• Access Rights & Permissions Matrix
    • Data Breach Notification Log
    • Data Classification Register
    • Data Loss Prevention (DLP) Incident Log
    • Document Retention & Disposal Tracker
    • Security KPI Dashboard
    • Asymmetric-Key Cryptography
    • Combined Security Model: Digital Signature + Digital Envelope
    • Database Encryption Techniques (API, Plug-in, TDE)
    • Diffie-Hellman Key Exchange
    • Digital Envelope
    • Digital Signature
    • Hash Function
    • Homomorphic Encryption
    • Hybrid Cryptography
    • PKI (Public Key Infrastructure)
    • Post-Quantum Cryptography (PQC)
    • Quantum Security
    • RSA Encryption
    • Sign-then-Encrypt
    • Symmetric-Key Cryptography
    • CIA Triad
    • Endpoint Security
    • Systematic Server Defense Strategy
    • DDoS Attack Mitigation Plan Tracker
    • IP Whitelist–Blacklist Tracker
    • Network Access Control Log
    • Network Device Inventory
    • Network Security Risk Mitigation
    • Network Traffic Monitoring Dashboard
    • DDoS (Distributed Denial of Service)
    • DRDoS (Distributed Reflective Denial of Service)
    • Network Separation & Integration
    • SASE (Secure Access Service Edge)
    • SDP (Software Defined Perimeter)
    • Spoofing
    • Zero Trust
    • IPSec
    • OSI 7-Layer Security
    • OSI 7-Layer Security Threats
    • TLS (Transport Layer Security)
    • Cloud Access Control Matrix
    • Cloud Asset Inventory Tracker
    • Cloud Backup & Recovery Testing Tracker
    • Cloud Incident Response Log
    • Cloud Security Configuration Baseline
    • CASB (Cloud Access Security Broker)
    • CNAPP (Cloud Native Application Protection Platform)
    • The Two Pillars of Cloud Security (CSPM and CWPP)
    • DSPM (Data Security Posture Management)
    • Integrated Cloud-Native Security Architecture
    • Shadow IT
    • Kubernetes Security
    • Amdahl's Law
    • Patch & Update Tracker
    • Secure Coding Checklist
    • Secure Mobile App Testing Tracker
    • Security Misconfiguration Log
    • Static Code Analysis Log
    • Web Application Vulnerability Tracker
    • Application Threat Modeling
    • CSRF (Cross-Site Request Forgery)
    • SQL Injection
    • XSS (Cross-Site Scripting)
    • API Security (OWASP API Top 10 and BOLA)
    • Code Security (SAST, DAST, and Secure Coding)
    • DevSecOps Pipeline
    • DevSecOps
    • Software Supply Chain Security (SBOM and SLSA)
    • Acceptable Use of Assets Policy
    • Password Policy
    • Backup and Recovery Policy
    • Compliance Management
    • Disposal and Destruction Policy
    • Information Classification Policy
    • Information Transfer Policy
    • ISMS Policy
    • COBIT-Based Security Governance
    • ISMS-P
    • ISO 27001
    • Privacy Impact Assessment (PIA)
    • Korea's Data 3 Acts
    • Differential Privacy
    • EU AI Act
    • 5 Pseudonymization Techniques
    • CSAP Tiered Certification
    • Incident Management Policy
    • Incident Management Process
    • Intern Incident Report
    • Major Incident Report Template
    • Structural Damage Incident Report
    • Workplace Violence Report
    • The Core of Endpoint Visibility, EDR
    • The Integrated Control Tower for Threat Detection and Analysis, SIEM
    • Digital Forensics
    • Known Error (KE) Record Template
    • Major Problem Report Template
    • Problem Management Process
    • Problem Record Template
    • DR Approach Document
    • DR Asset Register
    • DR Closure Report
    • DR Communications Plan
    • DR Plan Template
    • MAC vs. DAC vs. RBAC: Access Control Models Compared
    • Access Control
    • Authentication vs. Authorization
    • FIDO (Fast IDentity Online)
    • Identity Provider (IdP)
    • JWT (JSON Web Token)
    • Kerberos
    • OAuth 2.0
    • OAuth 2.0 and OIDC
    • OpenID Connect (OIDC)
    • Passkey
    • SAML (Security Assertion Markup Language)
    • Single Sign-On (SSO)
    • Active Directory (AD)
    • LDAP (Lightweight Directory Access Protocol)
    • Systematic Classification of Attack Techniques
    • Penetration Testing Methodology
    • OSINT (Open Source Intelligence)
    • OSSTMM (Open Source Security Testing Methodology Manual)
    • PTES (Penetration Testing Execution Standard)
    • RAV (Risk Assessment Value)
    • Fuzzing
    • CTF Categories
    • Red Teaming
    • AI System Security
    • Deepfake
    • LLM Security (OWASP Top 10 for LLM)
    • OT/ICS Security and the Purdue Model
    • Blockchain
    • GitHub
  • to navigate
  • to select
  • to close
    • Home
    • Application Security
    On this page
    code

    Application Security

    Templates and trackers for secure coding, patching, static analysis, and web and mobile application testing across the SDLC.

    system_update

    Patch & Update Tracker

    A living record of known application and dependency vulnerabilities, patch status, and remediation deadlines across owned software.

    checklist

    Secure Coding Checklist

    A per-release checklist of secure coding requirements covering input validation, authentication, and safe handling of common vulnerability …

    phone_android

    Secure Mobile App Testing Tracker

    A record of security test coverage, findings, and remediation status for iOS and Android application releases.

    settings_alert

    Security Misconfiguration Log

    A record of hardening gaps found in application, server, and framework configuration, and their remediation status.

    manage_search

    Static Code Analysis Log

    A record of SAST findings across the codebase, their severity, and remediation status, tracked per build or commit.

    bug_report

    Web Application Vulnerability Tracker

    A record of vulnerabilities found through DAST scans and penetration tests against running web applications, and their remediation status.

    psychology

    Application Threat Modeling

    A structured record of an application's threat model — trust boundaries, attacker scenarios, and mitigations — reviewed at design time and …

    swap_horiz

    CSRF (Cross-Site Request Forgery)

    A web attack technique that hijacks a user's authenticated session to make a target site perform actions the user never intended.

    database

    SQL Injection

    A classic web application attack technique that manipulates unvalidated user input to execute unintended SQL statements against a database.

    code

    XSS (Cross-Site Scripting)

    A client-side web vulnerability where an attacker injects a malicious script that executes in the browser of a user who views the page.

    api

    API Security (OWASP API Top 10 and BOLA)

    Technologies and processes that protect the APIs supporting inter-application interaction from unauthorized access, data leakage, and …

    verified_user

    Code Security (SAST, DAST, and Secure Coding)

    The practice of analyzing security weaknesses that can arise during software development and applying safe coding standards to build …

    conveyor_belt

    DevSecOps Pipeline

    A CI/CD pipeline that automates and integrates security activities across the entire software development lifecycle, delivering both speed …

    shield_lock

    DevSecOps

    A culture and methodology that treats security as a shared responsibility by automating and integrating security activities across the …

    link

    Software Supply Chain Security (SBOM and SLSA)

    The set of activities that manage security threats and ensure trustworthiness across the entire process from software production to …


    © 2026 Cybersecurity Knowledge Base. Built with Lotus Docs