI
Copy link
Contributor

Thanks @commjoen for the Update!

@commjoen
Copy link
Collaborator

commjoen commented Jul 24, 2019

Moved all actions to the top of the issue to track progress

@commjoen
Copy link
Collaborator

commjoen commented Jul 24, 2019

@A-AFTAHI
Copy link
Contributor

The First version of the excel was only based on https://www.owasp.org/index.php/OWASP_Mobile_Security_Project#Secure_M-Development , and since the current version is based on the first one so we have to make sure that everything in https://www.owasp.org/index.php/OWASP_Mobile_Security_Project#Top_10_Mobile_Controls is already covered.
let me check that

@commjoen
Copy link
Collaborator

Okidoki. Let me know when you have somethign to review which includes that, so we can extend and start executing the actions listed at #189 (comment)

@commjoen
Copy link
Collaborator

All MSTG actions based on #189 (comment) have been created. the MASVS issues can be fixed in 1 PR.

@commjoen commjoen moved this from To do to In progress in MASVS project Jul 27, 2019
@A-AFTAHI
Copy link
Contributor

Mobile-Sec-Project_&Mobile_Top10_Syn_MASVS-Sven_remarks_aftahi_jeroen.xlsx
He is the excel file updated with my Mobile Top 10 Analysis. please take a look at it and review my interpretations.

@commjoen
Copy link
Collaborator

Mobile-Sec-Project_.Mobile_Top10_Syn_MASVS-Sven_remarks_aftahi_jeroen_version 1.xlsx
Please find my comments. which top 10 is this? 2013? because 2016 has different items i believe (https://www.owasp.org/index.php/Mobile_Top_10_2016-Top_10)

@A-AFTAHI
Copy link
Contributor

A-AFTAHI commented Jul 28, 2019

You're right! in 2016 there are different items. well my analysis was based on the TOP 10 in the link initially suggested by @sushi2k https://www.owasp.org/index.php/OWASP_Mobile_Security_Project#Top_10_Mobile_Controls

@commjoen
Copy link
Collaborator

Can you do both please? Just add a few rows and we are fine :-)

A-AFTAHI added a commit to A-AFTAHI/owasp-masvs that referenced this issue Jul 29, 2019
… are the following: 1.11 (V1) | 2.13 & 2.14 (V2) | 4.12 & 4.13 (V4)
@A-AFTAHI
Copy link
Contributor

Mobile-Sec-Project_.Mobile_Top10_Syn_MASVS-Sven_remarks_aftahi_jeroen_version.2.xlsx
Here is an updated version of the excel with mobile Top 10 2016 analysis covered!

@commjoen
Copy link
Collaborator

Thank you very much! Will review tomorrow :)

@commjoen
Copy link
Collaborator

commjoen commented Jul 30, 2019

@commjoen commjoen self-assigned this Jul 30, 2019
@commjoen commjoen moved this from In progress to Ready for review in MASVS project Aug 4, 2019
commjoen added a commit that referenced this issue Aug 12, 2019
Adding 5 new requirements based on #189 disscussion. the changes are …
commjoen added a commit that referenced this issue Aug 12, 2019
… version and should not be translated yet
@commjoen commjoen mentioned this issue Aug 12, 2019
4 tasks
@commjoen commjoen moved this from Ready for review to In progress in MASVS project Aug 12, 2019
@commjoen
Copy link
Collaborator

commjoen commented Aug 12, 2019

Executed all actions till step 16. Let's make sure we make issues out of each of the steps to take and then close this issue.

@commjoen
Copy link
Collaborator

So OWASP/ASVS#664 came back "won't fix". @sushi2k , @TheDauntless , @cpholguera , @A-AFTAHI : what do we do with this? Because having an RD makes sense to me. For now I have set up https://owasp.slack.com/archives/C04T40NND/p1565798928215600 as a discussion within OWASP.

@sushi2k
Copy link
Collaborator Author

sushi2k commented Aug 15, 2019

Why not put a L1 requirement into V1:

A responsible disclosure policy exists that defines a communication channel to communicate identified vulnerabilities.

In the MSTG we could make a short test case, similar to https://github.com/OWASP/owasp-mstg/blob/master/Document/0x05d-Testing-Data-Storage.md#testing-the-device-access-security-policy-mstg-storage-11.

We could then reference and describe, e.g. https://securitytxt.org/. The security.txt is not a standard yet, but something that is very easy to implement and get's quite some acceptance (at least in the bug bounty community).

I know you don't wan't to have it in the MASVS, but it's part of a application security strategy/program (like threat modeling, which we also have as a requirement).

@sushi2k
Copy link
Collaborator Author

sushi2k commented Aug 15, 2019

Otherwise we could describe responsible disclosure in the MSTG and just leverage on this requirement in the MASVS:

| 1.10 | MSTG‑ARCH‑10 | Security is addressed within all parts of the software development lifecycle. | | ✓ |

Responsible Disclosure is then one way for a feedback loop for the SDLC? I know it's a bit far fetched, but then we at least don't need to touch the MASVS.

@commjoen
Copy link
Collaborator

You're right... If no one moves, we should be frontrunner. We could include http://disclose.io/ in the MSTG

@commjoen
Copy link
Collaborator

As @TheDauntless would say: let's put it in a separate issue 👍

@commjoen
Copy link
Collaborator

It is in #283

@commjoen
Copy link
Collaborator

All issues have been created or set. We are ready to close this. Thanks @A-AFTAHI for the long haul analysis!

MASVS project automation moved this from In progress to Done Sep 20, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
MASVS project
  
Done
Development

No branches or pull requests

3 participants