ISC2 CISSP (Certified Information Systems Security Professional)Security Architecture and EngineeringMedium

An organization is deploying a new web server that will host a public-facing application. To prevent common attacks such as SQL Injection and Cross-Site Scripting (XSS), the development team is adopting a 'secure by design' approach. Which of the following is the most effective security control to implement at the application layer to mitigate these specific vulnerabilities?

  1. AEnsuring all user input is properly validated and sanitized.
  2. BImplementing strong password policies for all user accounts.
  3. CUsing HTTPS to encrypt all traffic between the client and server.
  4. DDeploying a Web Application Firewall (WAF) in front of the server.
Show answer & explanation

Correct answer: A. Ensuring all user input is properly validated and sanitized.

Proper input validation and sanitization at the application layer are the most direct and effective controls against SQL Injection and XSS. SQL Injection is prevented by sanitizing input to prevent malicious database queries, and XSS is prevented by sanitizing output to prevent malicious scripts from executing in the user's browser.

Why the other options are wrong

  • B. Strong password policies mitigate authentication-related attacks, not injection or XSS.
  • C. HTTPS encrypts data in transit, protecting confidentiality and integrity of communication, but not against logical flaws like injection attacks within the application.
  • D. A WAF provides a layer of defense but is not a substitute for secure coding practices within the application itself.

Input Validation & Sanitization

The process of ensuring user-supplied data conforms to expected formats and removing or encoding potentially malicious characters.

  • Crucial for preventing injection attacks (SQL, XSS, OS Command).
  • Validation checks if input is legitimate, sanitization makes it safe.
  • Must be performed on all untrusted input, both client-side and server-side.

Memory trick: Clean your input, or your app will get sick!

More Security Architecture and Engineering questions