Risk-Based Application Security Management
In a large organization with thousands of applications and a small security team, a strategic application security management system is required to sustain security at the enterprise level. AppScan Enterprise 9.0offers a risk-based approach to efficiently address this requirement. However, a single measure of risk that can properly correspond to every organization’s strategy cannot be strictly determined and programmed. With IBM AppScan Enterprise 9.0, organizations can define risk based on their own strategy.
A measure for risk can be determined on an application by factors such as access, business impact, significance of security threats and so on. All these factors can be customized and programmed into AppScan Enterprise’s calculations. With this flexibility, managers can define rules to measure risk and then automatically classify or rank applications based on that risk to help them make reliable and resource-efficient decisions.