
By Jill R. Aitoro
Excerpt:
"[These] have become the attack vectors of choice for sophisticated hacker crews because they recognize that Web sites can serve as launch points by which to island hop into a government or commercial enterprise network," said Tom Kellermann, vice president of security awareness at Core Security Technologies and former senior data risk management specialist for the World Bank treasury security team.
Agencies should test sensitive Web applications frequently to determine how vulnerable they are, Kellermann said, and then develop aggressive remediation timelines for addressing identified vulnerabilities. They also should test the security of Web applications hosted by third party companies, which often can serve as conduits for hacker attacks.
Source: nextgov











