Application security is viewed more as an exercise in granting and managing privileges, rather than determining what exactly those privileges allow the user to access. Financial institutions need to continually push their software vendors for evidence that they’re doing what’s necessary to ensure the integrity of their products, says John Defterios. He says, “Bank management remains responsible for ensuring that the application meets the bank’s security requirements at acquisition and thereafter,” and this vigilance is expected. He urges banks to keep up with the new guidance and see how your institution stacks up against this new guidance.”]
Source: https://www.cuinfosecurity.com/blogs/application-security-exactly-what-your-users-access-p-36