Vulnerability testing in the development cycle

Alice van Rensburg, S.H. von Solms · 2017

Web applications have been the target of endless attacks. The root cause of such breaches and exposures are vulnerabilities found within web applications. Despite applying various mitigating measures, including security best-practises, a very high percentage of web applications contain vulnerabilities year after year. In order to improve the security of web applications, a comprehensive metrics program is required, which performs ongoing measurement of the security posture of a web application, tracks progress, and in so doing, guides the selection of the most effective security related activities. The prototype, “Vulnerability Test Network Prototype”, hereafter referred to as VTNP, determines the security posture of a web application as early as possible in the development cycle and does this continuously as the web application is changed. This enables measuring and tracking the security posture of a web application and guides the selection of the most appropriate S-SDLC measures.

Read the paper · More papers on PaperTik