Replies: 2 comments
-
That's a valid point, and we should think about rephrasing this. I would love to say 'let the OS do it for you', but with all the third party frameworks that's probably not clear/secure enough. |
Beta Was this translation helpful? Give feedback.
-
You are right, there are more checks that can be done, see: https://cwe.mitre.org/data/definitions/295.html However, we have to keep the abstraction level of the MASVS and leave the details for the MSTG. This is already being considered in the MSTG (search for MSTG-NETWORK-3 and you'll find the mentioned checks as part of the test case). Still, we should reformulate this to reflect that abstraction a bit better. |
Beta Was this translation helpful? Give feedback.
-
The requirement for MSTG-NETWORK-3 is:
Is this sufficient as a requirement for this topic?
What about additional checks like:
Beta Was this translation helpful? Give feedback.
All reactions