Skip to content

Application Security

What is Application Security?

The practice of finding, fixing, and preventing security vulnerabilities in software applications throughout the development lifecycle. Includes code review, penetration testing, and security architecture design.

Information Security

Each of these is named in at least one of the same controls as application security. The number is how many controls name both.

What the standards actually require on application security

Requirements naming application security across 6 standards, quoted from the control text.

CIS Controls v84 controls

Ensure that all software development personnel receive training in writing secure code for their specific development environment and responsibilities. Training can include general security principles and application security standard practices.

CIS-16.9 · Train Developers in Application Security Concepts and Secure Coding

Define and keep current the minimum security requirements each class of application must satisfy before it is built or released.

CCM-AIS-02 · Application Security Baseline Requirements

The OWASP Application Security Verification Standard is used in the development of web applications.

ISM-0971 · The OWASP Application Security Verification Standard is used in the development of web app

Integrate dynamic application security testing into the delivery workflow as a gating control, so results can prevent vulnerable builds reaching production.

ASBv3-DS-5 · Integrate dynamic application security testing into DevOps pipeline

Integrate routine static, dynamic, and interactive application security testing throughout the development and deployment lifecycle.

ZTMM-APP-TEST · Applications Pillar: Application Security Testing

Applications undergo SAST, DAST, dependency scanning, and penetration testing with remediation tracking.

IS-IV.E.2 · Application Security Testing

Questions people ask about application security

What is Application Security?
The practice of finding, fixing, and preventing security vulnerabilities in software applications throughout the development lifecycle. Includes code review, penetration testing, and security architecture design.
Why is Application Security important for compliance?
Application Security is a key concept in Information Security. Understanding application security helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Application Security?
Application Security appears in the requirement text of CIS Controls v8, Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1, Australian Information Security Manual, Azure Security Benchmark, CISA Zero Trust Maturity Model. Across these standards we have identified 17 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Application Security?
Explore our compliance framework pages to see how application security applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Application Security applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.