Security-X

Forum Security-X => News => Discussion démarrée par: igor51 le mai 01, 2012, 17:00:17

Titre: [ThreatPost]A CISO's Guide To Application Security - Part 3: Toward an AppSec Center of Excellence
Posté par: igor51 le mai 01, 2012, 17:00:17
A CISO's Guide To Application Security - Part 3: Toward an AppSec Center of Excellence

<p><span style="font-size: small;"><em>This post is the third in a 4-part series on Application Security, or “AppSec”. The series will define the components of a sound AppSec program, delineate the growing threats to software, weigh the costs of a data breach, and outline the CISO’s responsibility in managing software security risk. Taken together, they are a primer on AppSec best practices that will help organizations build the business case for further investment in this critical IT security discipline.</em></span></p><p><strong>By Fergal Glynn</strong><em></em></p><p><img src="https://threatpost.com/sites/default/files/fergal2_2.jpg" alt="Fergal Glynn" title="Fergal Glynn" style="float: left;" border="0" height="100" width="100" />This series began with a general definition of Application Security (“AppSec”) as a fundamental infosec practice that addresses the reduction of both immediate and systemic software risk. When undertaken correctly, AppSec takes a systematic, programmatic approach to hardening business-critical software, from the inside. That’s not to say that organizations must over-invest in an advanced program from the start to be effective – in fact, quite the opposite.<em></em></p><p><a href="http://threatpost.com/en_us/blogs/cisos-guide-application-security-part-3-toward-appsec-center-excellence-043012" target="_blank">read more</a></p>
Source: A CISO's Guide To Application Security - Part 3: Toward an AppSec Center of Excellence (http://threatpost.com/en_us/blogs/cisos-guide-application-security-part-3-toward-appsec-center-excellence-043012)