-
18
pages
-
English
-
Documents
Description
Response From Arizona State University To the Auditor General’s Report on Information Technology Security FINDING 1 1. ASU, UA, and NAU should: a) Develop and implement a plan for conducting regular security assessments of their Web-based applications. RESPONSE: The finding of the Auditor General is agreed to and the audit recommendation will be implemented. STATUS: ASU is actively developing a comprehensive strategy for assessing Web-based applications. In addition to collaborating with NAU and UA to deploy a common assessment tool set, ASU is leveraging industry standard methodologies for assessment around Web development and development in general practices and procedures. b) Enhance or develop and implement University-wide standards or procedures for updating and maintaining their Web servers. RESPONSE: The finding of the Auditor General is agreed to and the audit recommendation will be implemented. STATUS: ASU has created standards and procedures based on its Web-based applications. Implementation of these standards will be done in conjunction with training around secure coding practices. ASU’s approach is to first create standards on the Operating System (OS), all Web browsers, and application servers, to be followed by development and maintenance standards for its Web applications and Java 2 Platform Enterprise Edition (J2EE) Web applications. To update and maintain Web servers, ASU and UTO will create procedures on ...
-
Publié par
-
Langue
English