OWASP SAMM recommendation #2: organize basic data protections

technical7 maanden geleden1 minuut leestijd
Picture of author Olivier Sels

Did you ever receive an email from a company that was clearly meant as an internal test? I think you did. And it shows why our #2 recommendation to increase Application Security is to organize basic data protections. If you're doing business in the EU it's not even optional. The GDPR mandates it.

A cloud of key aspects related to the 'organize basic data protections' practice

Organize basic data protections
  • You need to understand the type and sensitivity of data your app processes.
  • You need to implement basic controls to protect important data.

Start with understanding the type and sensitivity of the data your app processes. Where is personally identifiable information processed and stored? Do we process sensitive information like healthcare or financial information? What happens with backups of the data? Then you can think about controls to protect this information.

Take great care to prevent production data from ending op in test or development environments. While it can often speed up development or help debugging efforts to test on production data, you should never allow it without proper sanitization. Not only will you send out embarrassing test emails to real clients, a developer laptop is easier to steal than a cloud server.

Does your organization have basic data protections? Perform a full OWASP SAMM assessment to find out. We developed a tool that will allow you to do it yourself.
Learn more about our #1 recommendation, best-effort patching.
And be sure to follow our LinkedIn page to learn our newest recommendations to improve Application Security.


Vindt ons op

SAMM analyse uitvoeren

Gratis

Veiligheid verbeteren

Gemakkelijk in gebruik

Gerelateerde artikelen

A snippet of text to describe mvsp: Minimum Viable Secure Product.
The NIST CSF functions wheel: identify, protect, detect, respond and recover.
The AppSec program is a continual loop of Assess -> Plan -> Improve
business
January 30, 2023
Onze missie

Secuma helpt softwarebedrijven om veiligere applicaties te ontwikkelen. We moedigen het gebruik aan en helpen met de integratie van innovatieve oplossingen en processen uit de DevSecOps industrie. Hierdoor verbeteren we de veiligheid van uw applicaties en voorkomen we dat problemen uitgroeien tot incidenten.

Bedrijf

infosecuma.be
Sels Software & Security BV
Hoogputstraat 22B
3690 Zutendaal
België
BE0748911858


Bedankt voor je bezoek aan Secuma |
Afbeeldingen met dank aan Unsplash