Financial Services Information Security News, Advice and Research - SearchFinancialSecurity.com

SaaS and Web application security

  • Mobile banking risks and mitigation measures

    Mobile banking is taking off, but can financial firms keep up with the risks? Learn about steps Wells Fargo and Bank of America are taking to ensure mobile banking security. 

  • Evaluating tools for online bank security

    Criminals are hijacking online bank accounts with sophisticated bank Trojans but a variety of technologies promise online bank security. In this tip, Dave Shackleford examines the pros and cons of tools designed to thwart online banking fraud. 

  • Financials and the need for software regression testing

    Attackers target financial-services websites, making it critical that financial firms include regression testing and version control in their software development practices. 

  • Why financials must implement Web application security best practices

    The financial services sector is a favorite target for attackers, making it critical that the industry dedicate more resources to securing Web applications. In this tip, Russ McRee describes his research into vulnerable financial Web applications and... 

  • The PCI compliance case for source code review

    Web application firewalls won't protect against application logic flaws. Michael Cobb explains why source code review can. 

  • Security questions to ask SaaS vendors when outsourcing services

    As financial-services firms turn to Software as a Service (SaaS) offerings to save money and increase efficiency, they need to make sure their SaaS providers implement strong data security. Someone providing SaaS is also supposed to be providing you ... 

  • The security risks of Google Notebook

    Security practitioners know to keep sensitive information under lock and key, but, as Web services proliferate, ensuring information remains private is more difficult than ever. In this tip, Ed Skoudis examines how one of Google's latest Web applicat... 

  • Developing a patch management policy for third-party applications

    Enterprises may push the latest critical Windows patches once a month, but here's a dirty little secret: Most organizations don't bother patching their third-party applications. The diversity of client-side software -- including everything from Acrob... 

About SaaS and Web application security

Software as a Service (SaaS) applications can create serious enterprise data integration challenges, especially when it comes to security. Learn about the security implications of SaaS, Web applications from Google and Microsoft, hosted software and application service providers (ASPs).