Requirement:
The cybersecurity requirements for external web applications must be implemented.
Control Implementation Guidelines:
- Implement all cybersecurity requirements to External web applications security procedures in the organization. The External web applications security procedures must cover at least the following, but not limited to:
- Web Application Firewall
- Multi-tier Architecture
- Use secure protocols such as HTTPS
- Clarify secure user usage policy
- Multi-Factor Authentication of users' access
- Develop an action plan to implement all cybersecurity requirements related to external web applications security
- Include cybersecurity requirements for external web applications security in the organization's external web applications security procedures to ensure compliance with cybersecurity requirements for all internal and external stakeholders
Expected Deliverables:
- Documents that confirm the implementation of cybersecurity requirements related to the protection of external web applications as documented in the policy
- An action plan document to implement the cybersecurity requirements for external web applications security
- Evidence showing the implementation of external web applications security controls, including but not limited to:
- Screenshot of web application firewall used by the organization
- Sample of web application designs that demonstrate the use of a multi-tier architecture principle for the organization's web application
- Screenshot from a web application showing the use of HTTPS in its link
- Screenshot from the organization's website indicating the publication of the secure usage policy for users
- Multiple screenshots showing entry process including MFA
Quick & Simple
Discover Our Cybersecurity Compliance Solutions:
Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you