Course Outline
Introduction
Overview of the OWASP Mobile Security Testing Guide for government
- Key areas in mobile application security
- The OWASP Mobile AppSec Verification Standard (MASVS)
- Navigating the guide for government use
- Mobile application taxonomy
Understanding Mobile Application Security Testing Basics
- Mobile application security checklist for government
- Fundamental testing principles for government applications
- Setting clear testing objectives for government projects
- Integrating security testing throughout the development lifecycle for government
Running General Testing Techniques for Mobile Applications
- Authentication architectures for government apps
- Testing network and cryptography for government applications
- Evaluating code quality for government mobile apps
- Assessing tampering and reverse engineering risks for government
- User interaction security in government mobile applications
Exploring Android and iOS Platforms for Government Use
- Overview of the Android platform for government
- Data storage considerations on Android for government apps
- Overview of the iOS platform for government
- Data storage practices on iOS for government applications
Performing Security Testing for Android in Government
- Basic security testing for Android applications in government
- Testing data storage mechanisms in government Android apps
- Evaluating local authentication methods for government Android apps
- Assessing Android APIs (cryptographic, network, and platform) for government use
- Code quality and build settings for government Android applications
- Identifying tampering and reverse engineering vulnerabilities in government Android apps
- Implementing anti-reversing defenses for government Android applications
Performing Security Testing for iOS in Government
- Basic security testing for iOS applications in government
- Testing data storage mechanisms in government iOS apps
- Evaluating iOS APIs (cryptographic, network, and platform) for government use
- Code quality and build settings for government iOS applications
- Identifying tampering and reverse engineering vulnerabilities in government iOS apps
- Implementing anti-reversing defenses for government iOS applications
Contributing to the MSTG Community for Government
- Reading the MSTG for government insights
- Contribution guide for government stakeholders
- Submitting feature requests and feedback from a government perspective
Summary and Conclusion for Government Use
Requirements
- A comprehensive understanding of the mobile app development lifecycle for government
- Experience in mobile application development, security, and testing
Audience
- Developers
- Engineers
- Architects
Testimonials (5)
Multiple examples for each module and great knowledge of the trainer.
Sebastian - BRD
Course - Secure Developer Java (Inc OWASP)
Module3 Applications Attacks and Exploits, XSS, SQL injection Module4 Servers Attacks and Exploits, DOS, BOF
Tshifhiwa - Vodacom
Course - How to Write Secure Code
Real-life examples.
Kristoffer Opdahl - Buypass AS
Course - Web Security with the OWASP Testing Framework
The trainer's subject knowledge was excellent, and the way the sessions were set out so that the audience could follow along with the demonstrations really helped to cement that knowledge, compared to just sitting and listening.
Jack Allan - RSM UK Management Ltd.
Course - Secure Developer .NET (Inc OWASP)
Piotr was very knowledgeable and related security issues to real world examples very well. His preparation was brilliant.