About
Subscribe

Execs neglect app security

Johannesburg, 05 Mar 2012

Applications is still not a priority in most organisations, as executives do not view it as a critical and strategic part of their business processes.

This emerged from a breakaway session at the RSA 2012 Conference, in San Francisco, on applications security last week. The session, themed “War Stories - the good, the bad and the ugly of app security”, was moderated by Chenxi Wang, principal analyst at Forrester Research.

Sitting on the panel were Brad Arkin, director of product security at Adobe; Doug Cavit, chief security strategist at Microsoft; and James Routh, global head of application security at JP MorganChase.

The panellists concurred that, in most cases, it is difficult to convince senior executives to prioritise applications security. And as businesses increasingly become more dependent on applications, these complex entities grow more difficult to secure, they said.

They also indicated that the cost of fixing vulnerabilities in applications can be damaging to an organisation. Thus, they called on businesses to implement solutions for application security during the initial stages of an app's life cycle.

It also emerged that while long-term fixes for applications are often most desirable, the reality is that organisations do not always have the time or resources to be able to implement them immediately.

They also cautioned that since apps have become the dominant source of information for many organisations, hackers are taking advantage and are exploiting vulnerabilities in these apps due to lax security systems.

Wang revealed that application security encompasses measures taken throughout the app's life cycle to prevent flaws or vulnerabilities in the security of an application.

Cavit pointed out that for organisations to improve the security of their applications software, they need a more proactive, holistic and systematic approach, in that they protect the software's whole life cycle, including the and host.

According to Arkin, software security is a rapidly evolving field and organisations are always on the lookout for ways to best adapt to the changing threat landscape. “However, if security is thought of as an additive to app security, then we have lost the plot.”

On the other hand, Routh noted that each organisation has a different app security DNA. He also urged businesses to develop resilient systems within their app ecosystems.

Share