Web Application Security for Auditors
COBIT defines a range of domains, processes and control objectives relevant to to secure software development lifecycle. ISACA has now published a white paper on web application security risks.
Web Application Security - Business Risk Decisions provides an introduction to the security issues relating to web applications and discusses the risks and common security weaknesses. It references other projects and resources that are relevant to web application security.
The paper recommends a systems-based approach which will be familiar to adopters of COBIT and similar frameworks. It emphasises the governance aspects, especially the need for enterprise support. The paper recommends a programme to drive security throughout the SDLC to include:
- Business/executive support
- Training
- Supply chain
- Policies and standards
- Technical controls
- Ongoing programme of scanning/code review
- Legacy code
- Project management
- Effective incident response capabilities
The approach is welcome. IT Auditors can be your friends! It will be interesting to see if this develops into a more formal initiative by ISACA.
Posted on: 28 October 2011 at 09:09 hrs

Comments are filtered automatically and should appear shortly after they been checked.