• About Us
    • Dominik Sauer
    • Patrick Sauer
  • Legal Information & Data Privacy
Sauer on Information Security | InfoSec-Blog for IT-Professionals | Patrick Sauer & Dominik Sauer

InfoSec Blog by Dominik & Patrick Sauer

OWASP Top 10

MPA Content Security Program Requirements for Penetration Testing

9. June 2022 by Patrick Sauer Leave a Comment

The Content Security Program of the Motion Picture Association (MPA) specifies security requirements in three areas in its Content Security Best Practices Common Guidelines (Version 4.10 of February 8, 2022): Management System Physical Security Digital Security In the requirements for the management system, vulnerability scans and external penetration tests are to be carried out in … [Read more…]

Posted in: Pentesting Tagged: CSRF, OWASP Top 10, SQL Injection, XSS

i-Kfz: Requirements for penetration tests from the german Federal Motor Transport Authority (KBA)

7. June 2022 by Patrick Sauer Leave a Comment

The “minimum security requirements for decentralized portals and registration authorities” for “internet-based vehicle registration (i-Kfz)” from the german Federal Motor Transport Authority (KBA) are extremely extensive. In addition to the architecture of the i-Kfz system, its interfaces and the security requirements derived from them, they also include requirements for conducting a penetration test. To check … [Read more…]

Posted in: Pentesting Tagged: iKfz, OWASP Top 10

Comparison of PCI DSS 3.2.1 and 4.0 penetration testing requirements

2. June 2022 by Patrick Sauer Leave a Comment

The current version 3.2.1 and the newer version 4.0 of the security standard PCI DSS require penetration tests to be performed. The PCI standard establishes detailed requirements a penetration test needs to comply with. In PCI DSS 3.2.1, the requirement is regulated in Requirement 11.3 and in PCI DSS 4.0 in Requirement 11.4. These requirements … [Read more…]

Posted in: PCI DSS, PCI DSS Tagged: OWASP Top 10, PCI DSS 3.2.1, PCI DSS 4.0

Requirements for penetration tests of DiGa APPS – Penetration test for digital health applications in the german fast-track procedure

18. April 2022 by Patrick Sauer Leave a Comment

In order to be included in the register of reimbursable digital health applications (DiGa), the fast-track procedure at the BfArM must be completed. With the Digital Supply and Care Modernization Act (DVPMG), the corresponding guideline included the requirement that company applicants must have a penetration test carried out for their DiGa application. Penetration tests: With … [Read more…]

Posted in: Pentesting Tagged: OWASP Top 10

Sprachen

  • English
    • Deutsch

Search

Categories

  • binsec
  • binsec.academy
  • binsec.tools
  • binsec.wiki
  • Digital Forensics
  • ISO27001
  • IT Security
  • legislative regulation
  • PCI DSS
  • Pentest Collective
  • Pentesting
  • Politics
  • Questions and Answers (Q&A)
  • university lecture
    • THM

Copyright © 2026 Sauer on Information Security | InfoSec-Blog for IT-Professionals | Patrick Sauer & Dominik Sauer.

Omega WordPress Theme by ThemeHall

  • Deutsch (German)
  • English