Secure development baseline
Development work is evaluated against information security management principles and current web application risk models.
- OWASP risk classes are reviewed during design and code review.
- Security expectations are defined before new modules, integrations or mobile workflows go live.
- Changes affecting authentication, authorization, tenant data or reporting are handled as high-impact changes.