{"id":21635,"date":"2020-02-13T20:48:12","date_gmt":"2020-02-13T20:48:12","guid":{"rendered":"https:\/\/www.process.st\/templates\/application-security-audit-checklist-template\/"},"modified":"2024-05-16T06:29:21","modified_gmt":"2024-05-16T06:29:21","slug":"application-security-audit-checklist-template","status":"publish","type":"post","link":"https:\/\/www.process.st\/templates\/application-security-audit-checklist-template\/","title":{"rendered":"Application Security Audit Checklist Template"},"content":{"rendered":"\n<section id=\"introduction\">\n <h2>Introduction:<\/h2>\n <div class=\"image-content\">\n  <figure>\n   <a href=\"https:\/\/ps-attachments.s3.amazonaws.com\/cec595ea-0569-4886-a469-bb652328cacf\/iAcYns5FDzVi089GkJhEQw.png\" alt=\"Introduction:\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/ps-attachments.s3.amazonaws.com\/cec595ea-0569-4886-a469-bb652328cacf\/iAcYns5FDzVi089GkJhEQw.png\"> <\/a><!-- No caption -->\n  <\/figure>\n <\/div>\n <div class=\"text-content\">\n  <p>Every application becomes vulnerable as soon as it's open to the internet, but luckily there are many ways you can protect your application and it's security when your app is being developed.&nbsp;<\/p>\n  <p>Application security should be an essential part of developing any application in order to prevent your company and its users' sensitive information from getting into the wrong hands.&nbsp;<\/p>\n  <p>Running an application security audit regularly allows you to protect your app from any potential threats and be prepared with a backup if anything were to happen. It's unrealistic to expect to be able to avoid every possible problem that may come up, but there are definitely many known recurrent threats that are avoidable when taking the right measures and auditing your application regularly.<\/p>\n  <p>This is exactly why we at <a href=\"https:\/\/www.youtube.com\/watch?v=jtSUWKI6PNo\" rel=\"nofollow noopener\" target=\"_blank\">Process Street<\/a> have created this application security audit checklist. It outlines all of the common tasks and checks needed to tighten up your team's application security and can easily be repeated whenever you might need.<\/p>\n <\/div>\n<\/section>\n<section id=\"create-model-of-application\">\n <h2>Create model of application<\/h2>\n <div class=\"text-content\">\n  <p>Before all else, you and your development team should focus on <strong>creating the application<\/strong> and getting it <a href=\"https:\/\/www.process.st\/help\/docs\/approvals\/\" rel=\"nofollow noopener\" target=\"_blank\"><strong>approved<\/strong> <\/a>by the management and IS security team.<\/p>\n  <p>Because this process involves multiple people, you can make things easier for yourself by <a href=\"https:\/\/www.process.st\/help\/docs\/role-assignments\/\" rel=\"nofollow noopener\" target=\"_blank\"><strong>assigning roles<\/strong><\/a>.<\/p>\n  <p>Use the <strong><a href=\"https:\/\/www.process.st\/help\/docs\/adding-members\/\" rel=\"nofollow noopener\" target=\"_blank\">Members<\/a>&nbsp;<\/strong>feature below to specify who will be doing what.<\/p>\n <\/div>\n <div class=\"members-field-content form-field-content\">\n  <div class=\"form-group\">\n   <label> Management <\/label> <select disabled class=\"form-control\"> <option value=\"A member or group will be selected here\">A member or group will be selected here<\/option> <\/select>\n  <\/div>\n <\/div>\n <div class=\"members-field-content form-field-content\">\n  <div class=\"form-group\">\n   <label> IS security team <\/label> <select disabled class=\"form-control\"> <option value=\"A member or group will be selected here\">A member or group will be selected here<\/option> <\/select>\n  <\/div>\n <\/div>\n <div class=\"text-content\">\n  <p>When the application is finished, make sure the designated people approve it.