![]() |
|
Processes and Tools for Better Security In an environment of complex and serious data security threats, organizations are increasingly recognizing applications as the most common area of attack. In response, some organizations employ security processes, while others implement application-security measures. While both approaches provide some security, on their own neither is comprehensive enough to provide true security. An approach that integrates both sound process and effective technology provides the best protection of organization and customer data. Two new whitepapers from Ounce Labs, available as free downloads, explore processes and tools for securing applications. Sustainable Processes Integrating security processes into each step of the SDLC makes pre-deployment remediation of software vulnerabilities affordable and achievable. Anthony Gerkis of Accenture and Jack Danahy of Ounce Labs outline these processes in Software Security Governance in the Development Lifecycle. To build security into the SDLC, they urge organizations to:
Once processes have been developed, organizations should create a pilot program and evaluate and improve upon its results. With a tested process, deployment the process across the organization is easier and leads to both greater efficiency and greater security. Effective Tools The Right Tool for the Right Job: An Application Security Tools Report Card, by Ryan Berg, co-founder and chief scientist at Ounce, helps organizations determine what class of applications — web application firewalls, web application scanners, or source code analyzers — best address critical software vulnerabilities. The at-a-glance report card, based on how these tools fare against the Open Web Application Security Project (OWASP) Top 10, shows that source-code analysis tools provide the greatest benefit to development organizations. By addressing vulnerabilities at the code level, before deployment, applications are more secure, data better protected, and maintenance costs reduced. Ounce Drives Better Application Security To learn more about how Ounce helps secure organizations, visit http://www.ouncelabs.com. |