Measures for Secure Applications at Eye-Able
Which measures has Eye-Able implemented for secure applications?
This article gives an overview of Eye-Able's application security framework as well as the policies, deployment processes, testing procedures and vulnerability management used to secure applications.
Application security framework
Eye-Able has a comprehensive application security framework that governs secure development and deployment both organisationally and technically.
Documented, approved and regularly updated policies for application security are in place, defining, among other things, minimum requirements, SDLC processes, development standards and testing requirements.
Security requirements in the SDLC process and for every application
The SDLC process integrates security requirements from the outset into design, development, testing and operation.
Binding technical and organisational security requirements apply to every application and are defined on the basis of the protection needs assessment.
Testing strategy and process automation
The testing strategy comprises automated static and dynamic analyses (SAST/DAST), manual code reviews and security sign-offs before go-live.
Build, test and deployment processes are, where possible, carried out automatically in controlled CI/CD pipelines.
Handling and tracking of security vulnerabilities
Security vulnerabilities are prioritised, handled and documented in accordance with standardised procedures.
The remediation of critical vulnerabilities is preferably carried out automatically and under central tracking.
Alignment with standards and a consistent security level
All measures are aligned with recognised standards (e.g. OWASP ASVS, ISO 27002) and documented in an audit-proof manner.
This ensures a consistent security level throughout the entire lifecycle of an application.
Further help
Do you have further questions or need personal support? The following article explains how you can get in touch with us: