Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

MASTG v2.0: what machine-readable mobile security testing changes


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 12754
Topic starter  

TL;DR: OWASP MASTG v2.0 replaces narrative mobile testing guidance with an 860-plus component knowledge graph that maps MASVS controls to MASWE weaknesses, atomic tests and demos, giving teams audit-ready evidence and automation hooks, according to NowSecure. The shift makes mobile AppSec measurable, but only if organisations treat control coverage as an operational discipline rather than a reporting exercise.

NHIMG editorial — based on content published by NowSecure: MASTG v2.0 and the machine-readable future of mobile app security testing

By the numbers:

Questions worth separating out

Q: What breaks when mobile security testing is not mapped to control evidence?

A: Teams lose traceability between what was tested and what was actually controlled.

Q: Why does mobile AppSec matter to IAM and secrets governance?

A: Mobile apps often store or transport credentials, tokens and certificates, which means they sit close to identity trust boundaries.

Q: How do teams know whether mobile testing coverage is actually working?

A: Look for explicit mapping from standards to tests, stable identifiers, and pass or fail conditions that can be replayed.

Practitioner guidance

  • Map mobile tests to control IDs Require every mobile test result to reference MASVS, MASWE and the specific MASTG test so evidence can be traced from requirement to validation.
  • Separate static, dynamic and manual checks Assign tooling based on the test type field so static binary analysis, runtime inspection and manual verification do not collapse into one unreviewable workflow.
  • Build audit-ready evidence packs Store the test result, failing observation and evaluation condition together with the mapped control so auditors can replay why a control passed or failed.

What's in the full article

NowSecure's full article covers the operational detail this post intentionally leaves for the source:

  • The full traceability model for MASVS control to MASWE weakness to MASTG test mapping.
  • The specific atomic test structure, including Steps, Observation and Evaluation fields.
  • The automation and CI/CD integration details for mobile application security pipelines.
  • The release background and contributor activity behind the three-year refactor.

👉 Read NowSecure's analysis of MASTG v2.0 and mobile control evidence →

MASTG v2.0: what machine-readable mobile security testing changes?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 12338
 

Machine-readable testing is becoming a governance requirement, not a documentation preference. MASTG v2.0 reflects a broader shift in AppSec from descriptive guidance to control evidence. When security standards can be parsed, mapped and validated, they become easier to operationalise across pipelines, third-party assessments and internal assurance. For identity and mobile risk teams, that means the evidence layer can finally match the control layer.

A question worth separating out:

Q: Should organisations compare mobile security vendors on scan volume or control coverage?

A: Control coverage is the more defensible measure because scan volume says little about whether the right weaknesses were evaluated. A mature programme can show which MASVS controls were exercised, which weaknesses were tested and where gaps remain. That is a better procurement and assurance signal than raw finding counts.

👉 Read our full editorial: MASTG v2.0 turns mobile app security testing into machine-readable control evidence



   
ReplyQuote
Share: