Code Review
The goal of a security code review is to ensure that program source code (which includes all scripts, configuration files, and libraries) is not subject to software vulnerabilities, including cross-site scripting, SQL Injection, cross-site request forgery, buffer overflow, and authorization bypass.
Security code reviews complement penetration testing because they each require the application to be examined from opposite sides, and while many vulnerabilities can be discovered by both methods, a significant number can only be discovered by one or the other. We therefore encourage our clients to consider both penetration testing and security code review for their most critical applications.
For more information about Trusted Advisor Security Group, please call us at +1 (800) 409-9790 or send us an e-mail.