The most popular and comprehensive Open Source ECM platform
“Security Debt” is the build up of security flaws over time. The first release of an application may contain security flaws that were not addressed. Each subsequent release of the application may add new flaws without correcting the previous ones, the tracking of which, may have been lost or forgotten. Frequently the flaws aren’t in the source code base of the application itself but exist in software libraries used by the application. Because they are indirect, it is less likely that they are closely tracked.
Hackers often target an application’s forgotten flaws.
A study by Veracode found that those organizations the more frequently are scanning their software for flaws are more likely to address and eliminate the problems. Those companies see the value in taking the time to scan, identify, and analyze severity of software problems, and because of their awareness, take the time to fix the issue.
Veracode said that “It’s a near certainty that your applications have security flaws of various types. The likelihood of remediating those flaws in a comprehensive and timely manner is not nearly as certain. The ability to do this consistently — and thereby driving down security debt rather than racking it up — is what separates leading and lagging SDLC programs.”