Editor's note
Crafting an effective corporate application security strategy is getting tricky.
That is because, among other things, applications don’t just sit on employee desktops within company walls anymore. Apps now are also riding around on all sorts of mobile, employee-owned devices and in the cloud. What that means is that sensitive corporate data, too, has escaped the bounds of the enterprise.
To set a strategy and create an application security policy means taking all these facts, plus the increased sophistication of hackers, into consideration. This guide aims to outline the various aspects of the issues that must now guide your application security strategy making.
1Best practices for any appsec program
After the basics are in place, next comes the tough stuff that’s required to make sure the applications in use in the enterprise are as secure as they can be. These stories look at specific appsec best practices, in categories like messaging apps, but also consider some of the myths that have developed around the issue of app security best practices.
-
Article
Make any application security strategy stronger with a hacker mindset
It can be beneficial to think like a black hat. Expert Kevin Beaver explains why enterprise security teams should apply a hacker mindset to their work and how it can help. Read Now
-
Article
Learn these essential app login fixes to keep things secure
Flawed web application login security can leave an enterprise vulnerable to attacks. Expert Kevin Beaver reviews the most common mistakes and how to fix them. Read Now
-
Article
Gary McGraw on the seven best practices myths
According to expert Gary McGraw, you're not helping yourself by believing the things -- all seven of them -- you've heard about secure software development. Read Now
2Mobile and more: Topics in application security
This segment of our guide is packed with actionable advice on several topics, including the vital security concerns that mobile applications raise. Learn more now about how to approach mobile application security and related policy. Be sure not to miss the collection of expert podcasts that rounds out this segment.