500 ARTICLES

All guides · Page 6

Browse by topic, or search for a specific concept, tool or platform.

Standards and evidence1 min

Defining application protection scope with OWASP MASVS

MASVS provides a shared requirements framework that extends beyond reverse-engineering resistance.

Read the guide
Standards and evidence1 min

OWASP MASTG: planning mobile security tests

MASTG helps turn security requirements into concrete test questions. Defined packages, device conditions and expected outcomes make reports reproducible.

Read the guide
Standards and evidence1 min

OWASP MASWE: a common language for mobile weaknesses

MASWE provides consistent terminology for mobile weaknesses. Classification still needs the application's actual impact and remediation context.

Read the guide
Standards and evidence1 min

Turning a mobile security checklist into evidence

A checked box does not show that a control works. Connect every item to a design decision, executed test and examined artifact.

Read the guide
Standards and evidence1 min

MASVS-RESILIENCE-1: platform integrity and device signals

Platform-integrity assessment explains which environment signals the application trusts. Review scope, unsupported conditions and false-positive effects together.

Read the guide
Standards and evidence1 min

MASVS-RESILIENCE-2: evidence of application integrity

Writing an integrity requirement and assessing tampering in a final package are separate tasks.

Read the guide
Standards and evidence1 min

MASVS-RESILIENCE-3: measuring resistance to static analysis

Success does not mean making all code invisible. Set realistic objectives around specific assets and the effort required to understand them.

Read the guide
Standards and evidence1 min

MASVS-RESILIENCE-4: resistance to dynamic analysis

Dynamic analysis examines interference with a running application. Blocking one research tool does not establish that the entire business risk is controlled.

Read the guide
Standards and evidence1 min

Using the OWASP Mobile Top 10

The Mobile Top 10 is a starting point for discussing common risks, not an exhaustive acceptance standard for every application.

Read the guide
Standards and evidence1 min

OWASP ASVS and the mobile back end

A mobile application's back end has its own requirements. ASVS helps assess that layer; client protection does not remove server controls.

Read the guide
Standards and evidence1 min

API Security Top 10 and application protection signals

APIs can expose abuse paths independently of the mobile package. Assess object, function and resource-consumption controls alongside client evidence.

Read the guide
Standards and evidence1 min

Building scenarios with MITRE ATT&CK Mobile

ATT&CK Mobile helps describe threat behavior. Mapping a technique name to a product feature does not prove effectiveness in an application.

Read the guide
Standards and evidence1 min

Classifying mobile security findings with CWE

CWE provides a shared weakness vocabulary. Classification does not replace an explanation of reachable code and business impact.

Read the guide
Standards and evidence1 min

Applying CVSS v4.0 to mobile findings

CVSS helps describe technical severity consistently. Product priority also depends on data value, reachability and business impact.

Read the guide
Standards and evidence1 min

NIST SSDF: placing RASP in secure development

SSDF addresses security across the development lifecycle. A protection product can contribute a control but does not assume responsibility for source, supply chain or…

Read the guide
Standards and evidence1 min

NIST CSF and application protection governance

CSF connects technical controls with organizational risk management. Evaluate mobile protection through ownership, measurement and improvement plans.

Read the guide
Standards and evidence1 min

SLSA and mobile build provenance

SLSA supports discussion of build and supply-chain trust. Keep source provenance connected to the final protected mobile artifact.

Read the guide
Standards and evidence1 min

SPDX for mobile component and license inventories

SPDX supports sharing component and license information. Matching inventories to final packages makes dependency decisions traceable.

Read the guide
Standards and evidence1 min

VEX: explaining whether a vulnerability affects a product

VEX communicates whether a particular vulnerability affects a particular product. An unaffected statement needs technical reasoning and evidence.

Read the guide
Standards and evidence1 min

Mobile application security in a PCI DSS context

A protection SDK is only one part of a payment-data architecture. Assess data flows, scope and operational controls against applicable requirements.

Read the guide
Standards and evidence1 min

PCI MPoC and accepting payments on phones

Phone-based payment acceptance includes monitoring and solution components beyond application code. MPoC assessment cannot be reduced to one RASP feature.

Read the guide
Standards and evidence1 min

Designing RASP telemetry with KVKK in mind

Mobile security events may contain personal data. Technical design should clarify necessity, access and retention, with legal assessment handled separately.

Read the guide
Standards and evidence1 min

Mobile security data in a GDPR context

Telemetry linked to a person or device can raise data-protection questions. Assess fields, purpose, transfers and retention against actual application behavior.

Read the guide
Standards and evidence1 min

ISO/IEC 27001 and managing mobile security controls

Control ownership, implementation and evidence matter in an ISO/IEC 27001 context. Buying a protection product does not complete a management system.

Read the guide
Standards and evidence1 min

What a SOC 2 report says about a RASP supplier

A SOC 2 report provides information about a defined system and period. Its existence does not mean your mobile application passed an independent security test.

Read the guide
Industry use cases1 min

Application protection in mobile banking

Viewing balances, adding recipients and transferring funds carry different loss scenarios.

Read the guide
Industry use cases1 min

RASP for SoftPOS and mobile payment acceptance

When a phone accepts payments, protection decisions affect sales continuity.

Read the guide
Industry use cases1 min

Application protection and key security in crypto wallets

Key generation, storage, backup and transaction approval matter alongside application integrity.

Read the guide
Industry use cases1 min

RASP, cheating and economy security in mobile games

Client resilience and game-economy rules belong together. Rewards and competitive outcomes must not rely solely on modifiable device values.

Read the guide
Industry use cases1 min

RASP for e-commerce accounts, coupons and payments

Accounts, promotions and payment flows have different abuse risks. Application protection should complement correct server-side business rules.

Read the guide
Industry use cases1 min

Application protection and continuity in healthcare apps

Healthcare applications must manage sensitive data and access continuity together.

Read the guide
Industry use cases1 min

RASP, MDM and privacy in BYOD applications

An enterprise application on a personal phone lacks the same authority as a fully managed device.

Read the guide
Industry use cases1 min

Application protection for public-service apps

Public services need security and broad access. Include older devices, accessibility and account recovery in protection acceptance.

Read the guide
Industry use cases1 min

RASP and DRM in video and media applications

DRM manages content rights while application protection addresses selected client risks. Keep their scopes distinct.

Read the guide
Industry use cases1 min

Protecting insurance documents and claims

Documents, claims and payment details need different validation. Secure file transport does not prove a claim is genuine or a user is authorized.

Read the guide
Industry use cases1 min

RASP and delivery records in logistics apps

Delivery applications combine offline records, location and uploads. Device signals should not be treated as proof that a business record is correct.

Read the guide
Industry use cases1 min

Location, driver and transaction security in transport apps

Transport applications combine location, driver accounts and payments. Make decisions from transaction context rather than one device label.

Read the guide
Industry use cases1 min

Booking and account security in travel apps

Booking and account changes can have lasting financial consequences. Client integrity needs server controls for ownership and repeated operations.

Read the guide
Industry use cases1 min

The limits of RASP in education and exam apps

Device controls can affect learning and accessibility. Local protection must not be presented as preventing every form of copying or outside assistance.

Read the guide
Industry use cases1 min

Protecting line and account changes in telecom apps

Line and account changes are more consequential than routine profile edits. Combine device context with authentication and transaction approval.

Read the guide
Industry use cases1 min

Application protection for IoT control apps

IoT applications can affect physical devices. Verify relationships between mobile accounts, device registrations and command authority.

Read the guide
Industry use cases1 min

Shared RASP policies in super apps

Different business modules may share one session. Policies should reflect each module's data and transaction risks rather than imposing one global response.

Read the guide
Industry use cases1 min

RASP integration for fintech SDK developers

A fintech SDK runs inside another organization's application. Define protection coverage, data responsibilities and failures through an explicit integration contract.

Read the guide
Industry use cases1 min

RASP policies for offline field applications

Offline field work operates with limited assurance. Later validation, conflict resolution and authorization lifetime are core design concerns.

Read the guide
Industry use cases1 min

Where small teams should start with application protection

Small teams should establish high-impact fundamentals first. Advanced runtime products cannot balance missing key storage, API authorization or secure delivery.

Read the guide
Industry use cases1 min

Build or buy RASP controls?

Building and buying distribute maintenance responsibility differently. Platform changes, test capacity and response work make the decision broader than licensing.

Read the guide
Industry use cases1 min

Comparing application protection, Play Integrity and App Attest

Runtime protection and platform attestation provide different trust sources.

Read the guide
Industry use cases2 min

An impartial guide to comparing application protection products

Compare products using the same package and tests. Marketing features are a starting point; security effects, user experience and operational work require observation.

Read the guide
Industry use cases1 min

RASP for enterprise approval applications

Approval requires knowing what was authorized as well as who approved it. Verify documents, amounts and privilege changes in their transaction context.

Read the guide
Industry use cases1 min

Protecting loyalty points and campaigns

Loyalty points and promotions are valuable business assets. A healthy device signal does not create unlimited reward entitlement.

Read the guide