Requirement:
Cybersecurity requirements for external web applications must be defined, documented and approved.
Control Implementation Guidelines:
- Include and document cybersecurity requirements for the organization's external web applications security against cyber risks, including, but not limited to:
- Web Application Firewall
- Multi-tier Architecture
- Use secure protocols such as HTTPS
- Use of applications development and update standards and testing them
- Clarify secure user usage policy
- Multi-Factor Authentication of users' access
- Screening for application-specific vulnerabilities (Vulnerability Assessment)
- Regular backups in secure locations (Backup Log Files)
- Regular screening of open ports, services, processes, and unused protocols
- Cybersecurity requirements for the security of external web applications must be supported by the Executive Management. This must be done through the approval of the organization head or his/her deputy
Relevant Cybersecurity Tools:
- Web Application Protection Policy Template
Expected Deliverables:
- A cybersecurity policy that covers the requirements for the organization's external web applications security against cyber risks (electronic copy or official hard copy)
- Formal approval by the head of the organization or his/her deputy on such document (e.g., via the organization's official e-mail, paper or electronic signature)
Quick & Simple
Discover Our Cybersecurity Compliance Solutions:
Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you