Skip to main content
University of California San Francisco Give to UCSF

UCSF IT Technology

Main navigation

  • Status
    • Security Announcements
  • Services
    • Projects
  • How To
  • News & Events
  • About Us
  • Log In
Open Close Search
Open menu
Give to UCSF

Breadcrumb

  1. Home
  2. Standards and Guidelines
  3. Best Practices For Application and Website Security

This content is viewable by Everyone

Guideline

Best Practices for Application and Website Security

Save

Log in via MyAccess to save.

  • Impacted Services IT Security Outreach and Training

Overview

By following application and website security best practices, application owners can take proactive steps to eliminate or significantly reduce vulnerabilities in software before deployment. These vulnerabilities potentially provide attackers with the ability to take control of a server or computer, which can result in the compromise of UCSF data and personal data, denial of service, loss of service or damage to a system used by thousands of users. By reducing the numbers of vulnerabilities, UCSF data and personal data is better protected.

Sources for application and website security best practices

  • Java
    • Oracle - Secure Coding Guidelines
  • C++
    • CERT - Secure Coding Standard for C++
  • C
    • CERT - Secure Coding Standard for C
  • Perl
    • CERT - Secure Coding Standard for Perl
  • Web applications and web servers
    • OWASP Top Ten
    • OWASP Top Ten (2017)
    • PHP - Security

Web application and system vulnerability scanning

In addition to application and website security best practices, ITS Security and Policy can scan your web server for web application vulnerabilities, such as SQL injection and cross-site scripting (XSS), as well as perform a system vulnerability scan on your system.

For more information, visit Application and Website Security.

  • Owning Team: IT Security
Section Menu
IT Security Outreach and Training
  • Information Security Is Everyone's Responsibility
  • IT Security Awareness - Stay Sharp to Stay Safe
  • IT Security and Awareness Champion Program: Overview
  • View IT Security Awareness Videos
  • Request IT Security Awareness Posters
  • IT Security Orientations and Education
  • IT Security Educational Meetings and Webinars
  • Advanced IT Security Training on the UCSF Learning Management System
Home

Footer Col 1

  • Status
  • Services
  • How To
  • News & Events

Footer Col 2

  • About
  • IT Directory
  • Standards & Guidelines

Footer Col 3

  • Get Help
  • Recognize IT Staff
  • Submit a Support Inquiry

    For emergencies and high priority issues please call the IT Service Desk (415) 514-4100

    • Facebook
    • Twitter
    • YouTube
    • Instagram

    © 2025 The Regents of the University of California