Skip to content

Instantly share code, notes, and snippets.

View bear's full-sized avatar

Mike Taylor bear

View GitHub Profile
@bear
bear / WSC.md
Last active July 29, 2017 21:42 — forked from prologic/WSC.md
Web Security Checklist (draft)

Web Security Checklist (draft)

Instructions

Please fork this gist and use as your own checklist as you develop/deploy your web application or api.

WARNING: This checklist makes an assumption of the level of expertise and experience of the reader and assumes significant in-depth knowledge and experience in web development.

App

In a perfect world, where things are done well, not just quickly, I would expect to find the following when joining the company:

Documentation

  • Accurate / up-to-date systems architecture diagram

  • Accurate / up-to-date network diagram

  • Out-of-hours support plan

  • Incident management plan