Ga naar inhoud

2023-02 – Security flaw introduced by developer or engineer

Veld Waarde
Status Actief
Behandeling Accepteren
Kans Laag
Impact Hoog
Blootstelling Midden
Restblootstelling Laag
Eigenaar Management
Verantwoordelijke Security Officer

Asset

Confidential information stored in application

Dreiging

A developer introduces a security flaw due to insufficient knowledge of secure development techniques

Risicocategorie

Vertrouwelijkheid, Integriteit, Beschikbaarheid

Risicoscore

Kans Impact Blootstelling Restblootstelling
Laag Hoog Midden Laag

Behandelingsmaatregelen

  • Check on security knowledge before hiring (A.6.1 Screening)
  • Enforce 4 eyes principle (A.8.27 Secure system architecture and engineering principles)
  • Enforce code reviews (A.8.25 Secure development life cycle)
  • Create a Secure development policy (A.8.28 Secure coding)
  • Implement A.8.29 Security testing in development and acceptance
  • Implement A.5.36 Compliance with policies and standards for information security

Gerelateerde documenten