
Is your application validated?
Present that your applications software has been validated for architecture complexity, security vulnerabilities, compliance to standards, and implementation quality.
|
If Java based Web Applications are within your control, then you need a strategy to address the risks inherent in:
Internally custom developed web applications
• Does your SDLC process have metrics to track application risk?
Outsourced custom development of web applications
• Are architecture, security, compliance, and quality metrics in place
to measure your software vendors deliverables?
Commercially purchased web applications
• Could purchased software open your organizations to security
threats or intellectual property litigations risks?
Web applications indirectly obtained through mergers and acquisitions
• Do you have a baseline bill of material for all the components
received and can you verify there are no back doors to the system
left
unchecked?
|