<\/p>\n <\/div>\n<\/section>\n<section id=\"approval-application-model\">\n <h2>Approval: Application model<\/h2>\n <div class=\"approval-content\">\n  <div class=\"header\">\n   <div class=\"list-title\">\n    Will be submitted for approval:\n   <\/div>\n  <\/div>\n  <div class=\"approval-rule-subject-tasks-list\">\n   <ul class=\"list\">\n    <li>\n     <div class=\"approval-rule-subject-tasks-list-item\">\n      <div class=\"item\">\n       <div class=\"container\">\n        <span class=\"title\">Create model of application<\/span>\n        <div class=\"body\">\n         Will be submitted\n        <\/div>\n       <\/div>\n      <\/div>\n     <\/div><\/li>\n   <\/ul>\n  <\/div>\n <\/div>\n<\/section>\n<section id=\"make-sure-the-applications-authentication-system-is-uptodate\">\n <h2>Make sure the application\u2019s authentication system is up-to-date<\/h2>\n <div class=\"text-content\">\n  <p>Next step is <strong>making sure your application's authentication system is up-to-date.<\/strong><\/p>\n  <p>Consider utilizing a <a href=\"https:\/\/www.process.st\/enable-two-factor-authentication\/\" rel=\"nofollow noopener\" target=\"_blank\"><strong>two-factor authentication<\/strong><\/a>, so users would need to not only enter a password, but also to enter a code sent to the phone number or email that's attached to their account to get in.<\/p>\n  <p>This means that if someone is trying to break into your user's account, they won\u2019t be be able to even if they're able to guess the password.&nbsp;<\/p>\n <\/div>\n<\/section>\n<section id=\"restrict-access-to-application-directories-and-files\">\n <h2>Restrict access to application directories and files<\/h2>\n <div class=\"text-content\">\n  <p>Ensure that no one except administrative users have access to application's directories and files.<\/p>\n <\/div>\n<\/section>\n<section id=\"implement-session-expiration-timeout\">\n <h2>Implement session expiration timeout<\/h2>\n <div class=\"text-content\">\n  <h4>How long should a session timeout be?<\/h4>\n  <p>Normal session timeouts range between <strong>2-5 minutes<\/strong> for high-risk applications and between <strong>15-30 minutes<\/strong> for low-risk applications.&nbsp;<\/p>\n <\/div>\n<\/section>\n<section id=\"forbid-multiple-concurrent-sessions\">\n <h2>Forbid multiple concurrent sessions<\/h2>\n <div class=\"text-content\">\n  <h5>How to prevent multiple concurrent user logins for the same username<\/h5>\n  <p>There are many ways to do this; a simple approach might be:<\/p>\n <\/div>\n <div class=\"multi-select-content form-field-content\">\n  <div class=\"form-group\">\n   <label> (Subtasks) <\/label>\n  <\/div>\n  <ul class=\"items\">\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">\n      1\n     <\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">\n     Set one flag at the time of login into database\n    <\/div><\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">\n      2\n     <\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">\n     Check flag every time when you are sign in\n    <\/div><\/li>\n   <li class=\"item\">\n    <div class=\"step-number-container\">\n     <div class=\"step-number\">\n      3\n     <\/div>\n    <\/div>\n    <div class=\"step-checkbox-container\">\n     <div class=\"step-checkbox\"><\/div>\n    <\/div>\n    <div class=\"item-name-static\">\n     Remove flag at time of logout\n    <\/div><\/li>\n  <\/ul>\n <\/div>\n<\/section>\n<section id=\"provide-least-privilege-to-application-users\">\n <h2>Provide least privilege to application users<\/h2>\n <div class=\"text-content\">\n  <h4>What is the Principle of Least Privilege (POLP)<\/h4>\n  <p>The idea of POLP means that all <strong>users should only have access to what they absolutely need<\/strong> and no more than that.&nbsp;<\/p>\n  <p>For example, if a user account was created to have access to database records, that account doesn't need <a href=\"https:\/\/www.process.st\/checklist\/privileged-password-management\/\" rel=\"nofollow noopener\" target=\"_blank\">administrative privileges<\/a>.<\/p>\n  <p>This principle is widely accepted as one of the best practices in information security.<\/p>\n <\/div>\n<\/section>\n<section id=\"implement-captcha-and-email-verification-system\">\n <h2>Implement CAPTCHA and email verification system<\/h2>\n <div class=\"text-content\">\n  <p><strong>CAPTCHA<\/strong> and <strong>email verification<\/strong> serve different purposes, but are both equally as important.<\/p>\n  <p><strong>CAPTCHA<\/strong> makes sure it's actual people submitting forms and not scripts.<\/p>\n  <p><strong>Email verification<\/strong> makes sure that the email address that was entered actually exists and is working.<\/p>\n <\/div>\n<\/section>\n<section id=\"use-encryption-algorithms-that-meet-data-security-requirements\">\n <h2>Use encryption algorithms that meet data security requirements<\/h2>\n <div class=\"text-content\">\n  <p>Depending on what your organization's data security requirements call for, you might want to consider using a <strong>data encryption algorithm<\/strong>.<\/p>\n  <p>Some data encryption algorithms include:<\/p>\n  <ul>\n   <li><a href=\"https:\/\/en.wikipedia.org\/wiki\/Triple_DES\" rel=\"nofollow noopener\" target=\"_blank\">Triple DES<\/a><\/li>\n   <li><a href=\"https:\/\/en.wikipedia.org\/wiki\/RSA_%28cryptosystem%29\" rel=\"nofollow noopener\" target=\"_blank\">RSA<\/a>&nbsp;<\/li>\n   <li><a href=\"https:\/\/en.wikipedia.org\/wiki\/Blowfish_%28cipher%29\" rel=\"nofollow noopener\" target=\"_blank\">Blowfish<\/a><\/li>\n   <li><a href=\"https:\/\/en.wikipedia.org\/wiki\/Twofish\" rel=\"nofollow noopener\" target=\"_blank\">Twofish<\/a><\/li>\n   <li><a href=\"https:\/\/en.wikipedia.org\/wiki\/Advanced_Encryption_Standard\" rel=\"nofollow noopener\" target=\"_blank\">Advanced Encryption Standard (AES)<\/a><\/li>\n  <\/ul>\n <\/div>\n<\/section>\n<section id=\"avoid-vulnerable-api-or-function-calls\">\n <h2>Avoid vulnerable API or function calls<\/h2>\n <div class=\"text-content\">\n  <p><strong>APIs<\/strong> are the keys to a company's databases, so it\u2019s very important to <strong>restrict and monitor who has access to them<\/strong>.<\/p>\n <\/div>\n<\/section>\n<section id=\"run-security-audit-on-source-codes\">\n <h2>Run security audit on source codes<\/h2>\n <div class=\"text-content\">\n  <p><strong>Source code analysis tools<\/strong>&nbsp;are made to look over your source code or compiled versions of code to help spot any security flaws.<\/p>\n  <h4>Free Security Audit Tools<\/h4>\n  <ul>\n   <li><a href=\"https:\/\/wiki.openstack.org\/wiki\/Security\/Projects\/Bandit\" rel=\"nofollow noopener\" target=\"_blank\">Bandit<\/a>&nbsp;- bandit is a comprehensive source vulnerability scanner for Python<\/li>\n   <li><a href=\"http:\/\/brakemanscanner.org\/\" rel=\"nofollow noopener\" target=\"_blank\">Brakeman<\/a>&nbsp;- Brakeman is an open source vulnerability scanner specifically designed for Ruby on Rails applications<\/li>\n   <li><a href=\"http:\/\/rubygems.org\/gems\/codesake-dawn\" rel=\"nofollow noopener\" target=\"_blank\">Codesake Dawn<\/a>&nbsp;- Codesake Dawn is an open source security source code analyzer designed for Sinatra, Padrino for Ruby on Rails applications. It also works on non-web applications written in Ruby<\/li>\n   <li><a href=\"https:\/\/discotek.ca\/deepdive.xhtml\" rel=\"nofollow noopener\" target=\"_blank\">Deep Dive<\/a>&nbsp;- Byte code analysis tool for discovering vulnerabilities in Java deployments (Ear, War, Jar).<\/li>\n   <li><a href=\"http:\/\/findbugs.sourceforge.net\/\" rel=\"nofollow noopener\" target=\"_blank\">FindBugs<\/a>&nbsp;- (Legacy - NOT Maintained - Use SpotBugs (see below) instead) - Find bugs (including a few security flaws) in Java programs<\/li>\n   <li><a href=\"https:\/\/find-sec-bugs.github.io\/\" rel=\"nofollow noopener\" target=\"_blank\">FindSecBugs<\/a>&nbsp;- A security specific plugin for SpotBugs that significantly improves SpotBugs\u2019s ability to find security vulnerabilities in Java programs. Works with the old FindBugs too,<\/li>\n   <li><a href=\"http:\/\/www.dwheeler.com\/flawfinder\/\" rel=\"nofollow noopener\" target=\"_blank\">Flawfinder<\/a>&nbsp;Flawfinder - Scans C and C++<\/li>\n   <li><a href=\"https:\/\/github.com\/golangci\/golangci-lint\" rel=\"nofollow noopener\" target=\"_blank\">GolangCI-Lint<\/a>&nbsp;- A Go Linters aggregator - One of the Linters is&nbsp;<a href=\"https:\/\/github.com\/securego\/gosec\" rel=\"nofollow noopener\" target=\"_blank\">gosec (Go Security)<\/a>, which is off by default but can easily be enabled.<\/li>\n  <\/ul>\n <\/div>\n<\/section>\n<section id=\"conduct-web-application-vulnerability-scan\">\n <h2>Conduct web application vulnerability scan<\/h2>\n <div class=\"text-content\">\n  <p>Conducting an <strong>application vulnerability scan<\/strong> is a security process used to&nbsp;find weaknesses in your computer security.&nbsp;<\/p>\n  <p><strong>Vulnerability scanning<\/strong>&nbsp;should be&nbsp;performed by your network administrators for security purposes. Otherwise, it could potentially be used to fraudulently gain access to your systems.<\/p>\n  <p><strong>These are some of the best open source&nbsp;web application&nbsp;penetration testing&nbsp;tools:<\/strong><\/p>\n  <ul>\n   <li><a href=\"https:\/\/tools.kali.org\/web-applications\/grabber\" rel=\"nofollow noopener\" target=\"_blank\">Grabber<\/a><\/li>\n   <li><a href=\"https:\/\/subgraph.com\/vega\/\" rel=\"nofollow noopener\" target=\"_blank\">Vega<\/a><\/li>\n   <li><a href=\"https:\/\/wapiti.sourceforge.io\/\" rel=\"nofollow noopener\" target=\"_blank\">Wapiti<\/a><\/li>\n   <li><a href=\"http:\/\/w3af.org\/\" rel=\"nofollow noopener\" target=\"_blank\">W3af<\/a><\/li>\n   <li><a href=\"https:\/\/webscarab.apponic.com\/\" rel=\"nofollow noopener\" target=\"_blank\">WebScarab<\/a><\/li>\n   <li><a href=\"https:\/\/tools.kali.org\/web-applications\/skipfish\" rel=\"nofollow noopener\" target=\"_blank\">Skipfish<\/a><\/li>\n   <li><a href=\"https:\/\/securiteam.com\/tools\/5xp010kouc\/\" rel=\"nofollow noopener\" target=\"_blank\">Ratproxy<\/a><\/li>\n   <li><a href=\"http:\/\/sqlmap.org\/\" rel=\"nofollow noopener\" target=\"_blank\">SQLMap<\/a><\/li>\n  <\/ul>\n <\/div>\n<\/section>\n<section id=\"conduct-penetration-test\">\n <h2>Conduct penetration test<\/h2>\n <div class=\"text-content\">\n  <p>A&nbsp;<strong>penetration test<\/strong>&nbsp;is a test cyber attack set against your computer system to check for any security vulnerabilities. <strong>P<\/strong><strong>enetration testing<\/strong>&nbsp;is typically used to strengthen an application's firewall.