In Brief

SC&A: How MassMutual Builds Secure Applications

MassMutual's SC&A (security certification and accreditation) process:

By Lauren Gibbons Paul

February 01, 2005CSO — 1. An IT person sends a request for an IT building permit to the information security department. An infosec "consultant" goes through a short triage, and either sends the project for more evaluation or gives it a green light if the security risk is minimal.

2. The assigned consultant helps the project manager with a more detailed security questionnaire. The answers help the security consultant categorize the project as high-, medium- or low-risk.

3. The consultant continues to meet with the IT project team during development or vendor selection, checking the work against documented in-house security policies.

4. After basic system testing, the project applies for a certificate of occupancy, then heads into the quality assurance phase of testing.

5. After Q/A, the CISO signs the certificate of occupancy, and the application or system is placed in the production environment.

Other stories by Lauren Gibbons Paul

SC&A

RESOURCE CENTER
Loading...
VIRTUAL CONFERENCE
Security Directions: A Virtual Conference

Security Directions Available On Demand Sept. 30 - Dec. 30

Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.

» Register Now

WEBCAST
Protecting PII: How to Work with IT to Manage Risk

Compuware Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.

» View this Webcast

Featured Sponsors