{"id":1226,"date":"2026-09-13T20:27:23","date_gmt":"2026-09-13T20:27:23","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1226"},"modified":"2026-09-13T20:27:23","modified_gmt":"2026-09-13T20:27:23","slug":"application-security","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/application-security\/","title":{"rendered":"Application Security"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: APPLICATION SECURITY\n     Live osto.one glossary stylesheet. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">Application security has two halves that operate at different times. Most teams buy one of them and believe the problem is covered.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Application<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>Application security is the set of practices that keep software safe from the moment it is written to the moment it is serving live traffic. It divides cleanly into build-time controls, which find flaws in code and dependencies before release, and run-time controls, which defend the application while it is exposed to the world. Both halves are necessary, because each catches things the other cannot.<\/p>\n<\/div>\n\n<p>The gap between the two halves of application security is where most breaches in production software actually occur.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#lifecycle\">Application security across the lifecycle<\/a><\/li>\n    <li><a href=\"#build\">Build-time application security controls<\/a><\/li>\n    <li><a href=\"#run\">Run-time application security controls<\/a><\/li>\n    <li><a href=\"#order\">What to build first<\/a><\/li>\n    <li><a href=\"#osto\">Where Osto fits<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"lifecycle\">Application security across the lifecycle<\/h2>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 200\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Application security controls mapped across code, build, deploy and run stages, split into build-time and run-time halves.\">\n  <defs><marker id=\"as\" markerWidth=\"8\" markerHeight=\"8\" refX=\"6.5\" refY=\"4\" orient=\"auto\"><path d=\"M0,0 L8,4 L0,8 z\" fill=\"#4a52a8\"\/><\/marker><\/defs>\n\n  <rect x=\"14\" y=\"26\" width=\"358\" height=\"100\" rx=\"14\" fill=\"#e3f0e9\"\/>\n  <text x=\"193\" y=\"16\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" font-weight=\"700\" fill=\"#3a6f5d\">BUILD TIME<\/text>\n  <rect x=\"30\" y=\"44\" width=\"158\" height=\"30\" rx=\"8\" fill=\"#ffffff\"\/>\n  <text x=\"109\" y=\"64\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#0f1538\">Code<\/text>\n  <rect x=\"198\" y=\"44\" width=\"158\" height=\"30\" rx=\"8\" fill=\"#ffffff\"\/>\n  <text x=\"277\" y=\"64\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#0f1538\">Build<\/text>\n  <text x=\"109\" y=\"94\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#3a6f5d\">SAST, secrets scanning<\/text>\n  <text x=\"277\" y=\"94\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#3a6f5d\">SCA, SBOM<\/text>\n  <text x=\"193\" y=\"115\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" font-style=\"normal\" fill=\"#3a6f5d\">Finds flaws before anyone can reach them<\/text>\n\n  <line x1=\"376\" y1=\"76\" x2=\"398\" y2=\"76\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#as)\"\/>\n\n  <rect x=\"404\" y=\"26\" width=\"342\" height=\"100\" rx=\"14\" fill=\"#e2eff7\"\/>\n  <text x=\"575\" y=\"16\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" font-weight=\"700\" fill=\"#2f6f96\">RUN TIME<\/text>\n  <rect x=\"420\" y=\"44\" width=\"150\" height=\"30\" rx=\"8\" fill=\"#ffffff\"\/>\n  <text x=\"495\" y=\"64\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#0f1538\">Deploy<\/text>\n  <rect x=\"580\" y=\"44\" width=\"150\" height=\"30\" rx=\"8\" fill=\"#ffffff\"\/>\n  <text x=\"655\" y=\"64\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#0f1538\">Run<\/text>\n  <text x=\"495\" y=\"94\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#2f6f96\">DAST, pen testing<\/text>\n  <text x=\"655\" y=\"94\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#2f6f96\">WAF, API protection<\/text>\n  <text x=\"575\" y=\"115\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#2f6f96\">Blocks what was missed, and what is new<\/text>\n\n  <rect x=\"14\" y=\"142\" width=\"732\" height=\"46\" rx=\"12\" fill=\"#fbe9dc\"\/>\n  <text x=\"380\" y=\"170\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#a2603a\">A flaw shipped on Monday is exploitable on Monday. Scanning tells you about it. Only run-time stops it.