• DMCA
  • Disclaimer
  • Terms and Conditions
  • Cookie Privacy Policy
  • Privacy Policy
  • Contact
  • Advertise
Real Hacker
  • Home
  • Review
    Meta introduces Instagram Reels APIs for developers – TechCrunch

    Meta introduces Instagram Reels APIs for developers – TechCrunch

    Basic home office hacks: 8 things you need to elevate your workspace

    Basic home office hacks: 8 things you need to elevate your workspace

    Fintech investors appear to be favoring later-stage deals as sector takes a hit, recent data shows – TechCrunch

    Fintech investors appear to be favoring later-stage deals as sector takes a hit, recent data shows – TechCrunch

    Spurred by Roe overturn, senators seek FTC probe of iOS and Android tracking

    Spurred by Roe overturn, senators seek FTC probe of iOS and Android tracking

    OSOM’s OV1 is now Solana’s web3 Android handset, Saga – TechCrunch

    OSOM’s OV1 is now Solana’s web3 Android handset, Saga – TechCrunch

    NFT summer in New York is in full swing amid crypto winter – TechCrunch

    NFT summer in New York is in full swing amid crypto winter – TechCrunch

  • Gaming
    How To Get Every Free Reward From Apex Legends Mobile’s Latest Login Event

    How To Get Every Free Reward From Apex Legends Mobile’s Latest Login Event

    Hideo Kojima set aside superhero project for being too close to Amazon’s The Boys

    Hideo Kojima set aside superhero project for being too close to Amazon’s The Boys

    Freshly Frosted Has Me Dreaming Colorful Donut Dreams

    Freshly Frosted Has Me Dreaming Colorful Donut Dreams

    Video Games Double Down On NFTs Despite Historic Crashes

    Video Games Double Down On NFTs Despite Historic Crashes

    Microsoft Flight Simulator update could lead to a virtual Space Shuttle

    Microsoft Flight Simulator update could lead to a virtual Space Shuttle

    Into The Breach Advanced Edition Introduces New Mechs And A Mobile Port Through Netflix

    Into The Breach Advanced Edition Introduces New Mechs And A Mobile Port Through Netflix

  • Gear
    • All
    • Audio
    • Camera
    • Laptop
    • Smartphone
    Nvidia GTX 1630 leaks, an entry level Turing card

    Nvidia GTX 1630 leaks, an entry level Turing card

    Check out the Akai Switch – a Nintendo Switch and Akai MPC concept

    Check out the Akai Switch – a Nintendo Switch and Akai MPC concept

    The Google Pixel 6a boasts faster fingerprint sensor than the 6 Pro in this video

    The Google Pixel 6a boasts faster fingerprint sensor than the 6 Pro in this video

    What to expect from Apple in the second half of 2022?

    What to expect from Apple in the second half of 2022?

    Intellytech Pocket-V Dual Charger – Newsshooter

    Intellytech Pocket-V Dual Charger – Newsshooter

    The Gamesir X3 adds a cooling fan to your phone, but does it work?

    The Gamesir X3 adds a cooling fan to your phone, but does it work?

    Trending Tags

    • Best iPhone 7 deals
    • Apple Watch 2
    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • iOS 10
    • iPhone 7
    • Sillicon Valley
  • Computers
    GEEKOM Mini IT8 Mini PC, A Price Almost As Small As The System

    GEEKOM Mini IT8 Mini PC, A Price Almost As Small As The System

    As HPC Chip Sizes Grow, So Does the Need For 1kW+ Chip Cooling

    As HPC Chip Sizes Grow, So Does the Need For 1kW+ Chip Cooling

    Cooler Master V850 SFX Gold, In White

    Cooler Master V850 SFX Gold, In White

    Banished To Work In The Metaverse For A Week

    Banished To Work In The Metaverse For A Week

    The Gigabyte UD1000GM PG5 1000W PSU Review: Prelude to ATX 3.0

    The Gigabyte UD1000GM PG5 1000W PSU Review: Prelude to ATX 3.0

    AMD Updates Ryzen Embedded Series, R2000 Series With up to Four Cores and Eight Threads

