A CISO's Guide To Application Security - Part 4: Weighing AppSec Technology Options<p><em>This post is the fourth in a 5-part series on Application Security, or “AppSec”. The series will define the components of a sound AppSec program, delineate the growing threats to software, weigh the costs of a data breach, and outline the CISO’s responsibility in managing software security risk. Taken together, they are a primer on AppSec best practices that will help organizations build the business case for further investment in this critical IT security discipline.</em></p><p><strong>By Fergal Glynn, Veracode</strong></p><p><img src="https://threatpost.com/sites/default/files/fergal2_3.jpg" alt="Fergal Glynn" title="Fergal Glynn" style="float: left;" border="0" height="100" width="100" />As we have examined in this series, the information security practice called Application Security (or “AppSec”) seeks to protect all of the software that runs a business. It has three distinct objectives:<br />1) Measurable reduction of risk from existing applications<br />2) Prevention of introduction of new risks<br />3) Ensuring compliance with regulatory mandates<em></em></p><p><a href="http://threatpost.com/en_us/blogs/cisos-guide-application-security-part-4-weighing-appsec-technology-options-050712" target="_blank">read more</a></p>
Source:
A CISO's Guide To Application Security - Part 4: Weighing AppSec Technology Options