Prevention of SQL Injection Attacks, v1.0
Specifies requirements in accordance with the DHS CISA Secure-by-Design Pledge, published by the U.S. Dept of Homeland Security (DHS) Cybersecurity and Infrastructure Agency (CISA). Requires an organization to enforce use of parameterized database queries to prevent SQL injection attacks, across all of its product and service offerings.
Assessment Step
1
Prevention of SQL Injection Attacks (PreventionofSQLInjectionAttacks)
Across all of its product and service offerings, does the organization enforce use of parameterized database queries to prevent SQL injection attacks?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Prevention of SQL Injection Attacks
Across all of its product and service offerings, the organization must enforce use of parameterized database queries to prevent SQL injection attacks.
Citation
SBDP
(doc)
|