    AMD Updates Ryzen Embedded Series, R2000 Series With up to Four Cores and Eight Threads

  • Applications
    Cybersecurity Experts Warn of Emerging Threat of “Black Basta” Ransomware

    Cybersecurity Experts Warn of Emerging Threat of “Black Basta” Ransomware

    iMore Show 800: What’s the deal with the new M2 MacBook Pro?

    iMore Show 800: What’s the deal with the new M2 MacBook Pro?

    Air Twister Flies Onto Apple Arcade

    Air Twister Flies Onto Apple Arcade

    Popular Apple Music service tier gets sudden price hike in the US, UK, and Canada

    Popular Apple Music service tier gets sudden price hike in the US, UK, and Canada

    Hackers Exploit Mitel VoIP Zero-Day in Likely Ransomware Attack

    Hackers Exploit Mitel VoIP Zero-Day in Likely Ransomware Attack

    Zoom’s new subscription makes it an even better team collaboration service

    Zoom’s new subscription makes it an even better team collaboration service

  • Security
    Stories from the SOC – Detecting internal reconnaissance

    Stories from the SOC – Detecting internal reconnaissance

    Threat Intelligence Services Are Universally Valued by IT Staff

    Threat Intelligence Services Are Universally Valued by IT Staff

    #InfosecurityEurope2022: Preparing for Future Challenges and Opportunities

    #InfosecurityEurope2022: Preparing for Future Challenges and Opportunities

    Mitek launches MiVIP platform to fight identity theft

    Mitek launches MiVIP platform to fight identity theft

    #InfosecurityEurope2022: The Interactivity Between Nation-State Attackers and Organized Crime Gangs

    #InfosecurityEurope2022: The Interactivity Between Nation-State Attackers and Organized Crime Gangs

    Does an iPhone Need Antivirus Software?

    Does an iPhone Need Antivirus Software?

No Result
View All Result
  • Home
  • Review
    Meta introduces Instagram Reels APIs for developers – TechCrunch

    Meta introduces Instagram Reels APIs for developers – TechCrunch

    Basic home office hacks: 8 things you need to elevate your workspace

    Basic home office hacks: 8 things you need to elevate your workspace

    Fintech investors appear to be favoring later-stage deals as sector takes a hit, recent data shows – TechCrunch

    Fintech investors appear to be favoring later-stage deals as sector takes a hit, recent data shows – TechCrunch

    Spurred by Roe overturn, senators seek FTC probe of iOS and Android tracking

    Spurred by Roe overturn, senators seek FTC probe of iOS and Android tracking

    OSOM’s OV1 is now Solana’s web3 Android handset, Saga – TechCrunch

    OSOM’s OV1 is now Solana’s web3 Android handset, Saga – TechCrunch

    NFT summer in New York is in full swing amid crypto winter – TechCrunch

    NFT summer in New York is in full swing amid crypto winter – TechCrunch

  • Gaming
    How To Get Every Free Reward From Apex Legends Mobile’s Latest Login Event

    How To Get Every Free Reward From Apex Legends Mobile’s Latest Login Event

    Hideo Kojima set aside superhero project for being too close to Amazon’s The Boys

    Hideo Kojima set aside superhero project for being too close to Amazon’s The Boys

    Freshly Frosted Has Me Dreaming Colorful Donut Dreams

    Freshly Frosted Has Me Dreaming Colorful Donut Dreams

    Video Games Double Down On NFTs Despite Historic Crashes

    Video Games Double Down On NFTs Despite Historic Crashes

    Microsoft Flight Simulator update could lead to a virtual Space Shuttle

    Microsoft Flight Simulator update could lead to a virtual Space Shuttle

    Into The Breach Advanced Edition Introduces New Mechs And A Mobile Port Through Netflix

