Chapter 4. Solving Problems for Application Security
Caroline Wong
Fundamentally, application security is about designing, building, and maintaining secure software. Good software helps organizations, and bad software hurts organizations.
There are four main categories of application security activities: governance, finding security problems, fixing security problems, and preventing security problems. This essay will provide a high-level description of each of these four categories, with an emphasis on fixing security problems:
- Governance
-
There are several high-level factors to consider when developing an application security program. These include compliance and regulatory requirements, contractual relationships with other organizations, and a solid understanding of what you’re supposed to be securing in the first place. It’s also important to define metrics up front so that the success of the program can be measured and demonstrated over time.
- Finding security problems
-
There are many ways to find security problems at different points in any software development life cycle, whether an organization follows a waterfall, Agile, or DevOps methodology. Security testing types include threat modeling, code review, and penetration testing. A combination of manual and automated security testing is likely to result in the most efficient and effective identification of true positive ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access