1. General Requirements:
- Web Application Firewall (WAF) must be used to protect external web applications from external attacks.
- External web applications must follow a multi-tier architecture, with a minimum of two tiers (2-tier architecture).
- External web applications for critical systems must follow a multi-tier architecture with a minimum of three tiers (3-tier architecture).
- Only secure communication protocols must be used, such as Hypertext Transfer Protocol Secure (HTTPS), Secure File Transfer Protocol (SFTP), Transport Layer Security (TLS), and other secure protocols.
- Logical segregation must be implemented between the Development Environment, Testing Environment, and Production Environment.
- Data and information protection technologies must be implemented in external web applications in accordance with King Saud University’s approved Data and Information Protection Policy and Data Classification Policy.
- When web applications are procured from a third party, the supplier’s compliance with King Saud University’s approved cybersecurity policies and standards must be ensured.
- At a minimum, the OWASP Top Ten Web Application Security Risks must be applied to external web applications supporting critical systems.
- At a minimum, the OWASP Top Ten API Security Risks must be applied to external web applications supporting critical systems.
- Cybersecurity requirements must be identified during the development, design, and secure implementation of web applications to ensure that they are developed and implemented securely and effectively.
- Event and audit logs for web applications at King Saud University must be retained and monitored.
- The integrity of web application data must be protected against tampering, accidental loss, or destruction, and its availability and recoverability must be ensured through backup and archival mechanisms.
- Cybersecurity requirements must be defined for web applications hosted in cloud environments to ensure that they are securely configured, deployed, and operated.
- The availability of external web applications must be maintained, and they must be protected against Distributed Denial-of-Service (DDoS) attacks at both the application and network levels.
- Specific procedures and standards for web application protection must be developed based on business requirements.
- Key Performance Indicators (KPIs) must be used to ensure the continuous improvement and the proper and effective implementation of web application protection requirements.
2. Access Rights Requirements:
- Multi-Factor Authentication (MFA) must be used for user authentication when accessing external web applications and for system administrators accessing internal web applications.
- Security standards for web application development must be documented and approved, including, at a minimum, Secure Session Management, covering session authenticity, lockout, and timeout.
- Access privileges to production environments must be restricted and controlled in accordance with job responsibilities.
- A secure usage policy must be communicated to all users of external web applications.
- Secure hashing functions must be used to store user authentication data, such as passwords, for external web applications.
3. Secure Configuration Review Requirements:
- A cybersecurity risk assessment must be conducted when planning to develop or procure web applications and before deploying them to the production environment, in accordance with King Saud University’s approved Cybersecurity Risk Management Policy.
- Security configurations and hardening requirements must be defined and reviewed to ensure that web applications are securely and effectively configured and operated, and such configurations must be documented.
- The confidentiality and integrity of web application data must be ensured in accordance with King Saud University’s approved Data and Information Protection Policy.
- Before using classified information in the testing environment, prior authorization must be obtained from the Cybersecurity Directorate at King Saud University, and stringent controls must be applied to protect such data, such as Data Scrambling and Data Masking techniques. The data must be deleted immediately after its use is completed.
- Source code must be securely stored, and access to or modification of the source code must be restricted to authorized personnel only.
- Penetration testing must be conducted on external web applications in the testing environment, and the results must be documented. All identified vulnerabilities must be remediated before deploying the application to the production environment, in accordance with King Saud University’s approved Penetration Testing Policy.
- Vulnerability assessments must be conducted for the technical components of web applications, and identified vulnerabilities must be remediated by installing updates and patches approved by King Saud University on an annual basis.
- Web application security testing must be conducted in the following cases:
- During the planning phase and before deploying web applications.
- Before implementing any planned or emergency change or update.