Why are security audits of software critical for addressing IT risk?
One of the greatest – but least understood – sources of IT security risks lies within software applications. As the engines that power today’s global enterprises, they process, calculate, transmit, and store the data that are an organization’s primary asset. Gartner states that 70% of attacks come at the application layer, yet security audits are never performed on most critical software applications to identify vulnerabilities that may expose critical data and operations to hackers. Increasing consequences caused by regulations, targeted attacks and consumer awareness mandate IT security audits and an enterprise-wide approach for measuring and addressing risk to operations from vulnerable software.