50% 60% 70% 80% 90% Iden0fica0on and Authen0ca0on Input Valida0on and Encoding Session Management Sensi0ve Data Protec0on Access Control/ Authoriza0on Error Handling Logging and Intrusion Detec0on Cross Site Request Forgery (CSRF) PlaXorm Security Database Security Code Quality System Availability -‐ DOS Protec0on Accessing External Services ApplicaAons with at Least One Vulnerability in Category Higher Risk Lower Risk Aspect 2013 Global AppSec Risk Report