OWASP SAMM recommendation #2: organize basic data protections

technical7 months ago1 minute read
Picture of author Olivier Sels

Did you ever receive an email from a company that was clearly meant as an internal test? I think you did. And it shows why our #2 recommendation to increase Application Security is to organize basic data protections. If you're doing business in the EU it's not even optional. The GDPR mandates it.

A cloud of key aspects related to the 'organize basic data protections' practice

Organize basic data protections
  • You need to understand the type and sensitivity of data your app processes.
  • You need to implement basic controls to protect important data.

Start with understanding the type and sensitivity of the data your app processes. Where is personally identifiable information processed and stored? Do we process sensitive information like healthcare or financial information? What happens with backups of the data? Then you can think about controls to protect this information.

Take great care to prevent production data from ending op in test or development environments. While it can often speed up development or help debugging efforts to test on production data, you should never allow it without proper sanitization. Not only will you send out embarrassing test emails to real clients, a developer laptop is easier to steal than a cloud server.

Does your organization have basic data protections? Perform a full OWASP SAMM assessment to find out. We developed a tool that will allow you to do it yourself.
Learn more about our #1 recommendation, best-effort patching.
And be sure to follow our LinkedIn page to learn our newest recommendations to improve Application Security.


Follow us on

Perform a SAMM assessment

Free

Improve security

Easy to use

Related articles

A snippet of text to describe mvsp: Minimum Viable Secure Product.
The NIST CSF functions wheel: identify, protect, detect, respond and recover.
The AppSec program is a continual loop of Assess -> Plan -> Improve
business
January 30, 2023
Our mission

Secuma helps technology companies develop more secure applications. We encourage and guide the integration of security best practices in the entire Software Development Lifecycle, improving the security of your applications and stopping issues from becoming incidents.

Company

infosecuma.be
Sels Software & Security BV
Hoogputstraat 22B
3690 Zutendaal
Belgium
BE0748911858


Thank you for visting Secuma |
Pictures courtesy of Unsplash