ISC2 CISSP (Certified Information Systems Security Professional)Security Architecture and EngineeringEasy
A software development team is designing a new web application that will handle sensitive customer data. They are concerned about potential vulnerabilities introduced during the coding phase. Which of the following principles should they prioritize to mitigate common web application risks identified by organizations like OWASP?
- AImplementing secure coding guidelines and conducting regular code reviews.
- BMaximizing code reuse from open-source libraries to accelerate development.
- CRelying solely on perimeter firewalls and intrusion detection systems for protection.
- DDeploying the application to a public cloud provider with built-in security features.
Show answer & explanationAnswer & explanation
Correct answer: A. Implementing secure coding guidelines and conducting regular code reviews.
Implementing secure coding guidelines and conducting regular code reviews are fundamental practices for addressing common web application vulnerabilities identified by OWASP. This proactive approach helps prevent security flaws from being introduced into the codebase.
Why the other options are wrong
- B. While code reuse can be efficient, it can also introduce vulnerabilities if not carefully vetted and secured.
- C. Perimeter defenses are important but do not protect against vulnerabilities within the application itself.
- D. Cloud providers offer infrastructure security, but the application layer security remains the developer's responsibility.
Secure Coding Guidelines
A set of best practices and rules for writing software code that minimizes security vulnerabilities.
- Aims to prevent common flaws like injection, XSS, and broken authentication.
- Often based on industry standards like OWASP Top 10.
- Integral part of a secure software development lifecycle (SSDLC).
Memory trick: Web apps need strong code, just like a knight needs strong armor.