OWASP Cornucopia Mobile App Edition v2.0
We are happy to announce the release of the OWASP Cornucopia Mobile App Edition v2.0 . The latest edition is compatible with MASVS v2.1 , MASTG v2.0 , and MASWE v1.0 , and features 80 threats that cover all the requirements, tests, and weaknesses of the OWASP Mobile Application Security Project. Why would you use OWASP Cornucopia Mobile App Edition? At Admincontrol, the OWASP Cornucopia Mobile App Edition is used to implement mobile application security by design . Before building mobile apps and features, OWASP Cornucopia helps the team identify threats during the threat modeling and design phase. For example, during gameplay, a developer identifies that card AA3 should be considered during app development. Each identified card includes a mapping table showing which CAPEC™s, OWASP MASWEs , MASTG Best Practices , MASTG Knowledge base , MASTG tests , and MASVS requirements apply when developing a specific mobile feature. This simplifies identifying mobile application security requirements during development and makes it possible to decide on security requirements during the development sprint in an agile, lean way. During gamification and threat modeling, the team identifies threats that naturally drive application security requirements. Doing this before sprint planning makes threat modeling and security requirement analysis part of the team's SDLC. In addition, it’s the team that gets to decide «what can go wrong» and «what we are going to do about it». Letting the team decide ensures alignment with the application security requirements and security goals and prevents scope creep and dissatisfied scrum masters. Security awareness and a security sprint scope are created as a result. Doing games and threat modeling before sprint planning builds engagement, alignment, and security awareness without pushback that could push security issues to the backlog and let them be forgotten. Why should I do this when I can use AI agents? There is this quote from David Dunning whe