Perform a Risk Assessment First

I know you’re itching to open your code file and get down to business, but you have a few things to take care of first. Before spending your valuable time and energy building a Fort Knox for your application, make sure you need to do that.

Yes, I’m telling you to perform a risk assessment.

A risk assessment determines which security measures you should implement and which you don’t have to. From a security perspective, implementing all defenses to the maximum level is always best. In reality, there’s a definite financial trade-off. Multiple methodologies are available on how to conduct a risk assessment, but here’s a brief overview of what the process entails, as shown in the following diagram.

First, ...

Get Secure Your Node.js Web Application now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.