Threat Modeling: A Process To Ensure Application Security

Hacker Halted 2010

86
vote

Application security has become a major concern in recent years. Hackers are
using new techniques to gain access to sensitive data, disable applications and
administer other malicious activities aimed at the software application. The
need to secure an application is imperative for use in today’s world. Until
recently, application security was an afterthought; developers were typically
focused on functionality and features, waiting to implement security at the end
of development. This approach to application security has proven to be
disastrous; many vulnerabilities have gone undetected allowing applications to
be attacked and damaged. This raises the following questions: How can
application security become an integral part of the development process? How
can an application design team discover and avoid vulnerabilities in their
application? There are three measures that can help discovering and avoiding
security vulnerabilities:
http://www.sans.org/rr/whitepapers/securecode/1646.php