Talk With an Expert

An Approach to Application Security

An Approach to Application Security (PDF, 1.67MB)Published: 30 Jan, 2002
Created by:
Ian Rathie

Applications themselves are often crafted with little oversight of security professionals and without standards of development which creates an opportunity for disaster. This document discusses an approach to assessing application security that will work within most organizations. It first discusses some classes of threats that should be considered when designing security for applications. It then shows how to develop a simple Security Development Life Cycle to complement an organization's Systems Development Life Cycle. One approach for assessing risk in applications or systems is then discussed, with an example. Finally, some conclusions are reached about how to approach security in applications.