Mobile Scoping

  1. What are the business security concerns regarding the mobile application in scope?

  2. What is the main functionality of this application?

  3. How many pages and input fields does the application contain?

  4. Does the application communicate with any API's, Web Services etc.? If yes how many?

  5. Is it an iOS or an Android application or both?

  6. Does the application use certificate pinning?

  7. Does the application implement jailbreak detection / root detection?

  8. Will source code be available?

  9. Does the application store or transmit sensitive information?

  10. What is the current version of the mobile application in scope?

  11. The IPA or the APK file needs to be provided ahead of the test

  12. How many level of users exist in the application? (standard, Admin etc.)

  13. Does the application contain a registration function?

  14. Are there any constraints?

  15. Who will be the technical contact?

Last updated