Hi InfoSec community,
Can anybody suggest how to approach Annual Security Architecture/design review (only Design/Architecture not implementation or VAPT ) of a web application which is not having any proper documentation for Security activities.
When I think about it... it's requires Threat Modeling and Risk Assessment... but it's overwhelming and I would like to get some pointers where to start , what needs to be covered..etc..
Thank you.
You can start with the principle aligned with your organization's objectives. Principles like Single Identity, Security Monitoring, Data Security and etc. You can then assess if the architecture/ design complies with those principles. This will be a continuous process and will get refined over a period of time but you need to start from somewhere and take the feedback for relevant stakeholders and improve.
Thanks!!
Rahul Sharma