Methodology and Standards

Our penetration testing is based on recognized standards and methodologies, including:

  • OWASP Top 10: List of the most critical web application threats (e.g., A01:2021 – Broken Access Control, A03:2021 – Injection).
  • OWASP Mobile Top 10: Key mobile application threats (e.g., M1: Improper Credential Usage, M2: Inadequate Supply Chain Security).
  • PTES (Penetration Testing Execution Standard): Defines penetration testing stages.
  • OSSTMM (Open Source Security Testing Methodology Manual): Methodology for infrastructure security testing.
  • NIST SP 800-115: Guidelines for information security testing.
  • OWASP Testing Guide v4.2: Latest guide for application security testing.
  • OWASP ASVS (Application Security Verification Standard): Standard for verifying application security based on its purpose.