2023-02 – Security flaw introduced by developer or engineer
| Veld | Waarde |
|---|---|
| Status | Actief |
| Behandeling | Accepteren |
| Kans | Laag |
| Impact | Hoog |
| Blootstelling | Midden |
| Restblootstelling | Laag |
| Eigenaar | Management |
| Verantwoordelijke | Security Officer |
Asset
Confidential information stored in application
Dreiging
A developer introduces a security flaw due to insufficient knowledge of secure development techniques
Risicocategorie
Vertrouwelijkheid, Integriteit, Beschikbaarheid
Risicoscore
| Kans | Impact | Blootstelling | Restblootstelling |
|---|---|---|---|
| Laag | Hoog | Midden | Laag |
Behandelingsmaatregelen
- Check on security knowledge before hiring (A.6.1 Screening)
- Enforce 4 eyes principle (A.8.27 Secure system architecture and engineering principles)
- Enforce code reviews (A.8.25 Secure development life cycle)
- Create a Secure development policy (A.8.28 Secure coding)
- Implement A.8.29 Security testing in development and acceptance
- Implement A.5.36 Compliance with policies and standards for information security