<\/p>\n  <p><strong>Free Security Testing Tools<\/strong><\/p>\n  <ul>\n   <li><a href=\"https:\/\/www.arachni-scanner.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Arachni<\/a><\/li>\n   <li><a href=\"https:\/\/resources.infosecinstitute.com\/ironwasp-part-1-2\/#gref\" rel=\"nofollow noopener\" target=\"_blank\">Iron Wasp<\/a><\/li>\n   <li><a href=\"https:\/\/www.digitalmunition.me\/nogotofail-network-security-testing-tool-https-tlsssl-bugs\" rel=\"nofollow noopener\" target=\"_blank\">Nogotofail<\/a><\/li>\n   <li><a href=\"https:\/\/resources.infosecinstitute.com\/sonarqube-hidden-gem\/#gref\" rel=\"nofollow noopener\" target=\"_blank\">SonarQube<\/a><\/li>\n   <li><a href=\"http:\/\/sqlmap.org\/\" rel=\"nofollow noopener\" target=\"_blank\">SQLMap<\/a><\/li>\n   <li><a href=\"https:\/\/tools.kali.org\/web-applications\/w3af\" rel=\"nofollow noopener\" target=\"_blank\">W3af<\/a><\/li>\n   <li><a href=\"https:\/\/sectools.org\/tool\/wapiti\/\" rel=\"nofollow noopener\" target=\"_blank\">Wapiti<\/a><\/li>\n  <\/ul>\n <\/div>\n<\/section>\n<section id=\"sources\">\n <h2>Sources:<\/h2>\n <div class=\"text-content\">\n  <p><\/p>\n  <ul>\n   <li><a href=\"http:\/\/www.dotnetfunda.com\/\" rel=\"nofollow noopener\" target=\"_blank\">dotnetfunda<\/a> - <a href=\"http:\/\/www.dotnetfunda.com\/articles\/show\/1083\/restricting-user-to-login-multiple-times-using-same-credentials\" rel=\"nofollow noopener\" target=\"_blank\">Restricting Use To Login Multiple Times Using Same Credentials<\/a><\/li>\n   <li><a href=\"http:\/\/geekswithblogs.net\/\" rel=\"nofollow noopener\" target=\"_blank\">geekswithblogs<\/a> - <a href=\"http:\/\/geekswithblogs.net\/Frez\/articles\/preventing-a-user-from-having-multiple-concurrent-sessions.aspx\" rel=\"nofollow noopener\" target=\"_blank\" title=\"Title of this entry.\">Preventing a User From Having Multiple Concurrent Sessions<\/a><\/li>\n   <li><a href=\"https:\/\/www.codeproject.com\/\" rel=\"nofollow noopener\" target=\"_blank\">codeproject<\/a> - <a href=\"https:\/\/www.codeproject.com\/Questions\/410002\/How-to-avoid-multi-user-signin-using-same-credenti\" rel=\"nofollow noopener\" target=\"_blank\">How To Avoid Multi-User Sign-In Using Same Credentials<\/a><\/li>\n   <li><a href=\"https:\/\/securitywing.com\/\" rel=\"nofollow noopener\" target=\"_blank\">securitywing<\/a> - <a href=\"https:\/\/securitywing.com\/63-web-application-security-checklist-auditors-developers\/\" rel=\"nofollow noopener\" target=\"_blank\">63 Web Application Security Checklist for IT Security Auditors and Developers<\/a><\/li>\n  <\/ul>\n <\/div>\n<\/section>\n<section id=\"related-checklists\">\n <h2>Related checklists:<\/h2>\n <div class=\"text-content\">\n  <ul>\n   <li><a href=\"https:\/\/process.st\/checklist\/invoice-approval-workflow-checklist-template\" rel=\"nofollow noopener\" target=\"_blank\">Invoice Approval Workflow Checklist Template<\/a><\/li>\n   <li><a href=\"https:\/\/process.st\/checklist\/blog-content-approval-checklist-template\" rel=\"nofollow noopener\" target=\"_blank\">Blog Content Approval Checklist Template<\/a><\/li>\n   <li><a href=\"https:\/\/process.st\/checklist\/graphic-design-approval-checklist-template\" rel=\"nofollow