
Key Benefits of Low-Code Platforms
Low-code vendors are frequently responsible for managing the upper levels of the overall stack; this is referred to as the shared security paradigm
By
CIO Applications Europe | Tuesday, August 24, 2021

Low-code vendors are frequently responsible for managing the upper levels of the overall stack; this is referred to as the shared security paradigm.
Fremont, CA: Today, over 300 vendors or platforms provide various kinds of low-code solutions. However, most of these low-code tools are actually no-code tools that assist individuals or groups in attempting to solve a given problem. The list of advantages of implementing low-code tools in an environment is lengthy and persuasive; yet, there are security dangers that enterprises should be aware of while utilizing these powerful tools.
When assessing or employing a low-code tool, keep in mind that while low-code tools abstract the process of producing code, code is still written. Low-code applications are vulnerable to the same kind of assaults as any other online application. However, because organizations have no control over the code created by a low-code tool, the task of designing safe applications is primarily pushed to the seller of the low-code tool. As a result, the best method to reduce risk when working with a low-code vendor is to thoroughly analyze that vendor's security policies and rigorously test applications generated using these technologies as you would any application developed with a traditional/pro-code strategy.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Managing Vendor Infrastructure: Low-code vendors are frequently responsible for managing the upper levels of the overall stack; this is referred to as the shared security paradigm. Examine the vendor to ensure that they have sound controls and processes in place to maintain and safeguard the infrastructure. Ideally, the vendor will submit to a recognized audit regularly, such as a SOC 2 Type 2 or ISO-27001. This helps ensure that controls and processes in areas such as security, availability, privacy, confidentiality, and processing integrity are in place to manage the aforementioned risks on the hosting platform for which the vendor is responsible.
Formal SDLC: For the creation of their low-code tool, the vendor should adhere to a documented software development life cycle (SDLC) and change management methodology. A good SDLC process includes using a source code management system, dependency checking, static code analysis, automated unit, regression tests, secure coding practices training, application vulnerability scanning, quality assurance testing, and third-party penetration testing.
Policies and Processes: The vendor should have documented policies and practices in place addressing information security, business continuity, disaster recovery, security incident handling, infrastructure hardening, and other topics. This helps to demonstrate the vendor's dedication to providing a secure, highly available, and high-quality offering.
More in News
Weekly Brief
I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info
Be first to read the latest tech news, Industry Leader's Insights, and CIO interviews of medium and large enterprises exclusively from CIO Applications Europe
THANK YOU FOR SUBSCRIBING


