How to Improve Your Application Security Practices
Organizations talk a good game when it comes to security, but many still focus the majority of their security resources on the network rather than their applications--the vector for most data breaches. Many organizations dedicate less than 10 percent of their IT security budget to application security, according to a study by research firm the Ponemon Institute, released earlier this year.
The reasons for this gap are multifaceted, says Jeremiah Grossman, founder and CTO of WhiteHat Security, provider of a continuous vulnerability assessment and management service for thousands of Web sites, including the Web sites of dozens of Fortune 500 companies. First, he says, many security professionals have a blind spot for software.
"Most of the security guys out there are not software people," he says. "They come from an IT background. All they really know how to do is protect the network." Second, regulatory compliance and the cruft that comes with regulations based on past threats also play a role in Grossman's view.