    Into The Breach Advanced Edition Introduces New Mechs And A Mobile Port Through Netflix

  • Gear
    • All
    • Audio
    • Camera
    • Laptop
    • Smartphone
    Nvidia GTX 1630 leaks, an entry level Turing card

    Nvidia GTX 1630 leaks, an entry level Turing card

    Check out the Akai Switch – a Nintendo Switch and Akai MPC concept

    Check out the Akai Switch – a Nintendo Switch and Akai MPC concept

    The Google Pixel 6a boasts faster fingerprint sensor than the 6 Pro in this video

    The Google Pixel 6a boasts faster fingerprint sensor than the 6 Pro in this video

    What to expect from Apple in the second half of 2022?

    What to expect from Apple in the second half of 2022?

    Intellytech Pocket-V Dual Charger – Newsshooter

    Intellytech Pocket-V Dual Charger – Newsshooter

    The Gamesir X3 adds a cooling fan to your phone, but does it work?

    The Gamesir X3 adds a cooling fan to your phone, but does it work?

    Trending Tags

    • Best iPhone 7 deals
    • Apple Watch 2
    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • iOS 10
    • iPhone 7
    • Sillicon Valley
  • Computers
    GEEKOM Mini IT8 Mini PC, A Price Almost As Small As The System

    GEEKOM Mini IT8 Mini PC, A Price Almost As Small As The System

    As HPC Chip Sizes Grow, So Does the Need For 1kW+ Chip Cooling

    As HPC Chip Sizes Grow, So Does the Need For 1kW+ Chip Cooling

    Cooler Master V850 SFX Gold, In White

    Cooler Master V850 SFX Gold, In White

    Banished To Work In The Metaverse For A Week

    Banished To Work In The Metaverse For A Week

    The Gigabyte UD1000GM PG5 1000W PSU Review: Prelude to ATX 3.0

    The Gigabyte UD1000GM PG5 1000W PSU Review: Prelude to ATX 3.0

    AMD Updates Ryzen Embedded Series, R2000 Series With up to Four Cores and Eight Threads

    AMD Updates Ryzen Embedded Series, R2000 Series With up to Four Cores and Eight Threads

  • Applications
    Cybersecurity Experts Warn of Emerging Threat of “Black Basta” Ransomware

    Cybersecurity Experts Warn of Emerging Threat of “Black Basta” Ransomware

    iMore Show 800: What’s the deal with the new M2 MacBook Pro?

    iMore Show 800: What’s the deal with the new M2 MacBook Pro?

    Air Twister Flies Onto Apple Arcade

    Air Twister Flies Onto Apple Arcade

    Popular Apple Music service tier gets sudden price hike in the US, UK, and Canada

    Popular Apple Music service tier gets sudden price hike in the US, UK, and Canada

    Hackers Exploit Mitel VoIP Zero-Day in Likely Ransomware Attack

    Hackers Exploit Mitel VoIP Zero-Day in Likely Ransomware Attack

    Zoom’s new subscription makes it an even better team collaboration service

    Zoom’s new subscription makes it an even better team collaboration service

  • Security
    Stories from the SOC – Detecting internal reconnaissance

    Stories from the SOC – Detecting internal reconnaissance

    Threat Intelligence Services Are Universally Valued by IT Staff

    Threat Intelligence Services Are Universally Valued by IT Staff

    #InfosecurityEurope2022: Preparing for Future Challenges and Opportunities

    #InfosecurityEurope2022: Preparing for Future Challenges and Opportunities

    Mitek launches MiVIP platform to fight identity theft

    Mitek launches MiVIP platform to fight identity theft

    #InfosecurityEurope2022: The Interactivity Between Nation-State Attackers and Organized Crime Gangs

    #InfosecurityEurope2022: The Interactivity Between Nation-State Attackers and Organized Crime Gangs

    Does an iPhone Need Antivirus Software?

    Does an iPhone Need Antivirus Software?

