Frameworks / OWASP MASVS / OWASPMASVS-7 OWASP MASVS
Resilience and Anti-Tampering
OWASP MASVS OWASPMASVS-7: MASVS-RESILIENCE: Resilience Against Reverse Engineering Per OWASP MASVS v2 MASVS-RESILIENCE: resilience against reverse engineering + tampering. Requirements include (a) understand resilience is defence in depth + not replacement for server-side controls + (b) implement anti-debugging + anti-tampering + anti-hooking + root/jailbreak detection appropriate to risk + (c) implement code + string + asset obfuscation where appropriate + (d) implement integrity checks for code + resources + (e) implement device binding + attestation for high-assurance scenarios + (f) maintain telemetry + detection for tampering attempts + (g) avoid hard-coded secrets + use server-side validation for sensitive logic + (h) maintain backup procedures resistant to ransomware + rollback.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 66 controls across 42 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
API1164-17 Wireless and Field Communications API1164-18 Field Device Security API1164-19 Safety Instrumented Systems Interface ASD37-34 Regular backups (Essential) ASD37-35 Business continuity and disaster recovery plans (Very Good) ASD37-36 System recovery capabilities (Very Good) IEC62443-16 Incident response plan for operational disruptions IEC62443-17 Recovery plan for critical systems IEC62443-20 Exercises and drills for OT incidents ISO27019-16 Incident response plan for operational disruptions ISO27019-18 Reporting obligations to authorities ISO27019-20 Exercises and drills for OT incidents 27031-8.1 Exercising and Testing 27031-8.2 Maintaining IRBC 27031-9.3 Management Review ISO22316-08 Recovery time and point objectives ISO22316-12 Recovery strategy for critical activities ISO22317-08 Recovery time and point objectives ISO22317-12 Recovery strategy for critical activities ISO22318-08 Recovery time and point objectives ISO22318-12 Recovery strategy for critical activities IM8-RES.2 Disaster Recovery IM8-RES.4 Resilience Testing ISMSP-PI-06 Personal Information Destruction ISMSP-SYS-06 Business Continuity and Disaster Recovery 4.4.8 Business Continuity and Recovery DIQ-1 Data Integration and Interoperability FFIEC-12 Disaster recovery procedures FEDRAMP-CP-9 System Backup ISO-22320-5.2 Incident management process 27011-8.6 Data protection and backup ISO27043-23 Backup and recovery procedures ISO21434-23 Backup and recovery procedures MTCS-Acquisition-Development-Maintenance-Supplier-Vulnerability-DevSecOps-SBOM-SDLC-SCA-API-Container MTCS Acquisition + Development + Maintenance + Supplier + Vulnerability + DevSecOps + SBOM + SDLC + SCA NABERS-3 NABERS Water Performance Rating NAIC-5 Third Party Service Provider Oversight - Section 4(F)(3) and Section 5 NERCCIP-6 Incident Reporting and Response Planning + Recovery Plans (CIP-008 + CIP-009) NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material NISTSP123-5 Server Operations - Patching, Malware, Logging, Backup NISTSP137-7 Incident Response Integration and Ongoing Authorization NISTSP144-6 Availability, Resilience, BCP/DR, and SLA Management NISTSP145-3 Rapid Elasticity Characteristic and Capacity Management NISTSP146-7 Service Level, Performance, Reliability, Interoperability, and Portability NISTSP61-5 Containment, Eradication, and Recovery NISTSP63R4-4 Authenticator Lifecycle: Binding, Recovery, Replacement, Suspension, Revocation NISTSP82-7 OT Incident Response, Forensics, Recovery, and Continuity NISTSP88-5 Media Inventory, Tracking, Chain of Custody, and Sanitization Records NISTSP92-6 Log Retention: Policy, Tiered Storage, Backup, Secure Disposal, Legal Hold OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery OMANCS-7 Business Continuity, Disaster Recovery, and Resilience OPENBANK-8 Incident Detection, Response, Customer Notification, Post-Incident Review, BCM OSSFSC-8 Project Maintenance, Sustainability, Integration with Supply Chain Security CYB-5 Cyber Incident Response Plan Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 66 it maps to, and the evidence behind each claim, over MCP and REST.