# Application Security Best Practices — Implementation Workbook

Version: 1.0
Published: 2026-07-27
Last updated: 2026-07-27
Owner: Rusaka Research
Review frequency: Every 6 months

## Decision statement

What decision must this workbook support?

________________________________________________________________________________

## Scope and exclusions

In scope:

________________________________________________________________________________

Out of scope:

________________________________________________________________________________

## Baseline evidence register

| Evidence item | Source | Date | Owner | Verified by | Status |
|---|---|---|---|---|---|
| | | | | | |
| | | | | | |
| | | | | | |

## Assumption register

| Assumption | Rationale | Decision affected | Downside case | Test | Owner | Review date |
|---|---|---|---|---|---|---|
| | | | | | | |
| | | | | | | |

## Options and decision criteria

| Option | Outcome | Feasibility | Cost | Time | Risk | Reversibility | Recommendation |
|---|---:|---:|---:|---:|---:|---:|---|
| | | | | | | | |
| | | | | | | | |

## Implementation plan

| Phase | Entry evidence | Actions | Owner | Control | Exit evidence | Due date |
|---|---|---|---|---|---|---|
| 1. Pilot — Application Security Best Practices | | During pilot, use Application Security Best Practices to apply reliable controls while adapting to organisational context. Start with a current asset inventory, data flows, threat model, control evidence, incidents, contracts, and applicable obligations. Name the accountable owner, the evidence reviewer, the decision deadline, and the output that proves this stage is complete. Record exclusions and unresolved questions rather than allowing them to disappear into narrative. The stage closes only when its evidence can be reproduced by someone who did not prepare it. | | | Required output: a standards register with applicability, exceptions, and review dates. | |
| 2. Scale — Application Security Best Practices | | During scale, use Application Security Best Practices to apply reliable controls while adapting to organisational context. Start with a current asset inventory, data flows, threat model, control evidence, incidents, contracts, and applicable obligations. Name the accountable owner, the evidence reviewer, the decision deadline, and the output that proves this stage is complete. Record exclusions and unresolved questions rather than allowing them to disappear into narrative. The stage closes only when its evidence can be reproduced by someone who did not prepare it. | | | Required output: a standards register with applicability, exceptions, and review dates. | |
| 3. Operations — Application Security Best Practices | | During operations, use Application Security Best Practices to apply reliable controls while adapting to organisational context. Start with a current asset inventory, data flows, threat model, control evidence, incidents, contracts, and applicable obligations. Name the accountable owner, the evidence reviewer, the decision deadline, and the output that proves this stage is complete. Record exclusions and unresolved questions rather than allowing them to disappear into narrative. The stage closes only when its evidence can be reproduced by someone who did not prepare it. | | | Required output: a standards register with applicability, exceptions, and review dates. | |
| 4. Discovery — Application Security Best Practices | | During discovery, use Application Security Best Practices to apply reliable controls while adapting to organisational context. Start with a current asset inventory, data flows, threat model, control evidence, incidents, contracts, and applicable obligations. Name the accountable owner, the evidence reviewer, the decision deadline, and the output that proves this stage is complete. Record exclusions and unresolved questions rather than allowing them to disappear into narrative. The stage closes only when its evidence can be reproduced by someone who did not prepare it. | | | Required output: a standards register with applicability, exceptions, and review dates. | |
| 5. Design — Application Security Best Practices | | During design, use Application Security Best Practices to apply reliable controls while adapting to organisational context. Start with a current asset inventory, data flows, threat model, control evidence, incidents, contracts, and applicable obligations. Name the accountable owner, the evidence reviewer, the decision deadline, and the output that proves this stage is complete. Record exclusions and unresolved questions rather than allowing them to disappear into narrative. The stage closes only when its evidence can be reproduced by someone who did not prepare it. | | | Required output: a standards register with applicability, exceptions, and review dates. | |

## Measures and thresholds

| Measure | Definition | Source | Baseline | Target | Threshold | Owner | Frequency |
|---|---|---|---:|---:|---:|---|---|
| | | | | | | | |
| | | | | | | | |

## Risk and control register

| Risk | Cause | Impact | Preventive control | Detective control | Owner | Residual risk |
|---|---|---|---|---|---|---|
| | | | | | | |
| | | | | | | |

## Review checklist

- [ ] 1. Current-state baseline: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.
- [ ] 2. Evidence design: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.
- [ ] 3. Operating model: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.
- [ ] 4. Architecture and integration: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.
- [ ] 5. Risk and compliance: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.
- [ ] 6. Economics and value: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.
- [ ] 7. Delivery sequencing: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.
- [ ] 8. Vendor and partner assessment: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.
- [ ] 9. Measurement system: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.
- [ ] 10. Quality assurance: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.
- [ ] 11. Change management: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.
- [ ] 12. Documentation: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.
- [ ] 13. Scenario analysis: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.
- [ ] 14. Security and resilience: evidence is linked, ownership is named, exceptions are recorded, and the current decision is clear.

## Approval record

| Role | Name | Decision | Conditions | Date |
|---|---|---|---|---|
| Accountable owner | | | | |
| Subject-matter reviewer | | | | |
| Risk or control reviewer | | | | |

## Authoritative references

- https://www.nist.gov/cyberframework — Authoritative reference 1 for the evidence and standards relevant to Cybersecurity. Confirm the current version and applicability before relying on it.
- https://owasp.org/www-project-top-ten/ — Authoritative reference 2 for the evidence and standards relevant to Cybersecurity. Confirm the current version and applicability before relying on it.
- https://www.cisa.gov/resources-tools — Authoritative reference 3 for the evidence and standards relevant to Cybersecurity. Confirm the current version and applicability before relying on it.

## Related Rusaka resources

- https://www.rusaka.com/resources/best-practices
- https://www.rusaka.com/resources/glossary/security-controls-library
- https://www.rusaka.com/resources/guides/identity-and-access-management-guide
- https://www.rusaka.com/resources/best-practices/documentation-standards
- https://www.rusaka.com/resources/best-practices/smart-contract-best-practices
- https://www.rusaka.com/resources/guides/cybersecurity-strategy-guide

## Important limitation

This educational workbook does not replace legal, investment, tax, accounting,
security, clinical, regulatory, or other qualified professional advice. Confirm
current requirements and obtain formal organisational approval where applicable.
