Resilience (RS4)
Resilience
4
Timur can replace, redistribute, or introduce unreviewed code into the production app because its signature, certificate, store origin, packaged-code integrity, or reproducible build provenance can't be properly verified
Scenario: Timur can replace, redistribute, or introduce unreviewed code into the production app because its signature, certificate, store origin, packaged-code integrity, or reproducible build provenance can't be properly verified
Example
Threat Modeling
STRIDE
What can go wrong?
What are we going to do about it?
Mappings
STRIDE: -
MASTG Best: 0006
SAFECode™: 14
MASVS: MASVS-RESILIENCE-2
No attacks registered!