Skip to main content

Securing an Application: A Paper on Plastic

This paper discusses the process of integrating a credit card application to the front end of already existing accounting and payments processing applications. It discusses the information risk analysis process needed to drive out a plan to secure the sensitive credit card information and the action plan to implementing the mitigated controls. Securing an application involves much more than the mechanics of creating access groups and granting permissions. It involves establishing business management alliances, building relationships with technical subject matter experts, and creating an environment for open dialog between these entities as well as with the members of the project team. Today, applications tend to be multi-platform, complex, integrated with purchased vendor products, and, many times, linked to external (to the company) customers and businesses. In this environment, the jobs of security professionals are complex, requiring the need to integrate dissimilar security solutions in order to provide the level of risk tolerance suitable to the application and yet complying with governmental laws and industry regulations.

855 (PDF, 1.78MB)

28 Feb 2003
ByJoe Rhode
Share
All papers are copyrighted

No re-posting of papers is permitted

Subscribe to GIAC’s Monthly Newsletter

Receive expert insights, priority access to certifications, essential updates on regulatory changes and industry developments.