Best Practices
NowSecure recently partnered with Coalfire to contribute mobile risk data to the cybersecurity advisory company’s 4th Annual Penetration Risk Report. The report findings reveal the importance of continuous testing in vulnerability management combined with human-based testing to reduce risk. The most successful vulnerability and risk management programs are no longer focused on point-in-time schedules but […]
If you learned there was a way to reduce mobile application security testing costs by up to 85% and achieve a 10x gain in productivity, wouldn’t that be compelling? Replacing manual mobile pen testing with integrated mobile application security testing in the software development lifecycle yields significant savings and productivity gains and simultaneously reduces risk. […]
A Software Bill of Materials (SBOM) catalogs all libraries, dependencies and transitive dependencies present in an application. This critical piece of the development and security puzzle allows development and security teams to identify outdated, unlicensed or untrusted first-party and third-party libraries that require updates or removal. Mobile app development and security teams can use SBOMs […]
Only 22% of developers have a clear understanding of which security policies they are expected to comply with, according to the “Bridging the Developer and Security Divide” study conducted by Forrester Consulting on behalf of VMware. For many organizationes, adopting mobile security standards such as OWASP Mobile Application Security Project Verification Standards (MASVS) can play […]
Highly regulated and strongly-branded organizations and organizationes that embrace industry standards should ensure that their mobile apps comply with the OWASP Mobile Application Security Verification Standard (MASVS) security requirements. To support these needs, NowSecure recently expanded its expert mobile application penetration tests to offer OWASP MASVS compliance and incorporated OWASP MASVS findings into NowSecure Platform […]
Healthcare mobile application developers now face heightened scrutiny over security and privacy vulnerabilities. The American Medical Association (AMA) recently encouraged companies that make mHealth apps and connected devices that collect health information to adopt privacy by design principles. And in 2022, all mHealth app makers must comply with the Federal Trade Commission’s Health Breach Notification […]
Mobile application security professionals following best practices for OWASP Mobile Application Security Testing now have a new resource to enhance their efficiency. As part of a series of updates to the OWASP MASVS and OWASP MASTG, the OWASP Mobile Application Security Project recently released a new fully automated version of its OWASP Mobile Application Security […]
Hurrying to meet an aggressive deadline, your mobile application development team will soon complete major updates to the company’s flagship Android and iOS applications. The project progresses smoothly until you discover that one major obstacle stands in the way of on-time release: nobody remembered to line up mobile penetration testing to validate mobile application security. […]
Escalating software supply-chain attacks pose a serious threat to the public sector and organizationes. Adversaries exploit vulnerabilities in third-party code to compromise a supplier to the vast digital ecosystem downstream. The ripple effect causes widespread disruption, financial loss and reputational damage and even endangers national security. Consider the enormous impact the SolarWinds software supply chain […]
Mobile app developers constantly face pressure to catch up with or leap ahead of the competition. Innovative mobile features certainly improve the user experience, but the accelerated pace of mobile app development often shortchanges security. DevSecOps teams can speed the delivery of high-quality mobile apps by performing continuous security testing throughout the software development lifecycle […]