Library tutorials & articles
Effective Controls for Attaining Continuous Application Security Throughout the Web Application Development Life Cycle
- Learn How to Improve Web Application Security Throughout the SDLC
- Secure Web Application Development: People, Process, and Technology
- Essential Elements of Secure Software Development Life Cycle Processes
- How Technology Helps Enforce and Maintain the Secure SDLC
- Put Baselines in Place (But Keep it Simple in the Early Days)
Secure Web Application Development: People, Process, and Technology
Building highly secure applications begins early in the software development life cycle with your developers. That's why instilling application security awareness through Web application development training is one of the first things you want to do. You not only want your developers armed with the latest knowledge on how to code securely--and how attackers exploit weaknesses--but you want them to know how important (and much more efficient) it is to consider security from the start. This awareness building shouldn't end with your Web application development team. It needs to include everyone who plays a part in the software development life cycle: your quality and assurance testing teams, who need to know how to properly identify potential security defects, and your IT management team, who need to understand how to invest organizational resources most effectively to develop security applications, as well as how to successfully evaluate such essential technologies as Web application security scanners, Web application firewalls, and quality assurance toolsets.
By building awareness throughout the Web application development life cycle, you're building one of the most central controls necessary to ensure the security of your Web applications. And while training is essential, you can't depend on it to make certain that your systems are built securely. That's why training needs to be reinforced with additional controls and technology. You need to begin to put into place the elements of a secure Software Development Life Cycle, or SDLC.
Related articles
Related discussion
-
protect your images on computer
by meiling277869 (2 replies)
-
Not able to launch the web application
by NaseemAhmed (0 replies)
-
Impersonation failing for a user.
by mittalpa (0 replies)
-
Trial Period Expire In VB6
by pavneet9 (0 replies)
-
Software Security
by pavneet9 (0 replies)
Related podcasts
-
Beyond Ajax - Java Rich Internet Applications
AJAX is great for many applications, but not for all. When applications get large, need to scale, or require superior security, Java-based Rich Internet Applications (RIA) are preferable. There is a simple reason for this: Java offers the most advanced, most standardized, and most reliable cr...
Events coming up
-
Dec
2
Web Standards Group (Sydney)
North Sydney, Australia
TBA
This thread is for discussions of Effective Controls for Attaining Continuous Application Security Throughout the Web Application Development Life Cycle.