HomeSecurityApplication security is a concern for CISOs

Application security is a concern for CISOs

Research finds that the top concern of security experts is application bugs, but that concern is not translating into secure development practices.

security-lock-security

Application vulnerabilities and malware continue to top the list of security professionals, but concerns have not translated into the adoption of secure development practices, a step that would improve application security flaws and detect software bugs earlier.

Seventy-two percent of the nearly 14,000 Chief Information Security Officers (CIOs) and other security professionals surveyed said application vulnerabilities were a top concern for them, according to the biennial Global Information Security Workforce Study published by the International Information Systems Security Certification Consortium (ISC) 2. However, only 24 percent of security professionals say their companies always check for bugs during the code development process, while 46 percent check for bugs sometimes during development.

The gap between security professionals' concerns and corporate practices highlights the importance of educating companies on the value of secure application development, said David Shearer, Executive Director of (ISC)2.

“The bottom line is that there is a tension between delivering [software] and meeting the schedule and doing the additional work required to build application security into the code stage—there is a tension there,” he said.

The (ISC)2 survey, prepared by Frost & Sullivan, predicts that a drastic shortage of cybersecurity professionals will have a significant impact on a variety of information security functions. The 2015 survey found that 62 percent of respondents said their companies do not have enough information security professionals, up from 56 percent who felt a similar shortage in the 2013 study.

A key issue for security professionals is managing application vulnerabilities, with 72 percent citing it as a top concern. Scanning for vulnerabilities in applications, either through static analysis or dynamic testing, is a key method of identifying vulnerabilities in an application, but 30 percent of companies have never scanned for vulnerabilities during code development, according to the survey.

The desire to audit applications increased dramatically following a breach or intrusion discovered by the company, with 58 percent of companies auditing all applications following a security incident, compared to 24 percent who audited applications consistently during code development.

Because of the tension between rapid software development and the time required to design product security and eliminate potential security flaws, most companies will continue to scan applications only after the software is in production or after a breach, Shearer said. Until application security requirements become part of the contract between the provider and the customer, this trend is likely to continue.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS