1.
Introduction
[Link] is an all you can finance app from checking net income to monthly bills. This app
is a dream of many as it will allow you to check your monthly expenses through debit or
credit card balances but also pay bills through a click on the app. The [Link] app will
include the following features:
-Two factor authentication
-User account transactions
-Secure money transfer to pay bills
-Ability to sync account balances within the application
The main objective of this app is to process and store sensitive of customers. The app will
respectfully follow the principles of Confidentiality, Integrity and Availability
principles. The main purpose for this document is for threat modelling and to highlight and
identify the value of the company assets, complete architecture
exploration , understand the boundaries of trust as identifying the threats and
vulnerabilities. This document will enable the understanding of security with the app.
Introduction and PCI Data Security Standard Overview
The Payment Card Industry Data Security Standard (PCI DSS) was developed to encourage
and enhance payment card account data security
and facilitate the broad adoption of consistent data security measures globally. PCI DSS
provides a baseline of technical and operational
requirements designed to protect account data. While specifically designed to focus on
environments with payment card account data, PCI DSS can also be used to protect against
threats and secure other elements in the payment ecosystem.
Build and Maintain a Secure Network and 1. Install and Maintain Network Security
Systems Controls.
2. Apply Secure Configurations to All
System Components.
Protect Account Data 3. Protect Stored Account Data.
4. Protect Cardholder Data with Strong
Cryptography During
Transmission Over Open, Public Networks.
Maintain a Vulnerability Management 5. Protect All Systems and Networks from
Program Malicious Software.
6. Develop and Maintain Secure Systems
and Software.
Implement Strong Access Control Measures 7. Restrict Access to System Components
and Cardholder Data by
Business Need to Know.
8. Identify Users and Authenticate Access to
System Components.
9. Restrict Physical Access to Cardholder
Data.
Regularly Monitor and Test Networks 10. Log and Monitor All Access to System
Components and Cardholder
Data.
11. Test Security of Systems and Networks
Regularly.
Maintain an Information Security Policy 12. Support Information Security with
Organizational Policies and
Programs
GDPR – General Data Protection Regulation
My [Link] is based the Ireland which means the company must adhere and follow
strictly the 7 key principles concepts of the GDPR and European Data Protection Law. Firstly
introduced in 2018 and can be found in the 2018 Act. Companies must comply with the
principles of data protection and it is crucial as penalties can occur.
Lawfulness, Fairness, and Transparency The collected data should be processed in a
lawful, fair and transparent to the subject
of the data
Purpose Limitation The date should be specified, explicit and
legitimate purposes when acquired for the
reasons collected
Data Minimisation Only have the minimum date required
Accuracy The date user must have personal data
accurate and up-to-date
Storage Limitation User who controls the data must attain
data for no longer than exact purposes
Integrity and Confidentiality The data processed by users should ensure
appropriate amount of security and
confidentiality
Accountability The person controlling the data must be in
compliance with the other all of the
principles of data protection
The OWASP Top 10 for 2021
The OWASP Top 10 is a document for awareness with standards for security in applications
such as this app. It highlights a great amount of information with the most severe risk to the
applications.
1 Broken Access Control
2 Cryptographic Failures
3 Injection
4 Insecure Design
5 Security Misconfiguration
6 Vulnerable and Outdated Components
7 Identification and Authentication Failures
8 Software and Data Integrity Failures
9 Security Logging and Monitoring Failures
1 Server-Side Request Forgery
0
Architecture Overview
This will highlight the aspects of a sketch detailing the sub-system of user roles in the system
along with the technologies which will be handled in the system.
Actors Role Permissions
Registered User When the user registration Full app access , server login
is successful and completely admin privileges
logged in with complete full
access to the app
Main Server The main server would
handle the
Database Admin
Web Server Admin
Actors
The application will have alternative actors in the network with different permissions as well
as access levels to the servers and database.