36 Miss. Code. R. 1-16.1

Current through August 31, 2024
Rule 36-1-16.1

Each agency must perform security assessments on all new applications to ensure key application security and privacy requirements are met. Code in the application and supporting infrastructure must be tested for common errors that can compromise the integrity of the production environment when the application is deployed.

A. Agencies should use one or more of the following application security assessment methods:
1. Contract with a third-party for assessment services
2. Perform Internal application security assessments
3. Utilize application security assessment software
B. At minimum, the following vulnerabilities must be assessed.
1. Un-validated input
2. Broken access control
3. Broken authentication and session management
4. Injection flaws
5. Improper error handling
6. Insecure configuration management
7. Insecure storage
8. Cross-Site scripting (XSS)
9. Insecure direct object references
10. Cross-Site request forgery (CSRF)
11. Insufficient transport layer protection
12. Unvalidated redirects and forwards

36 Miss. Code. R. 1-16.1

Miss. Code Ann. § 25-53-1 to § 25-53-25