<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<h2 id=\"build\" class=\"c-sage\">Build-time application security controls<\/h2>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Control<\/th><th>What it catches<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/sast\/\">SAST<\/a><\/td><td>Flaws in your own source code, such as injection and unsafe handling of input, read without running the application<\/td><\/tr>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/sca\/\">SCA<\/a><\/td><td>Known vulnerabilities in the open-source libraries you depend on, which is where the majority of a modern codebase comes from<\/td><\/tr>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/sbom\/\">SBOM<\/a><\/td><td>An inventory of every component shipped, so that when the next widely exploited library flaw lands you can answer whether you use it in minutes<\/td><\/tr>\n    <tr><td>Secrets scanning<\/td><td>Credentials and keys committed to the repository. Once pushed, a secret must be rotated rather than deleted, because the history retains it<\/td><\/tr>\n    <tr><td>Infrastructure as code scanning<\/td><td>Misconfigured cloud resources caught in the template, before the environment is created from it<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>These run in the pipeline, cost nothing per scan once wired in, and are the cheapest place to fix anything. They also share one limitation: they report, they do not prevent. A finding sits in a queue until somebody has time.<\/p>\n\n<h2 id=\"run\" class=\"c-plum\">Run-time application security controls<\/h2>\n\n<table class=\"h-plum\">\n  <thead>\n    <tr><th>Control<\/th><th>What it does<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/waf\/\">Web application firewall<\/a><\/td><td>Inspects live traffic and blocks injection, common attack patterns and automated abuse before requests reach your servers<\/td><\/tr>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/api-discovery\/\">API discovery<\/a><\/td><td>Finds the endpoints nobody documented. Undocumented APIs are a leading cause of exposure precisely because no control was ever applied to them<\/td><\/tr>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/api-security\/\">API protection<\/a><\/td><td>Schema enforcement, authentication checks and abuse limits on the interfaces that now carry most application traffic<\/td><\/tr>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/dast\/\">DAST<\/a><\/td><td>Tests the running application from the outside, catching problems that only appear once the code, configuration and environment are combined<\/td><\/tr>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/penetration-testing\/\">Penetration testing<\/a><\/td><td>A person attempting to chain findings together, which is how business logic flaws surface. No scanner finds those<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">Shifting left does not remove the run-time half<\/p>\n  <p>Scanning earlier is genuinely cheaper, and the argument for it is sound. It does not, however, close the window between a flaw being introduced and being fixed, and it cannot address a vulnerability disclosed in a library after you shipped. Two failure shapes are common. Teams that buy scanners and no <a href=\"https:\/\/www.osto.one\/resources\/glossary\/waf\/\">web application firewall<\/a> accumulate a backlog of known issues that remain exploitable while they wait in the queue. Teams that buy a firewall and never scan block the traffic patterns it recognises while the underlying flaw stays in the code. Application security needs both halves because each covers the other&#8217;s blind spot.<\/p>\n<\/div>\n\n<h2 id=\"order\" class=\"c-sky\">What to build first<\/h2>\n\n<p>For a small engineering team, application security is a sequence rather than a purchase. Roughly this order returns the most for the least effort.<\/p>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Step<\/th><th>Why it comes here<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>1. Know what is exposed<\/td><td>Discovery first. You cannot protect endpoints and services nobody has listed, and every stack has more of them than expected<\/td><\/tr>\n    <tr><td>2. Put a firewall in front<\/td><td>Immediate coverage against the common attack classes while everything else is still being organised<\/td><\/tr>\n    <tr><td>3. Dependency scanning<\/td><td>Most exploitable code in a young product is not code your team wrote. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sca\/\">SCA<\/a> is the highest return per hour spent<\/td><\/tr>\n    <tr><td>4. Secrets scanning in the pipeline<\/td><td>Cheap to add, and a leaked key is one of the fastest routes to a full compromise<\/td><\/tr>\n    <tr><td>5. Static analysis<\/td><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/sast\/\">SAST<\/a> after the first four, because it produces the most findings and needs someone with time to tune it<\/td><\/tr>\n    <tr><td>6. Penetration testing<\/td><td>Once the automated layers are running, so the tester spends their time on logic rather than reporting what a scanner would have found<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>Our <a href=\"https:\/\/www.osto.one\/resources\/guides\/application-security-for-saas-startups\/\">guide to application security for SaaS startups<\/a> works through this sequence with the practical detail, and <a href=\"https:\/\/www.osto.one\/resources\/guides\/do-you-need-a-waf\/\">the WAF guide<\/a> covers step two in depth.<\/p>\n\n<h2 id=\"osto\">Where Osto fits<\/h2>\n\n<p>Both halves of application security come from one platform rather than from separate build-time and run-time vendors. On the build side, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sast\/\">SAST<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sca\/\">SCA<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sbom\/\">SBOM<\/a> generation run against your repositories along with open-source licence checks. On the run side, the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/waf\/\">web application firewall<\/a> learns each application&#8217;s behaviour and applies a positive security policy automatically, so protection stands up without hand-written rules, and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/api-discovery\/\">API discovery<\/a> finds and protects endpoints that were never documented.