OWASP MASVS
Code Quality and Build

OWASP MASVS OWASPMASVS-6: MASVS-CODE: Code Quality, Build Settings, and Updates

Per OWASP MASVS v2 MASVS-CODE: code quality + build settings + secure updates. Requirements include (a) implement secure coding practices including input validation + output encoding + memory safety + (b) use memory-safe languages + APIs where possible + (c) implement secure build settings including code signing + debug flag removal + symbol stripping + obfuscation where appropriate + (d) maintain dependency inventory + scan for vulnerabilities + license issues + malicious packages + (e) implement secure update mechanism including signature verification + rollback prevention + (f) protect against client-side injection (XSS in WebView + SQL in local DB + similar) + (g) integrate static + dynamic + interactive application security testing + maintain test coverage.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 63 controls across 42 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ASD37-06 Email content filtering (Excellent)
  • ASD37-12 Antivirus software with heuristics (Very Good)
  • ASD37-16 Antivirus software with signatures (Limited)

ISO/IEC 30111:2019 · 3 controls

  • 30111-1 Scope
  • 30111-3 Terms and definitions
  • 30111-8.1 Post-release monitoring

ISO/IEC 27043:2015 · 2 controls

  • ISO27043-22 Protection from malware
  • ISO27043-25 Technical vulnerability management

ISO/IEC 29147:2018 · 2 controls

  • 29147-5.6 Advisory Content and Quality
  • 29147-7.8 Remediation information

ISO/SAE 21434 · 2 controls

  • ISO21434-22 Protection from malware
  • ISO21434-25 Technical vulnerability management
  • NISTSP115-3 Target Identification and Analysis - Network Discovery, Port and Service ID, Vuln Scanning
  • NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material

NIST SP 800-137 · 2 controls

  • NISTSP137-5 Vulnerability + Patch + Configuration Status Monitoring
  • NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring

OpenSSF Scorecard · 2 controls

  • OSSFSC-2 Dependency Management, Pinning, Updates, Vulnerability Tracking
  • OSSFSC-4 Security Policy, Vulnerability Disclosure, Responsible Reporting

API 1164 · 1 control

  • API1164-12 Incident Response

BSI IT-Grundschutz · 1 control

  • BSI-14 Vulnerability scanning and management
  • CPG-5.A Vulnerability Disclosure Program
  • CJIS-10 System and Information Integrity
  • CAT-D3-3 Corrective controls
  • FTC-Safeguards-ServiceProvider-Evaluation Service Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g))

IEC 62443 · 1 control

  • IEC62443-12 Malware prevention for operational systems

ISO/IEC 27010:2015 · 1 control

  • 27010-12.2 Protection from malware

ISO/IEC 27011:2024 · 1 control

  • 27011-8.5 Vulnerability and malware management

ISO/IEC 27019:2024 · 1 control

  • ISO27019-12 Malware prevention for operational systems

ISO/IEC 29134:2023 · 1 control

  • 29134-9.2 Report findings and recommendations

MITRE ATT&CK · 1 control

MTCS (Singapore) · 1 control

  • MTCS-Acquisition-Development-Maintenance-Supplier-Vulnerability-DevSecOps-SBOM-SDLC-SCA-API-Container MTCS Acquisition + Development + Maintenance + Supplier + Vulnerability + DevSecOps + SBOM + SDLC + SCA

NERC CIP · 1 control

  • NERCCIP-5 System Security Management + Configuration Change Management and Vulnerability Assessments (CIP-007 + CIP-010)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 800-123 · 1 control

  • NISTSP123-5 Server Operations - Patching, Malware, Logging, Backup

NIST SP 800-144 · 1 control

  • NISTSP144-7 Cloud Workload Protection, Containers, Serverless, and Configuration

NIST SP 800-145 · 1 control

  • NISTSP145-7 Cloud Procurement Standards Aligned to NIST SP 800-145 Definition

NIST SP 800-146 · 1 control

  • NISTSP61-5 Containment, Eradication, and Recovery

NIST SP 800-63-4 · 1 control

  • NISTSP63R4-8 Operational Audit, Session Management, Recovery, and Cross-cutting Controls
  • NISTSP82-5 OT Configuration Management, Patching, Vulnerability Management, and Malware Protection

NIST SP 800-88 · 1 control

  • NISTSP88-7 Verification, Audit, Training, and Environmental/Safety Controls

NIST SP 800-92 · 1 control

  • NISTSP92-5 Log Analysis: Correlation, Baselining, Anomaly Detection, Alerting, Manual Review
  • NRFCS-2 Risk Assessment, Customer Data Inventory, Classification, and Retail Threat Model
  • NZISM-5 Network Security, System Hardening, and Application Security
  • ORANWG11-1 O-RAN Threat Model, Risk Management, and Security Architecture
  • IM8-SEC.4 Vulnerability Management

South Korea ISMS-P · 1 control

  • ISMSP-SYS-04 Vulnerability Management
  • UNGPBHR-2 Pillar II: Corporate Responsibility to Respect Human Rights

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 63 it maps to, and the evidence behind each claim, over MCP and REST.