About
Subscribe
  • Home
  • /
  • Computing
  • /
  • Are directors and auditors aware of the data security risks of Web applications?

Are directors and auditors aware of the data security risks of Web applications?

Johannesburg, 23 Oct 2009

While Web applications may be essential to a business, if they are not secured, they can provide an open door for hackers to a company's most sensitive data.

According to the Web Application Security Consortium (WASC), more than 40% of Web hacking incidents are aimed at stealing personal information, which is the easiest virtual commodity to exchange for money. According to WASC, in scans of over 31 000 sites, over 85% showed a vulnerability that could give hackers the ability to read, modify and transmit sensitive data.

Many companies are not doing enough to protect their data linked to Web applications. In a recent survey of over 1 000 IT professionals worldwide, over 50% have not implemented an automated application security solution. Of these, some are using manual testing methods, and others are entrusting their security to firewalls and other infrastructure related areas, but most fail to apply application security measures.

Relevant company directors and internal auditors can be held accountable for data stolen if found not to have done enough to protect their application data from threats such as hacking.

Web applications should be tested and scanned for vulnerabilities. Production security tests must be accurate. Hackers are finding new ways of penetrating applications every day. Manual security testing is inadequate in addressing the continual evolution and discovery of new hacking techniques; security professionals need software that is up to date with the latest vulnerabilities.

There are software solutions available that can help companies reduce their Web application data vulnerability risks and improve their compliance of relevant industry regulations. An example of such a solution can scan a production Web application and report on vulnerabilities that exist on that application and suggestions to fix.

SORTIT and Rubric Consulting have been focusing on providing application, functional performance and security testing solutions and services for many years in South Africa.

SORTIT was started in 2005. The company has quickly built a reputation as a company that provides quality and fair value in everything it delivers. Its focus is in providing market leading IT solutions and consultancy to help its customers optimise and secure their IT so they can achieve more business value from IT investments, and to manage their IT governance, risk and compliance.

Share

Editorial contacts

Jose De Nobrega
sortit
(011) 325 6213
info@sortit.co.za