noopener\" target=\"_blank\">Graphic Design Approval Checklist Template<\/a><\/li>\n   <li><a href=\"https:\/\/process.st\/checklist\/wordpress-security-audit-checklist-template\" rel=\"nofollow noopener\" target=\"_blank\">WordPress Security Audit Checklist Template<\/a><\/li>\n   <li><a href=\"https:\/\/process.st\/checklist\/video-content-approval-workflow-checklist-template\" rel=\"nofollow noopener\" target=\"_blank\">Video Content Approval Workflow Checklist Template<\/a><\/li>\n   <li><a href=\"https:\/\/process.st\/checklist\/information-security-checklist-template\" rel=\"nofollow noopener\" target=\"_blank\">Information Security Checklist Template<\/a><\/li>\n   <li><a href=\"https:\/\/process.st\/checklist\/content-marketing-workflow-management-checklist-template\" rel=\"nofollow noopener\" target=\"_blank\">Content Marketing Workflow Management Checklist Template<\/a><\/li>\n   <li><a href=\"https:\/\/process.st\/checklist\/enterprise-password-management-checklist-template\" rel=\"nofollow noopener\" target=\"_blank\">Enterprise Password Management Checklist Template<\/a><\/li>\n   <li><a href=\"https:\/\/process.st\/checklist\/enterprise-video-content-management-checklist\" rel=\"nofollow noopener\" target=\"_blank\">Enterprise Video Content Management Checklist<\/a><\/li>\n  <\/ul>\n <\/div>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>Introduction: Every application becomes vulnerable as soon as it's open to the internet, but luckily there are many ways you can protect your application and it's security when your app is being developed.&nbsp; Application security should be an essential part of developing any application in order to prevent your company and its users' sensitive information [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":21636,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"ep_exclude_from_search":false,"cover_icon_emoji":"\ud83d\udd10","cover_icon_url":"","tasks_count":"16","template_description":"Run this checklist whenever you need to perform an application security audit.","template_id":"jxuOTC00SFDSzQPytjZEoA","task_0":"Introduction:","task_slug_0":"introduction","task_1":"Create model of application","task_slug_1":"create-model-of-application","task_2":"Approval: Application model","task_slug_2":"approval-application-model","task_3":"Make sure the application\u2019s authentication system is up-to-date ","task_slug_3":"make-sure-the-applications-authentication-system-is-uptodate","task_4":"Restrict access to application directories and files","task_slug_4":"restrict-access-to-application-directories-and-files","task_5":"Implement session expiration timeout","task_slug_5":"implement-session-expiration-timeout","task_6":"Forbid multiple concurrent sessions","task_slug_6":"forbid-multiple-concurrent-sessions","task_7":"Provide least privilege to application users","task_slug_7":"provide-least-privilege-to-application-users","task_8":"Implement CAPTCHA and email verification system","task_slug_8":"implement-captcha-and-email-verification-system","task_9":"Use encryption algorithms that meet data security requirements","task_slug_9":"use-encryption-algorithms-that-meet-data-security-requirements","task_10":"Avoid vulnerable API or function calls ","task_slug_10":"avoid-vulnerable-api-or-function-calls","task_11":"Run security audit on source codes","task_slug_11":"run-security-audit-on-source-codes","task_12":"Conduct web application vulnerability scan","task_slug_12":"conduct-web-application-vulnerability-scan","task_13":"Conduct penetration