Application Developer Guidance

From attackics
Revision as of 13:48, 10 April 2021 by Oalexander (talk | contribs) (Oalexander moved page Application Developer Guidance to Application Developer Guidance)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to navigation Jump to search
Application Developer Guidance
Mitigation
ID M0913
NIST SP 800-53 Rev. 4 AT-3

Description

This mitigation describes any guidance or training given to developers of applications to avoid introducing security weaknesses that an adversary may be able to take advantage of.


Techniques Addressed by Mitigation

NameUse
Valid AccountsEnsure that applications and devices do not store sensitive data or credentials insecurely (e.g., plaintext credentials in code, published credentials in repositories, or credentials in public cloud storage).1