{"id":53377,"date":"2014-05-19T14:16:33","date_gmt":"2014-05-19T14:16:33","guid":{"rendered":"https:\/\/www.checkmarx.com\/?post_type=glossary&#038;p=8435"},"modified":"2024-07-15T16:25:14","modified_gmt":"2024-07-15T16:25:14","slug":"enterprise-application-security-through-secure-development","status":"publish","type":"glossary","link":"https:\/\/checkmarx.com\/glossary\/enterprise-application-security-through-secure-development\/","title":{"rendered":"Enterprise Application Security through Secure Development"},"content":{"rendered":"<h2 class=\"article-anchor\" id=\"article-anchor-1\"><b>How critical is secure development?<\/b><\/h2>\n<p>Web threats are constant threats to company security. A single data breach can cost companies thousands or even millions of dollars. If a malicious attacker gains unauthorized access to the company network, it can put sensitive company information, confidential customer and client information, and company assets at risk. Malware is the leading cause of data breaches, and malicious code can often be hidden in application code without detection. Applications, whether developed on-site or third-party implementations, must be completely secured. The cost incurred for each lost or stolen record containing sensitive and confidential information increased more than nine percent to a consolidated average of $145, while overall, the average data breach has increased 15% over the last year for total company response costs of $3.5 million.<br>\n<span style=\"color: #333333;\"><!--more--><\/span><br>\nSecure development ensures that applications are free from flaws, defects and vulnerabilities that could potentially contribute to a company data breach, costing the company hundreds, thousands, or even millions of dollars.<br>\n<b><\/b><\/p>\n<h2 class=\"article-anchor\" id=\"article-anchor-2\"><b><br>\nSecure development benefits<\/b><\/h2>\n<p>Secure development lifecycle benefits range from network security, threat and vulnerability elimination, competent defense of a DDoS attack, data security and backup planning, and much more. This eliminates external, as well as internal threats, and provides secure application code for company developmental use. By creating a solid outline for secure development, companies can manage their application and network security in a simple, efficient and cost-effective manner.<\/p>\n<h2 class=\"article-anchor\" id=\"article-anchor-3\"><b>Security Development Lifecycle<\/b><\/h2>\n<p>The Security Development Lifecycle is the process used for planning, creating, testing, and deploying an information system such as an application or other software. It also incorporates the security of the application code in order to ensure that there are no vulnerabilities or weaknesses that could be exploited by a malicious attacker. While the stages of the process vary depending on the type of software to be developed, there are typically five stages that are always constant.<\/p>\n<ul>\n<li>\n<b>Analysis<\/b>: This the pre-planning stage which involves collaboration between developers, management and consumers to determine the best course of action to take.<\/li>\n<li>\n<b>Design<\/b>: Developers use the results from the information gathering phase to develop prototypes and come up with a solid design for a final product.<\/li>\n<li>\n<b>Coding<\/b>: The software code for the application is developed, then undergoes extensive security testing including vulnerability assessment and penetration testing.<\/li>\n<li>\n<b>Testing<\/b>: The application is tested to see if it performs as expected, as well as to determine if there are any additional bugs or vulnerabilities not found during the coding phase.<\/li>\n<li>\n<b>Deployment<\/b>: The application is deployed across the system and integrated into the network to ensure proper usage and security.<\/li>\n<\/ul>\n<p>There are two methods of SDLC, <a href=\"https:\/\/www.sdlc.ws\/agile-vs-waterfall\/\">waterfall and agile<\/a>. The method used varies due to the complexity and size of the project.<\/p>\n<h2 class=\"article-anchor\" id=\"article-anchor-4\"><b>Secure coding during the SDLC<\/b><\/h2>\n<p>As part of the SDLC, secure coding practices and testing is required. The developers should have proper training that provides them with proper certification and CPE credits. Compliance with ISO regulations including SANS Application Security Procurement Contract Language is essential for secure coding.<\/p>","protected":false},"excerpt":{"rendered":"<p>How critical is secure development? Web threats are constant threats to company security. A single data breach can cost companies thousands or even millions of dollars. If a malicious attacker gains unauthorized access to the company network, it can put sensitive company information, confidential customer and client information, and company assets at risk. Malware is [&hellip;]<\/p>\n","protected":false},"author":11,"featured_media":0,"template":"","glossary-tags":[],"class_list":["post-53377","glossary","type-glossary","status-publish","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.1.