Web Site Security Maturity Model
The Web Site Security Maturity Model gives an at-a-glance indicator, or litmus test, of an organisation's web site security posture!
Organisations tend to fit into one of five categories, which I'll light-heartedly call the Web Site Security Maturity Model. This is comprised of five maturity levels, and it's very easy to determine your own organisation's level. Start at the lowest (level 1) and work up the maturity model—stop as soon as you agree with the statement:
1: Use FTP to update the web site
2: Worried about web site security
3: Have undertaken a web site security audit or review
4: Security built into web site development and operation processes
5: Don't have a web site
So on this quick guide, the safest option is not to have a web site. Many small and medium-sized organisations are operating at maturity level 1.
But seriously, if you want to review and improve the security of your web site and other software development processes properly, the Software Assurance Maturity Model is the best starting point.
Posted on: 23 June 2009 at 08:36 hrs

Comments are filtered automatically and should appear shortly after they been checked.