Security is not a single feature. It is a set of habits applied throughout the life of an application. Use this checklist to review your business applications.
Access control
- Role-based access, with users getting only the permissions they need
- Multi-factor authentication for admin and privileged accounts
- Accounts removed promptly when people leave
- Regular review of user and admin lists
Secure development
- Input validation and protection against common vulnerabilities (injection, XSS, CSRF)
- Secrets kept out of source code
- Code reviews for changes to sensitive areas
- Dependencies checked for known vulnerabilities
Data protection
- HTTPS everywhere
- Sensitive data encrypted where appropriate
- Personal data collected only when needed and handled according to applicable regulations
- Clear data retention and deletion practices
Infrastructure
- Servers and services patched on a schedule
- Firewalls allow only required traffic
- Databases not directly exposed to the internet
- Separate production and test environments
Backups and recovery
- Automated backups stored separately from production
- Restores tested regularly
- Documented recovery steps
Monitoring and logging
- Logs for logins, admin actions and errors
- Alerts for unusual activity
- Logs retained for an agreed period
Incident response
- A named contact and escalation path for security incidents
- Steps to contain, investigate and recover
- Communication plan for affected users where required
Reviewing this checklist regularly, and after major changes, keeps security part of normal operations rather than an afterthought.