No Result
View All Result
Real Hacker
No Result
View All Result

Home Security

4 security concerns for low-code and no-code development

RealHacker Staff by RealHacker Staff
February 28, 2022
4 security concerns for low-code and no-code development
Share on FacebookShare on Twitter


There’s an elevated push for what’s being dubbed the citizen developer, coupled with the need to empower software growth and creation by non-developers. That is sometimes facilitated utilizing low-code or no-code frameworks. These frameworks and instruments permit non-developers to make use of a GUI to seize and transfer elements to make enterprise logic pleasant purposes.

Empowering the broader IT and enterprise group to create purposes to drive enterprise worth has an apparent attraction. That stated using low code and no code platforms aren’t with out their very own safety considerations. Very like another software program product, the rigor that goes into creating the platform and its related code is a priority that shouldn’t be neglected.

What’s low-code/ no-code growth?

No-code instruments and platforms use a drag-and-drop interface to permit non-programmers similar to enterprise analysts to create or modify purposes. In some instances, precise coding (low code) could be wanted for integration with different purposes, report era, or modifying the person interface. That is sometimes performed utilizing a high-level programming language like SQL or Python.

Examples of low-code/no-code platforms embody Salesforce Lightning, FileMaker, Microsoft PowerApps and Google App Maker. These are the 4 most necessary safety considerations for utilizing such platforms.

1. Low visibility into low-code/no-code purposes

Utilizing a platform that was developed by an exterior get together at all times comes with visibility considerations. You’re consuming the software program and due to this fact don’t know in regards to the supply code, related vulnerabilities or probably the extent of testing and rigor the platform has undergone.

This could possibly be mitigated by leveraging practices similar to requesting a software program invoice of supplies (SBOM) from the seller. This would offer perception into the software program elements it accommodates and their related vulnerabilities. The usage of SBOMs are on the rise, with the most recent Linux Basis research indicating that 78% of organizations plan to make use of SBOMs in 2022. That stated, using SBOMs remains to be maturing and there’s a lot of room to go for the trade to normalize on practices, processes and tooling.

2. Insecure code

Dovetailing from the visibility considerations is the opportunity of insecure code. Low-code and no-code platforms nonetheless have code; they’ve simply abstracted the coding and allowed the top person as an alternative to make use of pre-provided code performance. That is nice because it saves the non-developer from needing to creator the code themselves. The place it will get problematic is when the code that’s used is insecure and is extrapolated throughout organizations and purposes by the low-code and no-code platforms.

One strategy to tackle that is to work with the platform vendor to ask for safety scanning outcomes for the code that’s used inside the platform. Scan outcomes similar to these from static and dynamic software safety testing (SAST/DAST) may give shoppers a stage of assurance that they aren’t simply replicating insecure code. The concept of code created outdoors a company’s management isn’t a brand new idea and is prevalent within the rampant use of open-source software program, which is utilized by upwards of 98% of organizations and with software program provide chain threats related to different repositories as properly, similar to these for infrastructure-as-code (IaC) templates.

One other side to contemplate is that many low-code and no-code platforms are delivered as software program as a service (SaaS). This places you ready to request trade certifications similar to ISO, SOC2, FedRAMP and others from the seller. This gives additional assurance relating to the group’s operational and the safety controls relevant to the SaaS software/platform itself.

SaaS purposes current many safety dangers themselves and warrant correct governance and safety rigor. With out correctly vetting the SaaS purposes and platforms your group is utilizing, you might be exposing the group to undue danger. That is additional exacerbated if the low-code and no-code platforms are used to develop purposes that can expose delicate organizational or buyer information.

3. Out-of-control shadow IT

Since low-code and no-code platforms permit purposes to be rapidly created, even by these with out growth backgrounds, it can also result in rampant shadow IT. Shadow IT happens when enterprise models and employees create purposes and expose them each internally inside the group or externally to the world. These purposes may home delicate organizational, buyer or regulated information, which may have a slew of implications for the group if these purposes have been compromised in a knowledge breach.

