New addition to the IT Governance catalogue: Application Security in the ISO 27001:2013 Environment, second edition


Ely, England, 20 October 2015 – The international information security experts IT Governance have added a new title to their catalogue: the second edition of Application Security in the ISO 27001:2013 Environment.
Updated to reflect ISO 27001:2013, Application Security in the ISO 27001:2013 Environment, second edition explains how organisations can implement and maintain effective security practices to protect their web applications – and the servers on which they reside – as part of a wider information security management system by following the guidance set out in the international standard for information security management, ISO 27001.
It describes the methods used by criminal hackers to attack organisations via their web applications and provides a detailed explanation of how organisations can combat such attacks by employing the guidance and controls set out in ISO 27001.
Topics covered include:
  • A full introduction to ISO 27001 and information security management systems, including implementation guidance.
  • Risk assessment, management and treatment approaches.
  • Common types of web app security attack, including injection attacks, cross-site scripting, and attacks on authentication and session management, explaining how each can compromise ISO 27001 control objectives and showing how to test for each attack type.
  • The ISO 27001 controls relevant to application security.
  • Useful web app security metrics and their relevance to ISO 27001 controls.
  • A four-step approach to threat profiling, and descriptions of application security review and testing approaches.
  • Guidelines and the ISO 27001 controls relevant to them, covering:
o    input validation
o    authentication
o    authorisation
o    sensitive data handling and the use of TLS rather than SSL
o    session management
o    error handling and logging
  • The importance of security as part of the web app development process.
Application Security in the ISO 27001:2013 Environment, second edition is available from IT Governance in various formats (including softcover, Adobe eBook, Kindle and ePub): (International) (USA) (EU) (APAC) (India and South Asia) (Southern Africa)
This website uses cookies. View our cookie policy