Security is not a single feature. It is a set of habits applied throughout the life of an application. Use this checklist to review your business applications.

Access control

  • Role-based access, with users getting only the permissions they need
  • Multi-factor authentication for admin and privileged accounts
  • Accounts removed promptly when people leave
  • Regular review of user and admin lists

Secure development

  • Input validation and protection against common vulnerabilities (injection, XSS, CSRF)
  • Secrets kept out of source code
  • Code reviews for changes to sensitive areas
  • Dependencies checked for known vulnerabilities

Data protection

  • HTTPS everywhere
  • Sensitive data encrypted where appropriate
  • Personal data collected only when needed and handled according to applicable regulations
  • Clear data retention and deletion practices

Infrastructure

  • Servers and services patched on a schedule
  • Firewalls allow only required traffic
  • Databases not directly exposed to the internet
  • Separate production and test environments

Backups and recovery

  • Automated backups stored separately from production
  • Restores tested regularly
  • Documented recovery steps

Monitoring and logging

  • Logs for logins, admin actions and errors
  • Alerts for unusual activity
  • Logs retained for an agreed period

Incident response

  • A named contact and escalation path for security incidents
  • Steps to contain, investigate and recover
  • Communication plan for affected users where required

Reviewing this checklist regularly, and after major changes, keeps security part of normal operations rather than an afterthought.