How do government regulations address application security?

How do government regulations address application security?

How do government regulations such as Health Insurance Portability and Accountability Act (HIPAA) and Gramm-Leach Bliley Act (GLBA) address Web application security?

    Requires Free Membership to View

    When you register, you'll receive targeted emails designed to keep you informed of the most relevant information on Agile development, application security, testing & QA, software requirements, and more.

    Hannah Smalltree, Editorial Director

    By submitting your registration information to SearchSoftwareQuality.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSoftwareQuality.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

Web security is not specifically called out in HIPAA, GLBA, Sarbanes-Oxley or even the Federal Information Security Management Act (FISMA). Only general info security and system requirements are discussed. However, Visa's Payment Card Industry Data Security Standard (PCI) does have sections specifically dedicated to Web security. I predict we will see more focus on Web security in government regulations in the future due to the rapid growth toward a Web-enabled world.

More information:
* Encryption may help regulatory compliance
* Commentary: Why companies still struggle with compliance

This was first published in February 2006