OWASP SAMM recommendation #2: organize basic data protections

technical1 jaar geleden1 minuut leestijd
Picture of author Olivier Sels

Did you ever receive an email from a company that was clearly meant as an internal test? I think you did. And it shows why our #2 recommendation to increase Application Security is to organize basic data protections. If you're doing business in the EU it's not even optional. The GDPR mandates it.

A cloud of key aspects related to the 'organize basic data protections' practice

Organize basic data protections
  • You need to understand the type and sensitivity of data your app processes.
  • You need to implement basic controls to protect important data.

Start with understanding the type and sensitivity of the data your app processes. Where is personally identifiable information processed and stored? Do we process sensitive information like healthcare or financial information? What happens with backups of the data? Then you can think about controls to protect this information.

Take great care to prevent production data from ending op in test or development environments. While it can often speed up development or help debugging efforts to test on production data, you should never allow it without proper sanitization. Not only will you send out embarrassing test emails to real clients, a developer laptop is easier to steal than a cloud server.

Does your organization have basic data protections? Perform a full OWASP SAMM assessment to find out. We developed a tool that will allow you to do it yourself.
Learn more about our #1 recommendation, best-effort patching.
And be sure to follow our LinkedIn page to learn our newest recommendations to improve Application Security.


Vindt ons op

SAMM analyse uitvoeren

Gratis

Veiligheid verbeteren

Gemakkelijk in gebruik

Gerelateerde artikelen

A snippet of text to describe mvsp: Minimum Viable Secure Product.
business
December 15, 2022

After the ransomware attacks on Antwerp and Diest, many will think: "Can this happen to us?" Here are some major red flags. If you encounter…

business
November 28, 2022

Ask any developer, manager, tester or even security professional, and they will almost certainly agree with this statement. But is it…

Onze missie

Secuma helpt softwarebedrijven om veiligere applicaties te ontwikkelen. We moedigen het gebruik aan en helpen met de integratie van innovatieve oplossingen en processen uit de DevSecOps industrie. Hierdoor verbeteren we de veiligheid van uw applicaties en voorkomen we dat problemen uitgroeien tot incidenten.

Bedrijf

infosecuma.be
Sels Software & Security BV
Hoogputstraat 22B
3690 Zutendaal
België
BE0748911858

Geregistreerd dienstverlener voor de KMO portefeuille

DV.A249876


Bedankt voor je bezoek aan Secuma |
Afbeeldingen met dank aan Unsplash