September 18, 2003

Application Security Review and Testing Audit Work Program

Application security involves checking the security controls of an application, not the operating system or device that hosts the application. A thorough and exhaustive evaluation of the security issues related to e-Business applications is best tackled using a phased approach, such as that described here.