|
An Introduction To |
|
Correct processing in applicationsObjective: To prevent errors, loss, unauthorised modification or misuse of information in applications. Appropriate security controls, validation methodologies and audit trails or activity logs should be designed into application systems. Input data validationData input into application systems should validated. Control of internal processingData processed by application systems should be validated. Message integrityA message authentication system should be considered for applications that have a requirement to protect the integrity and authenticity of the message content. Output data validationData input from application systems should validated. |
The Security Practitioner An Introduction to Information Security |