How does ensuring web application security affect an organizations regulatory compliance?
Web application security is a significant element of compliance with the laws, regulations, and policies that govern an organization and its data. Weak application security can represent, for example, a significant control deficiency in terms of compliance with the Sarbanes-Oxley Act; potentially compromising the reliability of financial information and reporting. Compliance guides for Commercial Organizations, Financial Services firms and Federal Agencies are available at the Ounce Labs’ library. Please refer to the appendixes of Software Security Assurance Guide for references to example laws and regulations related to information security, and cross-reference sources of guidance for assuring effective compliance practices.