Screen Shot 2016-08-27 at 11.32.39 PM

In this Security Report Analysis (SRA) series I look at various security reports and pull out the main points.

This doesn’t replace a complete and detailed read of these reports, but at least you’ll get exposed to some of the key takeaways that you might not otherwise have seen.


REPORT: Ponemon: Application Security in the Changing Risk Landscape


Key points

[ NOTE: These points are a combination of the report’s actual content combined with my interpretation. Some of the analysis is not theirs, in other words. Don’t take this as me putting words in their mouths, but rather me trying to parse and interpret for my and your benefit. ]

[ STUDY: The report is the result of a survey of 605 IT and InfoSec practitioners in the United States who are in some way tied to the information security function. ]

Summary

Here’s my breakdown.

  1. Application security attacks are harder to detect
  2. AppSec is WAY under-funded compared to NetSec
  3. Apps are the most attacked, but people still don’t even know where all their apps are and/or have them under management
  4. Developers still aren’t incentivized to make secure coding a priority
  5. Security is still adding enough slowdown to development that it’s probably a contributing factor to development teams ignoring it when they can

In short, it’s what many of us in AppSec expected: We need to reduce the friction of adding security to the lifecycle, we need to know where our apps are, and we need to spend more of our security budget on apps vs. network.


REPORT: Ponemon: Application Security in the Changing Risk Landscape


Notes

  1. While this capture can be helpful, I suggest reading the whole report for full context.
源链接

Hacking more

...