23 June 2009

Web Site Security Maturity Model

The Web Site Security Maturity Model gives an at-a-glance indicator, or litmus test, of an organisation's web site security posture!

Illustration like a litmus paper test colour chart, labelled 'Web Site Security Testing Laboratory', the instructions 'Compare your test paper with these colours and pick the correct level' and five maturity level colour/color swabs, red=1, orange=2, gold=3, green=4 and blue=5

Organisations tend to fit into one of five categories, which I'll light-heartedly call the Web Site Security Maturity Model. This is comprised of five maturity levels, and it's very easy to determine your own organisation's level. Start at the lowest (level 1) and work up the maturity model—stop as soon as you agree with the statement:

1: Use FTP to update the web site

2: Worried about web site security

3: Have undertaken a web site security audit or review

4: Security built into web site development and operation processes

5: Don't have a web site

So on this quick guide, the safest option is not to have a web site. Many small and medium-sized organisations are operating at maturity level 1.

But seriously, if you want to review and improve the security of your web site and other software development processes properly, the Software Assurance Maturity Model is the best starting point.

Posted on: 23 June 2009 at 08:36 hrs

Comments Comments (0) | Permalink | Send Send

Comments

Comments are filtered automatically and should appear shortly after they been checked.

Post a comment
Confirm acceptance and understanding of the terms of use
New posts to this thread will be sent to your email address
Web Site Security Maturity Model
http://www.clerkendweller.com/2009/6/23/Web-Site-Security-Maturity-Model
ISO/IEC 18004:2006 QR code for http://clerkendweller.com

Page http://www.clerkendweller.com/2009/6/23/Web-Site-Security-Maturity-Model
Requested by 38.107.191.115 on Tuesday, 9 February 2010 at 03:29 hrs (London date/time)

Please read our terms of use and obtain professional advice before undertaking any actions based on the opinions, suggestions and generic guidance presented here. Your organisation's situation will be unique and all practices and controls need to be assessed with consideration of your own business context.

Terms of use http://www.clerkendweller.com/page/terms
Privacy statement http://www.clerkendweller.com/page/privacy
© 2009-2010 clerkendweller.com