Budgeting for Web Application Security
Great post on Budgeting for Web Application Security by Jeremiah Grossman.
Some key approaches are:
Some key approaches are:
- Risk Mitigation - "If we spend $X on Y, we’ll reduce of risk of loss of $A by B%."
- Due Diligence - "We must spend $X on Y because it’s an industry best-practice."
- Incident Response - "We must spend $X on Y so that Z never happens again."
- Regulatory Compliance - "We must spend $X on Y because PCI-DSS says so."
- Competitive Advantage - "We must spend $X on Y to make the customer happy."




0 comments:
Post a Comment