NIST SP 800-124 Revision 2 - Guidelines for Managing the Security of Mobile Devices
Mobile Device Security Technologies

NIST SP 800-124 Revision 2 - Guidelines for Managing the Security of Mobile Devices MD124-TECH-03: Mobile Application Vetting

Establish a mobile application vetting process to evaluate app security before deployment. Assess apps for malware, privacy violations, and vulnerabilities.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 38 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ASD37-06 Email content filtering (Excellent)
  • ASD37-12 Antivirus software with heuristics (Very Good)
  • ASD37-16 Antivirus software with signatures (Limited)

API 1164 · 1 control

  • API1164-12 Incident Response
  • CJIS-10 System and Information Integrity

IEC 62443 · 1 control

  • IEC62443-12 Malware prevention for operational systems

ISO/IEC 27010:2015 · 1 control

  • 27010-12.2 Protection from malware

ISO/IEC 27011:2024 · 1 control

  • 27011-8.5 Vulnerability and malware management

ISO/IEC 27019:2024 · 1 control

  • ISO27019-12 Malware prevention for operational systems

ISO/IEC 27043:2015 · 1 control

  • ISO27043-22 Protection from malware

ISO/SAE 21434 · 1 control

  • ISO21434-22 Protection from malware

MITRE ATT&CK · 1 control

NERC CIP · 1 control

  • NERCCIP-5 System Security Management + Configuration Change Management and Vulnerability Assessments (CIP-007 + CIP-010)

NIST SP 1800-32 · 1 control

  • NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material

NIST SP 800-123 · 1 control

  • NISTSP123-5 Server Operations - Patching, Malware, Logging, Backup

NIST SP 800-137 · 1 control

  • NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring
  • NISTSP61-5 Containment, Eradication, and Recovery

NIST SP 800-63-4 · 1 control

  • NISTSP63R4-8 Operational Audit, Session Management, Recovery, and Cross-cutting Controls
  • NISTSP82-5 OT Configuration Management, Patching, Vulnerability Management, and Malware Protection

NIST SP 800-88 · 1 control

  • NISTSP88-7 Verification, Audit, Training, and Environmental/Safety Controls

NIST SP 800-92 · 1 control

  • NISTSP92-5 Log Analysis: Correlation, Baselining, Anomaly Detection, Alerting, Manual Review

OWASP SAMM · 1 control

  • OWASPSAMM-5 Operations: Incident Management, Environment Management, Operational Management

OpenSSF Scorecard · 1 control

  • OSSFSC-4 Security Policy, Vulnerability Disclosure, Responsible Reporting

PTES · 1 control

  • PTESPHASE-3 Threat Modeling
  • PICERL-E1 Threat Removal
  • SHAREASSESS-4 Vulnerability Management, Patching, Application Security

SLSA · 1 control

  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Mobile Device Security Technologies

Query this from an agent

The graph holds this control, the 38 it maps to, and the evidence behind each claim, over MCP and REST.