OWASP MASVS
Resilience and Anti-Tampering

OWASP MASVS OWASPMASVS-7: MASVS-RESILIENCE: Resilience Against Reverse Engineering

Per OWASP MASVS v2 MASVS-RESILIENCE: resilience against reverse engineering + tampering. Requirements include (a) understand resilience is defence in depth + not replacement for server-side controls + (b) implement anti-debugging + anti-tampering + anti-hooking + root/jailbreak detection appropriate to risk + (c) implement code + string + asset obfuscation where appropriate + (d) implement integrity checks for code + resources + (e) implement device binding + attestation for high-assurance scenarios + (f) maintain telemetry + detection for tampering attempts + (g) avoid hard-coded secrets + use server-side validation for sensitive logic + (h) maintain backup procedures resistant to ransomware + rollback.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 66 controls across 42 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

API 1164 · 3 controls

  • API1164-17 Wireless and Field Communications
  • API1164-18 Field Device Security
  • API1164-19 Safety Instrumented Systems Interface
  • ASD37-34 Regular backups (Essential)
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • ASD37-36 System recovery capabilities (Very Good)

IEC 62443 · 3 controls

  • IEC62443-16 Incident response plan for operational disruptions
  • IEC62443-17 Recovery plan for critical systems
  • IEC62443-20 Exercises and drills for OT incidents

ISO/IEC 27019:2024 · 3 controls

  • ISO27019-16 Incident response plan for operational disruptions
  • ISO27019-18 Reporting obligations to authorities
  • ISO27019-20 Exercises and drills for OT incidents

ISO/IEC 27031:2011 · 3 controls

  • 27031-8.1 Exercising and Testing
  • 27031-8.2 Maintaining IRBC
  • 27031-9.3 Management Review

ISO 22316 · 2 controls

  • ISO22316-08 Recovery time and point objectives
  • ISO22316-12 Recovery strategy for critical activities

ISO/TS 22317:2021 · 2 controls

  • ISO22317-08 Recovery time and point objectives
  • ISO22317-12 Recovery strategy for critical activities

ISO/TS 22318:2021 · 2 controls

  • ISO22318-08 Recovery time and point objectives
  • ISO22318-12 Recovery strategy for critical activities
  • IM8-RES.2 Disaster Recovery
  • IM8-RES.4 Resilience Testing

South Korea ISMS-P · 2 controls

  • ISMSP-PI-06 Personal Information Destruction
  • ISMSP-SYS-06 Business Continuity and Disaster Recovery
  • 4.4.8 Business Continuity and Recovery
  • DIQ-1 Data Integration and Interoperability
  • FFIEC-12 Disaster recovery procedures

FedRAMP Rev 5 · 1 control

  • FEDRAMP-CP-9 System Backup

ISO 22320:2018 · 1 control

  • ISO-22320-5.2 Incident management process

ISO/IEC 27011:2024 · 1 control

  • 27011-8.6 Data protection and backup

ISO/IEC 27043:2015 · 1 control

  • ISO27043-23 Backup and recovery procedures

ISO/SAE 21434 · 1 control

  • ISO21434-23 Backup and recovery procedures

MITRE ATT&CK · 1 control

MTCS (Singapore) · 1 control

  • MTCS-Acquisition-Development-Maintenance-Supplier-Vulnerability-DevSecOps-SBOM-SDLC-SCA-API-Container MTCS Acquisition + Development + Maintenance + Supplier + Vulnerability + DevSecOps + SBOM + SDLC + SCA
  • NABERS-3 NABERS Water Performance Rating
  • NAIC-5 Third Party Service Provider Oversight - Section 4(F)(3) and Section 5

NERC CIP · 1 control

  • NERCCIP-6 Incident Reporting and Response Planning + Recovery Plans (CIP-008 + CIP-009)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)
  • NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material

NIST SP 800-123 · 1 control

  • NISTSP123-5 Server Operations - Patching, Malware, Logging, Backup

NIST SP 800-137 · 1 control

  • NISTSP137-7 Incident Response Integration and Ongoing Authorization

NIST SP 800-144 · 1 control

  • NISTSP144-6 Availability, Resilience, BCP/DR, and SLA Management

NIST SP 800-145 · 1 control

  • NISTSP145-3 Rapid Elasticity Characteristic and Capacity Management

NIST SP 800-146 · 1 control

  • NISTSP146-7 Service Level, Performance, Reliability, Interoperability, and Portability
  • NISTSP61-5 Containment, Eradication, and Recovery

NIST SP 800-63-4 · 1 control

  • NISTSP63R4-4 Authenticator Lifecycle: Binding, Recovery, Replacement, Suspension, Revocation
  • NISTSP82-7 OT Incident Response, Forensics, Recovery, and Continuity

NIST SP 800-88 · 1 control

  • NISTSP88-5 Media Inventory, Tracking, Chain of Custody, and Sanitization Records

NIST SP 800-92 · 1 control

  • NISTSP92-6 Log Retention: Policy, Tiered Storage, Backup, Secure Disposal, Legal Hold

OSFI B-13 · 1 control

  • OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery
  • OMANCS-7 Business Continuity, Disaster Recovery, and Resilience
  • OPENBANK-8 Incident Detection, Response, Customer Notification, Post-Incident Review, BCM

OpenSSF Scorecard · 1 control

  • OSSFSC-8 Project Maintenance, Sustainability, Integration with Supply Chain Security

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 66 it maps to, and the evidence behind each claim, over MCP and REST.