Application context
Understand architecture, data and trust boundaries.
Review application design, configuration and development controls before weaknesses become expensive production incidents.
Teams preparing a production release
Businesses inheriting or acquiring software
Development teams improving secure delivery
Understand architecture, data and trust boundaries.
Assess configuration, controls and development practices.
Give developers specific, prioritised improvements.
Agree the application and review depth.
Review evidence and validate material weaknesses.
Prioritise fixes and secure-development changes.
An application audit can include different evidence and review methods. Where active penetration testing is required, it is explicitly scoped and authorised.
Answer nine questions to find the security gaps that deserve attention now.