<\/p>\n\n<p>Testing sits alongside both. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vapt\/\">VAPT<\/a> combines expert-led penetration testing with scheduled scanning and retest reports, so the sixth step in the sequence above is not a separate procurement exercise.<\/p>\n\n<p>The reason to keep them together is what happens between them. When a scanner finds a flaw that cannot be patched this week, the firewall in front of the same application can carry a compensating rule for it, and both events appear in <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">the same SIEM<\/a>. Split across vendors, that coordination is a manual exercise nobody runs. The resulting evidence covers the secure development and vulnerability management expectations in <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/annex-a-controls\/\">ISO 27001 Annex A<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/pci-dss\/\">PCI DSS<\/a>.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Platform walkthrough<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Both halves, one platform<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">SAST, SCA and SBOM in the pipeline. Self-configuring WAF, API discovery and VAPT in production. Findings and traffic in one dashboard.<\/p>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 32px;border-radius:12px;margin:0;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Book a demo<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:18px 0 0;\">Evidence from live controls &middot; 200+ frameworks mapped &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is application security?<\/summary>\n  <p>The practices that protect software across its life, from build-time controls that find flaws in code and dependencies before release to run-time controls that defend the application while it serves traffic.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between application security and network security?<\/summary>\n  <p>Network security protects the paths between systems. Application security protects the logic and data inside the software itself. A request can be perfectly legitimate at the network level and still be an attack on the application.<\/p>\n<\/details>\n\n<details>\n  <summary>Is a WAF enough on its own?<\/summary>\n  <p>No. A <a href=\"https:\/\/www.osto.one\/resources\/glossary\/waf\/\">web application firewall<\/a> blocks attacks against a flaw that remains in your code, which is valuable but temporary. Without scanning, the flaw is never fixed and any gap in the rules exposes it.<\/p>\n<\/details>\n\n<details>\n  <summary>What should a startup do first?<\/summary>\n  <p>Find out what is exposed, put a firewall in front of it, then add dependency scanning. Most exploitable code in a young product comes from open-source libraries rather than from your own team.<\/p>\n<\/details>\n\n<details>\n  <summary>Do compliance frameworks require application security?<\/summary>\n  <p>Yes, though usually by outcome rather than by tool. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/annex-a-controls\/\">ISO 27001 Annex A<\/a> expect secure development and vulnerability management, and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/pci-dss\/\">PCI DSS<\/a> is more specific, naming secure coding and regular testing directly.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sast\/\">SAST<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dast\/\">DAST<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sca\/\">SCA<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sbom\/\">SBOM<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/waf\/\">WAF<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/api-security\/\">API Security<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/api-discovery\/\">API Discovery<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vapt\/\">VAPT<\/a><\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Application security has two halves that operate at different times. Most teams buy one of them and believe the problem\u2026<\/p>\n","protected":false},"author":8,"featured_media":1227,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[627,628,629],"class_list":["post-1226","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-application-security","tag-application-security-tools","tag-build-time-vs-run-time-security"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1226","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1226"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1226\/revisions"}],"predecessor-version":[{"id":1228,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1226\/revisions\/1228"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1227"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1226"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1226"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1226"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}