• Email
  • Like
  • Save
  • Private Content
  • Embed
 

Vulnerability Management In An Application Security World

by

  • 1,655 views

Identifying application-level vulnerabilities via penetration tests and code reviews is only the first step in actually addressing the underlying risk. Managing vulnerabilities for applications is ...

Identifying application-level vulnerabilities via penetration tests and code reviews is only the first step in actually addressing the underlying risk. Managing vulnerabilities for applications is more challenging than dealing with traditional infrastructure-level vulnerabilities because they typically require the coordination of security teams with application development teams and require security managers to secure time from developers during already-cramped development and release schedules. In addition, fixes require changes to custom application code and application-specific business logic rather than the patches and configuration changes that are often sufficient to address infrastructure-level vulnerabilities.
This presentation details many of the pitfalls organizations encounter while trying to manage application-level vulnerabilities as well as outlines strategies security teams can use for communicating with development teams. Similarities and differences between security teams’ practice of vulnerability management and development teams’ practice of defect management will be addressed in order to facilitate healthy communication between these groups.

From the OWASP Washington DC meeting August 5, 2009.

Accessibility

Categories

Upload Details

Uploaded via SlideShare as Adobe PDF

Usage Rights

© All Rights Reserved

Flagged as inappropriate Flag as inappropriate
Flag as inappropriate

Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

Cancel

7 Embeds 392

http://blog.denimgroup.com 222
http://www.denimgroup.com 116
http://denimgroup.typepad.com 28
http://www.robotcreative.com 21
http://www.slideshare.net 2
http://denimgroup.com 2
http://translate.googleusercontent.com 1

More...

Statistics

Likes
0
Downloads
33
Comments
0
Embed Views
392
Views on SlideShare
1,263
Total Views
1,655
Post Comment
Edit your comment

Vulnerability Management In An Application Security World Vulnerability Management In An Application Security World Presentation Transcript