Security Standards for Test Data
Kelly Jackson Higgins of DarkReading.com reports on a successful hack of an RBS WorldPay Systems database. The database is reported as being a test database that does not include any live data. This has created speculation as to the proper security standards for such systems.
Should organizations use test applications that are susceptible to things like SQL injection and that are accessible via the Internet? Given the specialized nature of application security, does your organization have a great program in place to prevent bad code from exposing the rest of the information assets?
Share your experience and insights.
Subscribe to comments via RSS 2.0

