OWASP MASVS
Storage

OWASP MASVS OWASPMASVS-1: MASVS-STORAGE: Storage of Sensitive Data

Per OWASP MASVS v2 MASVS-STORAGE: secure storage of sensitive data on mobile devices. Requirements include (a) identify + classify sensitive data handled by the app (credentials + tokens + personal data + financial + health + behavioural data) + (b) use the platform-provided secure storage facilities (Android Keystore + iOS Keychain + secure enclaves) for sensitive data + (c) avoid storing sensitive data in shared storage + logs + screenshots + clipboard + keyboard cache + backups + (d) implement encryption at rest with keys protected by hardware-backed storage where available + (e) clear sensitive data from memory + UI + caches when no longer needed + (f) implement secure backup handling preventing sensitive data inclusion + (g) restrict permission justification for storage access.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 50 controls across 32 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CFR211-G-122 Section 211.122 - Materials Examination and Usage Criteria
  • CFR211-G-125 Section 211.125 - Labeling Issuance
  • CFR211-G-130 Section 211.130 - Packaging and Labeling Operations

ISO/IEC 27043:2015 · 3 controls

  • ISO27043-06 Asset inventory and ownership
  • ISO27043-08 Information classification and labeling
  • ISO27043-10 Media management and disposal

ISO/SAE 21434 · 3 controls

  • ISO21434-07 Acceptable use of assets
  • ISO21434-08 Information classification and labeling
  • ISO21434-09 Asset handling procedures

NIST SP 800-61 Rev. 3 · 3 controls

  • NISTSP61-1 Incident Response Policy, Plan, and Procedures
  • NISTSP61-3 Preparation: Communications, Toolkits, Training, Exercises, Threat Intelligence
  • NISTSP61-4 Detection and Analysis: Sources, Triage, Categorisation, Prioritisation
  • CPG-2.A Asset Inventory
  • CPG-2.B Prohibit Connection of Unauthorized Devices

ISO/IEC 27010:2015 · 2 controls

  • 27010-8.1 Membership Onboarding
  • 27010-8.2 Membership Termination

MITRE ATT&CK · 2 controls

NIST SP 800-88 · 2 controls

  • NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework
  • NISTSP88-5 Media Inventory, Tracking, Chain of Custody, and Sanitization Records

NIST SP 800-92 · 2 controls

  • NISTSP92-2 Log Generation: OS, Application, Security Tools, Network, Cloud, Required Event Content
  • NISTSP92-7 Privacy in Logs, Sensitive Content Handling, Cloud and SaaS Log Considerations

API 1164 · 1 control

  • API1164-02 Risk Management Framework

BSI IT-Grundschutz · 1 control

  • BSI-15 Security categorization
  • QMSR-820.45 Device labelling and packaging controls (§820.45)
  • 60601-1.7.1 Equipment identification and marking

IEC 62443 · 1 control

  • IEC62443-02 System security categorization
  • ISO-14064-1-5.4 Categorization of indirect GHG emissions

ISO/IEC 27019:2024 · 1 control

  • ISO27019-02 System security categorization

MTCS (Singapore) · 1 control

  • MTCS-Acquisition-Development-Maintenance-Supplier-Vulnerability-DevSecOps-SBOM-SDLC-SCA-API-Container MTCS Acquisition + Development + Maintenance + Supplier + Vulnerability + DevSecOps + SBOM + SDLC + SCA
  • NAIC-2 Information Security Program (ISP) - Section 4
  • NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material

NIST SP 800-123 · 1 control

NIST SP 800-137 · 1 control

  • NISTSP137-1 ISCM Strategy, Governance, and Volatility Assessment

NIST SP 800-144 · 1 control

  • NISTSP144-5 Identity and Access in Cloud, Federation, and Privileged Access

NIST SP 800-145 · 1 control

  • NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition

NIST SP 800-146 · 1 control

NIST SP 800-63-4 · 1 control

  • NISTSP63R4-7 Privacy, Records Retention, and User-Controlled Wallets

OECD AI Principles · 1 control

  • OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection
  • OMANCS-4 Data Protection, Cryptography, and Privacy Alignment

OpenSSF Scorecard · 1 control

  • OSSFSC-2 Dependency Management, Pinning, Updates, Vulnerability Tracking
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 50 it maps to, and the evidence behind each claim, over MCP and REST.