EDUMATIC: Jurnal Pendidikan Informatika
Vol 10 No 1 (2026): Edumatic: Jurnal Pendidikan Informatika (IN PRESS)

Security Maturity Assessment of Indonesian Android Mobile Banking Apps using MobSF and OWASP

Faozi, Rizal Aglal (Unknown)
Majid, Nuur Wachid Abdul (Unknown)
Widodo, Suprih (Unknown)



Article Info

Publish Date
12 Mar 2026

Abstract

The rapid expansion of mobile banking in emerging economies has increased exposure to client-side security risks, while MASVS-based security maturity benchmarking of conventional banking applications remains underrepresented in the literature. This study conducts a standard-based comparative security maturity assessment of two major Indonesian Android banking applications, BRImo and myBCA. APK files obtained from the Google Play Store were analysed using Static Application Security Testing with the Mobile Security Framework (MobSF) and evaluated against OWASP MASVS Level 2 and MASVS-R. MobSF scores were interpreted as relative indicators of security maturity based on severity-weighted findings across multiple domains. The results reveal a clear divergence in maturity levels. Although both applications demonstrate strong network-layer protection, BRImo exhibits structural weaknesses in storage, cryptography, platform interaction, and resilience domains, indicating fragmented defence-in-depth implementation. In contrast, myBCA shows more consistent cross-domain control integration. This study contributes an MASVS-based security maturity benchmarking approach and provides conceptual evidence that formal regulatory compliance may coexist with inconsistent client-side technical implementation. The findings offer analytically transferable insights for developers, security auditors, and regulators in rapidly digitalising financial ecosystems.

Copyrights © 2026






Journal Info

Abbrev

edumatic

Publisher

Subject

Computer Science & IT Education

Description

EDUMATIC: Jurnal Pendidikan Informatika (e-ISSN: 2549-7472) adalah jurnal ilmiah bidang pendidikan informatika yang diterbitkan oleh Universitas Hamzanwadi dua kali setahun yaitu pada bulan Juni dan Desember. Adapun fokus dan skup jurnal ini adalah (1) Komputer dan Informatika dalam Pendidikan; (2) ...