Templates
Security
Mobile App Security Testing Checklist
🔒

Mobile App Security Testing Checklist

1
Define the Scope of the Security Testing
2
Identify the Type of Mobile App (Native, Web or Hybrid)
3
Check the App for Possible Input Fields Vulnerabilities
4
Validate Server-side Security Controls and Encryption
5
Review User Authentication Process
6
Approval: User Authentication Process
7
Inspect Data Storage and Privacy Policies
8
Run Binary and File System Analysis
9
Use Automated Scanning Tools for Quick Security Analysis
10
Perform a Manual Penetration Test
11
Verify Mobile App Behavior in Different Network Environments
12
Check the App against OWASP Mobile Top 10 Risks
13
Use a Source Code Review Tool to Inspect the App Code
14
Approval: Source Code Review
15
Check Application Debug Code and Sensitive Information Leakage
16
Validate Certificate Pinning
17
Create a Report including all Identified Vulnerabilities and Suggested Remediations
18
Approval: Testing Report Review
19
Share Final Report with Developers and Stakeholders
20
Plan for the Necessary Remediation Actions based on the Report