test","task_slug_13":"conduct-penetration-test","task_14":"Sources:","task_slug_14":"sources","task_15":"Related checklists:","task_slug_15":"related-checklists","task_16":"","task_slug_16":"","task_17":"","task_slug_17":"","task_18":"","task_slug_18":"","task_19":"","task_slug_19":"","task_20":"","task_slug_20":"","task_21":"","task_slug_21":"","task_22":"","task_slug_22":"","task_23":"","task_slug_23":"","task_24":"","task_slug_24":"","task_25":"","task_slug_25":"","task_26":"","task_slug_26":"","task_27":"","task_slug_27":"","task_28":"","task_slug_28":"","task_29":"","task_slug_29":"","task_30":"","task_slug_30":"","task_31":"","task_slug_31":"","task_32":"","task_slug_32":"","task_33":"","task_slug_33":"","task_34":"","task_slug_34":"","task_35":"","task_slug_35":"","task_36":"","task_slug_36":"","task_37":"","task_slug_37":"","task_38":"","task_slug_38":"","task_39":"","task_slug_39":"","task_40":"","task_slug_40":"","task_41":"","task_slug_41":"","task_42":"","task_slug_42":"","task_43":"","task_slug_43":"","task_44":"","task_slug_44":"","task_45":"","task_slug_45":"","task_46":"","task_slug_46":"","task_47":"","task_slug_47":"","task_48":"","task_slug_48":"","task_49":"","task_slug_49":"","task_50":"","task_slug_50":"","task_51":"","task_slug_51":"","task_52":"","task_slug_52":"","task_53":"","task_slug_53":"","task_54":"","task_slug_54":"","task_55":"","task_slug_55":"","task_56":"","task_slug_56":"","task_57":"","task_slug_57":"","task_58":"","task_slug_58":"","task_59":"","task_slug_59":"","task_60":"","task_slug_60":"","task_61":"","task_slug_61":"","task_62":"","task_slug_62":"","task_63":"","task_slug_63":"","task_64":"","task_slug_64":"","task_65":"","task_slug_65":"","task_66":"","task_slug_66":"","task_67":"","task_slug_67":"","task_68":"","task_slug_68":"","task_69":"","task_slug_69":"","task_70":"","task_slug_70":"","task_71":"","task_slug_71":"","task_72":"","task_slug_72":"","task_73":"","task_slug_73":"","task_74":"","task_slug_74":"","task_75":"","task_slug_75":"","task_76":"","task_slug_76":"","task_77":"","task_slug_77":"","task_78":"","task_slug_78":"","task_79":"","task_slug_79":"","task_80":"","task_slug_80":"","task_81":"","task_slug_81":"","task_82":"","task_slug_82":"","task_83":"","task_slug_83":"","task_84":"","task_slug_84":"","task_85":"","task_slug_85":"","task_86":"","task_slug_86":"","task_87":"","task_slug_87":"","task_88":"","task_slug_88":"","task_89":"","task_slug_89":"","task_90":"","task_slug_90":"","task_91":"","task_slug_91":"","task_92":"","task_slug_92":"","task_93":"","task_slug_93":"","task_94":"","task_slug_94":"","task_95":"","task_slug_95":"","task_96":"","task_slug_96":"","task_97":"","task_slug_97":"","task_98":"","task_slug_98":"","task_99":"","task_slug_99":"","footnotes":""},"categories":[60,57],"tags":[],"class_list":["post-21635","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-creative-workflow-management","category-information-security"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/posts\/21635","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/comments?post=21635"}],"version-history":[{"count":0,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/posts\/21635\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/media\/21636"}],"wp:attachment":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/media?parent=21635"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/categories?post=21635"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/tags?post=21635"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}