10 Commandments Of Application Security


Application security leaders sound off on business process and technology imperatives for fostering better application security.

While application security cascades into just about every facet of IT security today, many enterprises have a difficult time implementing sustainable application security programs that offer measurable benefits to the business. A general disconnect between security goals and the profit motives of development teams can cause insurmountable conflict between infosec teams and developers, with line-of-business leaders all too ready to side with money-making dev teams nine times out of 10.

Which is why so much of application security comes down to not just bolting on security technology and checking off OWASP Top 10 items. Many of the secrets to success involve smart politics, education and delegation among developer ranks, and championing improved business processes without causing a disruption to the everyday workflow.

1. Thou Shall Execute App Security At The Speed Of Business

There's nothing worse for application security than the hubris shown when an expert tells developers or line-of-business leaders to completely re-engineer their processes for the sake of security, said Bill Pennington, chief strategy officer of WhiteHat Security.

...
Read full story on Dark Reading

Related Reading


More Insights




InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS

Resource Links