preview

Security Analyst

Decent Essays

One of the biggest challenges, Security Analyst face is maintaining a balance between the App Security and time to market.

Both are crucial, if balance is not maintained, any one of it is bound to suffer. Once we agree to this fact, then comes the next question how to maintain the balance.

Use Case 1

Security Analyst: Scans the application, triage it and comes out with the Security Assessment report.

Developer: Receives a report, works on it, remediate the vulnerability reported. Plans for re-assessment.

Security Analyst: Re-assess the application, comes out with a re-scanned and re-assessed report.

Concern: :Old issues/vulnerability is successfully closed, but tool has identified few more new issues, issues are of high risk and need …show more content…

They can have different understanding about the issues and assessment can deviate up to some extent, which should be acceptable up to some extent. But what if high or medium vulnerability is identified in assessment by another Analyst 2, was not reported in initial scan. With this kind of in consistency application development time is exceeding.

Recommendations:

Application Security team should practice below guidelines to minimise the delta.

Prepare a common checklist of vulnerabilities and define its risk level (High, Medium and Low) as per the organisation impact on the application. So that analyst refer to the common checklist and high the issue in a correct category.
Try to do a peer review of the assessment report before publishing, so that others are also on same page and agree on the published assessment report.
Re-assessment to be done by a same analyst if possible, if not they should refer or consult the earlier version of report published.
Conclusion

By incorporating some basic but effective best practices, we can maintain the balance between application security and time to market by not attributing much in the increased SDLC time but at the same time promoting secured development

Get Access