Search

  
 
Data put at risk by app testing naivety


December 11 2007

Data put at risk by app testing naivety

 

A new report has found that 62 percent of companies use real rather than disguised customer data during the application development and testing process.


This includes employee, vendor and customer records, and credit card and Social Security numbers, says the Ponemon Institute report. This data often isn't protected in a non-production environment. Thus it could be vulnerable to unauthorised sources including in-house testing staff, consultants, partners and offshore personnel.

The latter is particularly notable, since 52 percent of the companies outsourced application testing, and 49 percent of those respondents shared live data with the outsourced organisation.

"For many organisations, large customer data files represent an easy, cheap source of data to use when testing applications, but this process introduces a huge element of risk to the challenge of maintaining the integrity of sensitive information, particularly when third parties and offshore resources are involved," said Dr. Larry Ponemon, chairman of the Ponemon Institute, in a statement.

According to the study:

The survey, commissioned by Compuware, was conducted between July 2007 and August 2007, based on the responses of 897 IT professionals with an average of ten years experience.


 

Reproduced from an article published by Techworld.com
© Techworld.com

The original article can be viewed here:
http://www.techworld.com/security/news/index.cfm?NewsID=10894

 Bookmark Digg this story

RSS feed  |  About RSS feeds

Get the Industry's top stories delivered straight to your inbox...
Firstname:

Surname:

Email:

Frequency:
 Daily  Weekly
 
 
Industry News
Case Studies
White Papers
Press Releases
Vulnerability Advisories
Monthly Newsletter Archive
Bandwidth Management
Consultancy Products
Content Control
Desktop Protection
Email Management
Encryption Solutions
Firewall/VPN Solutions
Identity and Security
Intrusion Management
Network Optimisation
Secure Remote Access
SIEM (Event correlation)
Strong Access Control
Vulnerability Management
Web Services Security
Wireless Security
About GSS
Supported Charities
Partner Accreditations
Exhibitions & Events
Contact Details
Location
Careers
Terms & Conditions of Sale
Network Penetration Testing
Web Application Testing
Managed Vulnerability Scanning
Citrix ESA
Wireless Scanning
GCSx ITHC Testing
Vulnerability Advisories
ICS Catalogue