For Security & Risk Professionals (Length: 11 pages)

August 14, 2007

Managing Application Security From Beginning To End

This is the first document in the "Application Security" series.

by Chenxi Wang, Ph.D.

with Jonathan Penn, Alissa Dill


Executive Summary (This is a document excerpt)

Organizations that develop applications in-house have a decision to make: you can wait until someone exploits vulnerability in your system and fix it, or you can proactively build security early on in your development process — mitigating vulnerabilities before attackers find them. A proactive application security program should extend to every relevant phase of the application life cycle, from conception to operation: program success hinges on commitment and support from executive management. Security personnel need to work with application owners and business stakeholders to prioritize resources and to ensure proper measures are implemented throughout the life cycle.

Buy Risk-Free

Download and print PDF immediately. Price: US $499

Our Money-Back Guarantee: If you are not completely satisfied, return it for a full refund within three weeks of your online purchase.

Already a Forrester Client?
Log in to read this document.

Add to cart

TABLE OF CONTENTS

NOTES & RESOURCES

itemAddressing Security Throughout The Application Life Cycle

itemDesign: Reviews And Audits

itemImplementation: Static Analysis

itemQuality Assurance: Black Box And Penetration Testing

itemOperation: A Process Of Continuous Monitoring And Assessment, Analysis, And Response

itemBarriers To Adoption For Secure Application Life Cycle

recommendations

itemManaging Application Security Requires A Top-Down Commitment

In developing this report, Forrester drew from a wealth of analyst experience, insight, and research through advisory and inquiry discussions with end users, vendors, and regulators across industry sectors.

Related Research Documents

itemThe Forrester Wave™: Web Application Firewalls, Q2 2006

June 23, 2006

itemProtecting Private Data with Data Masking

March 21, 2006

itemTrends 2006: Application Security Testing

January 24, 2006

Find Documents In Related Categories

This document falls under the following categories. Click on a link below to find similar documents.

Analyst: Chenxi Wang, Ph.D.
Technology: Application Security, Security & Risk, Security Program Governance
Geography: Asia Pacific, Europe, North America

Archived Teleconference:
A Close Look At Cloud Computing Security Issues
Original air date: Monday, May 04, 2009
corner border corner
Ratings and Comments
Rating: 9 out of 10
based on 2 ratings across all roles.
corner border corner