Security testing has been limited to manual analysis by consultants, using internal teams with source code tools or trusting software vendors to test their own code. None of these approaches scale to cover entire application portfolios (as required by the OCC), and can add significant time and costs to projects. This whitepaper outlines how these limitations can be overcome by following five best practices that institutions can use to secure their applications.Mitigate risk from commercial software, outsourced development, and contracted software for both internal and web-facing applications.”]
Source: https://www.bankinfosecurity.com/whitepapers/occ-bulletin-2008-16-blueprint-for-compliance-w-188

