- CEOs see mobile for employees as their top mandate for upcoming technology innovation initiatives, making security a key competency for development.
- Unsecure mobile applications can cause your employees to question the mobile applications’ integrity for handling sensitive data, limiting uptake.
- Secure mobile development tends to be an afterthought, where vulnerabilities are tested for post-production rather than during the build process.
- Developers lack the expertise, processes, and proper tools to effectively enhance applications for mobile security.
Our Advice
Critical Insight
- Organizations currently react to security issues. Info-Tech recommends a proactive approach to ensure a secure software development life cycle (SSDLC) end-to-end.
- Organizations currently lack the secure development practices to provide highly secure mobile applications that end users can trust.
- Enable your developers with five key secure development techniques from Info-Tech’s development toolkit.
Impact and Result
- Embed secure development techniques into your SDLC.
- Create a repeatable process for your developers to continually evaluate and optimize mobile application security for new threats and corresponding mitigation steps.
- Build capabilities within your team based on Info-Tech’s framework by supporting ongoing security improvements through monitoring and metric analysis.
Workshop: Strengthen the SSDLC for Enterprise Mobile Applications
Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.
Module 1: Assess Your Secure Mobile Development Practices
The Purpose
- Identification of the triggers of your secure mobile development initiatives.
- Assessment of the security vulnerabilities in your mobile applications from an end-user perspective.
- Identification of the execution of your mobile environment.
- Assessment of the mobile threats and vulnerabilities to your systems architecture.
- Prioritization of your mobile threats.
- Creation of your risk register.
Key Benefits Achieved
- Key opportunity areas where a secure development optimization initiative can provide tangible benefits.
- Identification of security requirements.
- Prioritized list of security threats.
- Initial mobile security risk register created.
Activities
Outputs
Establish the triggers of your secure mobile development initiatives.
- Mobile Application High-Level Design Requirements Document
Assess the security vulnerabilities in your mobile applications from an end-user perspective.
- Systems Architecture Diagram
Understand the execution of your mobile environment with a systems architecture.
Assess the mobile threats and vulnerabilities to your systems architecture.
Prioritize your mobile threats.
Begin building your risk register.
Module 2: Implement and Test Your Secure Mobile Techniques
The Purpose
- Discovery of secure development techniques to apply to current development practices.
- Discovery of new user stories from applying secure development techniques.
- Discovery of new test cases from applying secure development techniques.
Key Benefits Achieved
- Areas within your code that can be optimized for improving mobile application security.
- New user stories created in relation to mitigation steps.
- New test cases created in relation to mitigation steps.
Activities
Outputs
Gauge the state of your secure mobile development practices.
Identify the appropriate techniques to fill gaps.
- Mobile Application High-Level Design Requirements Document
Develop user stories from security development gaps identified.
Develop test cases from user story gaps identified.
Module 3: Monitor and Support Your Secure Mobile Applications
The Purpose
- Identification of key metrics used to measure mobile application security issues.
- Identification of secure mobile application and development process optimization initiatives.
- Identification of enablers and blockers of your mobile security optimization.
Key Benefits Achieved
- Metrics for measuring application security.
- Modified triaging process for addressing security issues.
- Initiatives for development optimization.
- Enablers and blockers identified for mobile security optimization initiatives.
- Process for developing your mobile optimization roadmap.
Activities
Outputs
List the metrics that would be gathered to assess the success of your mobile security optimization.
Adjust and modify your triaging process to enhance handling of security issues.
Brainstorm secure mobile application and development process optimization initiatives.
- Mobile Optimization Roadmap
Identify the enablers and blockers of your mobile security optimization.
Define your mobile security optimization roadmap.