4. Enterprise disruption 

From a enterprise continuity perspective, reliance on low-code and no-code platforms delivered as a service may disrupt enterprise if that platform experiences an outage. It is necessary for organizations to determine service stage agreements (SLAs) for business-critical purposes, together with low-code and no-code platforms.

Tricks to mitigate danger from low-code/no-code growth

Frequent safety finest practices can mitigate the dangers described above whatever the expertise concerned, together with:

  • Purchase software program and platforms from trusted distributors with revered trade reputations.
  • Guarantee these distributors have third-party attested certifications to signify their inside safety practices and processes.
  • Account for low-code and no-code platforms in your software and software program inventories, in addition to the purposes created by their use.
  • Keep good entry management; know who’s accessing the platforms and what actions they’re allowed to carry out.
  • Implement safe information practices to grasp the place your crucial information resides and if purposes created utilizing low-code and no-code platforms home delicate information.
  • Know the place low-code/no-code platforms are hosted. Are the platforms hosted in a hyperscale international Cloud Service Supplier (CSP) similar to AWS, Google or Microsoft Azure? Or are they hosted in a legacy on-premises information heart with restricted to no bodily and logical entry management?

It’s additionally necessary think about your group’s safety tradition. Whereas the platform customers is probably not builders or safety professionals by commerce, they need to perceive the safety implications of the low-code and no-code platforms and purposes they’re utilizing and creating. With nice energy comes nice accountability as they stated, and that is relevant right here with low-code and no-code platforms.

Copyright © 2022 IDG Communications, Inc.



Source link

Related

Tags: concernsdevelopmentlowcodenocodesecurity
RealHacker Staff

RealHacker Staff

Recommended.

Four Russians Charged with Dragonfly Attacks on Critical Infrastructure

Four Russians Charged with Dragonfly Attacks on Critical Infrastructure

March 25, 2022
How to cite a YouTube video in APA or MLA

How to cite a YouTube video in APA or MLA

May 6, 2022

Trending.

Hypex Presents New Nilai500 DIY Audio Amplifier Module

Hypex Presents New Nilai500 DIY Audio Amplifier Module

May 16, 2022
ADPTR Audio Sculpt review: A must-have dynamics plug-in for mastering and mixing engineers

ADPTR Audio Sculpt review: A must-have dynamics plug-in for mastering and mixing engineers

March 15, 2022
12 best rotary mixers for DJs

12 best rotary mixers for DJs

March 16, 2022
NAMM 2022: Audeze partners Manny Marroquin on the Manny MM-500 headphones

NAMM 2022: Audeze partners Manny Marroquin on the Manny MM-500 headphones

June 3, 2022
Behringer synthesizers 2022: Every hardware instrument Behringer is working on

Behringer synthesizers 2022: Every hardware instrument Behringer is working on

April 12, 2022

Follow Us

Categories

  • Applications
  • Audio
  • Camera
  • Computers
  • Gaming
  • Gear
  • Laptop
  • Metaverse
  • Microsoft
  • Photography
  • Review
  • Security
  • Smartphone
  • Uncategorized

Recent News

Meta introduces Instagram Reels APIs for developers – TechCrunch

Meta introduces Instagram Reels APIs for developers – TechCrunch

June 27, 2022
How To Get Every Free Reward From Apex Legends Mobile’s Latest Login Event

How To Get Every Free Reward From Apex Legends Mobile’s Latest Login Event

June 27, 2022
  • DMCA
  • Disclaimer
  • Terms and Conditions
  • Cookie Privacy Policy
  • Privacy Policy
  • Contact
  • Advertise

© 2019 - theme develop by real hacker news.

No Result
View All Result
  • Home
  • Review
  • Applications
  • Computers
  • Gaming
  • Gear
    • Audio
    • Camera
    • Smartphone
  • Microsoft
  • Photography
  • Security

© 2019 - theme develop by real hacker news.

error: Content is protected !!