3. Identifying and Selecting Measures

3.1. Security measures

Security measures encompass policies, procedures, and technologies designed to protect information, systems, and physical spaces from potential threats. 

Key security measures in software are:
  • Authentication and Authorization: Implementing Multi-Factor Authentication (MFA) and Role-Based Access Control (RBAC) to ensure only authorized users access specific data.
  • Data Protection: Using encryption (e.g., AES-256 for data at rest, TLS for data in transit) and data masking/tokenization to secure sensitive information.
  • Secure Coding Practices: Following secure coding guidelines, such as input validation to prevent SQL injection and Cross-Site Scripting (XSS).
  • Vulnerability Assessment & Testing: Performing Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and penetration testing to identify flaws.
  • Software Composition Analysis (SCA): Managing open-source components to ensure they are updated and free from known vulnerabilities.
  • Patch Management & Updates: Regularly updating software to fix security vulnerabilities.
  • Logging and Monitoring: Using Security Information and Event Management (SIEM) systems to detect anomalies and unauthorized activity.
  • Security in SDLC: Integrating security throughout the software development life cycle (SDLC) from design to deployment.