|
Compliance Through Application Security |
|
|
Softwares play a key role in every strata of our life. They are being used in financial institutions, government agencies, health sectors, power control systems to store and process security critical information. As business become more dependent on such software systems, the need for developing secure software is becoming more evident.
Application security is a significant element of policies that govern an organization. Application development processes fail to model some nonfunctional requirements such as security and safety. Incorporating security at the latter stages of a software lifecycle is more difficult and time consuming. Weak application security represents significant control deficiencies. These deficiencies potentially compromises sensitive business critical data and reporting, regulatory compliance and industry best practices .
Security vulnerabilities can exist in virtually any application accessible via the Internet or other networks. The Internet provides a popular avenue for delivering information and services, which makes the web applications attractive targets for attack. These applications may contain security vulnerabilities that unless identified by some reliable means, can remain undetected until an exploit is discovered and the damage has been done.
Many organizations neglect to monitor system activity at the Web application level, and therefore, intrusion attempts can easily go unnoticed. A carefully crafted exploit may leave little evidence and provide a significant lag between the exploit and its detection.
|