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Enterprise Application Security through Secure Development - Checkmarx<\/title>\n<meta name=\"description\" content=\"Enterprise Application Security through Secure Development And just How critical is secure development? - Checkmarx\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/checkmarx.com\/glossary\/enterprise-application-security-through-secure-development\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Enterprise Application Security through Secure Development - Checkmarx\" \/>\n<meta property=\"og:description\" content=\"Enterprise Application Security through Secure Development And just How critical is secure development? - Checkmarx\" \/>\n<meta property=\"og:url\" content=\"https:\/\/checkmarx.com\/glossary\/enterprise-application-security-through-secure-development\/\" \/>\n<meta property=\"og:site_name\" content=\"Checkmarx\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis\" \/>\n<meta property=\"article:modified_time\" content=\"2024-07-15T16:25:14+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@checkmarx\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/checkmarx.com\/glossary\/enterprise-application-security-through-secure-development\/\",\"url\":\"https:\/\/checkmarx.com\/glossary\/enterprise-application-security-through-secure-development\/\",\"name\":\"Enterprise Application Security through Secure Development - Checkmarx\",\"isPartOf\":{\"@id\":\"https:\/\/checkmarx.com\/#website\"},\"datePublished\":\"2014-05-19T14:16:33+00:00\",\"dateModified\":\"2024-07-15T16:25:14+00:00\",\"description\":\"Enterprise Application Security through Secure Development And just How critical is secure development? - Checkmarx\",\"breadcrumb\":{\"@id\":\"https:\/\/checkmarx.com\/glossary\/enterprise-application-security-through-secure-development\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/checkmarx.com\/glossary\/enterprise-application-security-through-secure-development\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/checkmarx.com\/glossary\/enterprise-application-security-through-secure-development\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Glossary\",\"item\":\"https:\/\/checkmarx.com\/glossary\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Enterprise Application Security through Secure Development\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/checkmarx.com\/#website\",\"url\":\"https:\/\/checkmarx.com\/\",\"name\":\"Checkmarx\",\"description\":\"The world runs on code. We secure it.\",\"publisher\":{\"@id\":\"https:\/\/checkmarx.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/checkmarx.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/checkmarx.com\/#organization\",\"name\":\"Checkmarx\",\"url\":\"https:\/\/checkmarx.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg\",\"width\":1,\"height\":1,\"caption\":\"Checkmarx\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis\",\"https:\/\/x.com\/checkmarx\",\"https:\/\/www.youtube.com\/user\/CheckmarxResearchLab\",\"https:\/\/www.linkedin.com\/company\/checkmarx\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Enterprise Application Security through Secure Development - Checkmarx","description":"Enterprise Application Security through Secure Development And just How critical is secure development? - Checkmarx","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/checkmarx.com\/glossary\/enterprise-application-security-through-secure-development\/","og_locale":"en_US","og_type":"article","og_title":"Enterprise Application Security through Secure Development - Checkmarx","og_description":"Enterprise Application Security through Secure Development And just How critical is secure development? - Checkmarx","og_url":"https:\/\/checkmarx.com\/glossary\/enterprise-application-security-through-secure-development\/","og_site_name":"Checkmarx","article_publisher":"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis","article_modified_time":"2024-07-15T16:25:14+00:00","twitter_card":"summary_large_image","twitter_site":"@checkmarx","twitter_misc":{"Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/checkmarx.com\/glossary\/enterprise-application-security-through-secure-development\/","url":"https:\/\/checkmarx.com\/glossary\/enterprise-application-security-through-secure-development\/","name":"Enterprise Application Security through Secure Development - Checkmarx","isPartOf":{"@id":"https:\/\/checkmarx.com\/#website"},"datePublished":"2014-05-19T14:16:33+00:00","dateModified":"2024-07-15T16:25:14+00:00","description":"Enterprise Application Security through Secure Development And just How critical is secure development? - Checkmarx","breadcrumb":{"@id":"https:\/\/checkmarx.com\/glossary\/enterprise-application-security-through-secure-development\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/checkmarx.com\/glossary\/enterprise-application-security-through-secure-development\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/checkmarx.com\/glossary\/enterprise-application-security-through-secure-development\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Glossary","item":"https:\/\/checkmarx.com\/glossary\/"},{"@type":"ListItem","position":2,"name":"Enterprise Application Security through Secure Development"}]},{"@type":"WebSite","@id":"https:\/\/checkmarx.com\/#website","url":"https:\/\/checkmarx.com\/","name":"Checkmarx","description":"The world runs on code. We secure it.","publisher":{"@id":"https:\/\/checkmarx.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/checkmarx.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/checkmarx.com\/#organization","name":"Checkmarx","url":"https:\/\/checkmarx.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg","width":1,"height":1,"caption":"Checkmarx"},"image":{"@id":"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis","https:\/\/x.com\/checkmarx","https:\/\/www.youtube.com\/user\/CheckmarxResearchLab","https:\/\/www.linkedin.com\/company\/checkmarx"]}]}},"_links":{"self":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/glossary\/53377","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/glossary"}],"about":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/types\/glossary"}],"author":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/users\/11"}],"version-history":[{"count":0,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/glossary\/53377\/revisions"}],"wp:attachment":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/media?parent=53377"}],"wp:term":[{"taxonomy":"glossary-tags","embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/glossary-tags?post=53377"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}