Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Softwares and Software Security
Software Security Controls and Best Practices Explained
Updated 11 October 2026 · Fact-checked
Software security controls are measures that protect software from misuse, attack and failure. They include patching, access control, encryption, code review, security testing and audits. To answer an exam question, name the risk, match each control to it, explain how it works, and link it to the legal duty to keep reasonable security.
Understand Software Security Controls and Best Practices
Software is secure when only the right people can use it, its data stays confidential and correct, and it keeps working when attacked. A weakness in software is called a vulnerability. An attacker who uses it is exploiting it. Security controls reduce the chance of this or limit the damage.
Controls fall into three groups. Preventive controls stop an attack: access control, encryption, patching, secure coding. Detective controls spot an attack: logging, monitoring, audits, vulnerability scans. Corrective controls repair damage: backups, incident response, restoring from a clean version.
The main controls are these:
- Patch management: Vendors release patches to fix known flaws. Attackers study patches and target systems that have not applied them. A good process lists all software, ranks patches by risk, tests them, applies them quickly and records the result.
- Access control: Give users only the rights they need (least privilege). Use strong authentication, preferably multi-factor, and remove access when a person leaves or changes role.
- Encryption: It turns data into unreadable form without a key. Use it for data at rest (stored) and data in transit (moving over a network).
- Code review: Another person, or a tool, reads the source code to find flaws before release. Secure coding rules, such as validating all input, apply here.
- Testing: Vulnerability assessment scans systems to find and list known weaknesses. Penetration testing is an authorised, simulated attack that tries to exploit weaknesses to show real impact.
- Security audit: An independent check of whether controls exist, are suitable and work in practice, measured against a policy or standard.
Security should be built in from the design stage of the software development life cycle, not added at the end. No single control is enough. Layering several controls is called defence in depth.
For law, the Information Technology Act, 2000 expects a body corporate handling sensitive personal data to keep reasonable security practices. If it fails and causes wrongful loss, it may have to pay compensation. Documented controls and audits are your evidence of reasonable security.
Key rules to remember
- Control types
- Preventive + Detective + Corrective
- Classify every control you name into one of these three groups. It shows structure in your answer.
- Least privilege
- User access = only what the job needs, nothing more
- Reduces damage from errors, insider misuse and stolen credentials.
- Confidentiality, Integrity, Availability
- CIA triad = Confidentiality + Integrity + Availability
- Link each control to the goal it protects. Encryption mainly protects confidentiality; backups protect availability.
- Vulnerability assessment vs penetration test
- VA = find and list weaknesses; PT = exploit them to prove impact
- VA is broad and usually automated. PT is deeper, targeted, manual and needs written authorisation.
- Patch cycle
- Identify → Assess risk → Test → Deploy → Verify → Record
- Use this order when asked how to run patch management.
How to solve Software Security Controls and Best Practices questions
Use the same frame for any question on software security measures. It keeps your answer complete and case-based.
- 1Read the facts and identify the asset (application, database, customer data) and the threat or failure described.
- 2Name the weakness: unpatched software, weak access, unencrypted data, unreviewed code, no testing or no audit.
- 3Pick the control that fixes that weakness and say whether it is preventive, detective or corrective.
- 4Explain how the control works in two or three lines, using the facts of the case.
- 5Add supporting controls to show defence in depth, such as logging, backups and training.
- 6Link to the legal duty: reasonable security practices and possible compensation under the IT Act, 2000.
- 7Conclude with a clear recommendation for the company, including documentation and periodic review.
Quickest way: Weakness-Control-Law in three lines
When to use it: Use it for short-answer questions or when you have under ten minutes for a case.
- Write the weakness in one line.
- Write the matching control and its type in one line.
- Write the legal or compliance consequence in one line, then add one supporting control.
Common mistakes in Software Security Controls and Best Practices
Treating vulnerability assessment and penetration testing as the same thing.
Both are called security testing and both use tools.
Fix: State that assessment finds and lists weaknesses, while penetration testing exploits them with authorisation to show real impact.
Saying patching is optional or only needed after an attack.
Students see patches as upgrades, not security fixes.
Fix: Explain that patches close known flaws and delay lets attackers use them. Describe a regular, risk-ranked cycle.
Naming controls without linking them to the facts.
Students memorise lists and write them out.
Fix: Tie each control to the weakness in the case. Say why it fits.
Confusing encryption with access control.
Both protect data from outsiders.
Fix: Access control decides who may enter or use. Encryption keeps data unreadable even if someone gets past access control.
Ignoring the legal angle.
The chapter looks technical.
Fix: Finish with reasonable security practices and compensation exposure under the IT Act, 2000, and the value of audit records.
Relying on a single control as a full solution.
Students look for one right answer.
Fix: Propose layers: prevent, detect and correct.
Worked examples
Example 1
Suraksha Finserv Ltd runs a customer loan portal. A known flaw in its web server software was fixed by the vendor six months ago, but the company never applied the patch. An attacker used the flaw to read customer records. Advise the company on what went wrong and what it should do.
Show the solution
- Weakness: the company did not apply an available patch, so a known vulnerability stayed open. This is a failure of patch management.
- Control: set up a patch management process. Keep an inventory of software, rank patches by risk, test them, deploy them quickly, verify and record them. Patching is a preventive control.
- Supporting controls: run regular vulnerability assessments to catch missing patches, apply least privilege and encrypt stored customer records so a breach exposes less.
- Detective and corrective: enable logging and monitoring, keep tested backups and have an incident response plan.
- Legal: customer records may include sensitive personal data. If the company did not keep reasonable security practices and the breach caused wrongful loss, it may be liable to pay compensation under the IT Act, 2000.
- Recommendation: adopt a written patch policy, assign responsibility and keep audit records as evidence.
Answer: The breach came from failure to patch a known flaw. Suraksha Finserv should adopt a risk-based patch cycle, supported by vulnerability assessment, least privilege, encryption, logging and backups. Without documented reasonable security practices, it risks compensation liability under the IT Act, 2000.
Example 2
Explain the difference between vulnerability assessment and penetration testing, and advise when a company should use each before launching a new mobile banking application.
Show the solution
- Define vulnerability assessment: a systematic, often automated scan that identifies, lists and ranks known weaknesses. It does not try to break in.
- Define penetration testing: an authorised, simulated attack by skilled testers who try to exploit weaknesses to show what an attacker could really achieve.
- Difference: assessment gives breadth and a list of issues. Penetration testing gives depth and proof of impact. Penetration testing needs written permission and a defined scope.
- Use before launch: run code review and vulnerability assessment during development and again before release, so common flaws are fixed early and cheaply.
- Then conduct penetration testing on the near-final application, as it handles money and sensitive data, and fix the findings.
- Repeat both after major changes and at regular intervals, and record results for security audit and legal evidence.
Answer: Vulnerability assessment finds and lists weaknesses; penetration testing exploits them with authorisation to show real impact. The company should use assessment and code review throughout development and before release, then penetration testing on the near-final app, and repeat both periodically and after major changes.
Exam tips
- Answer in the written format: provision or principle, analysis of facts, conclusion. Do not just list controls.
- Always define vulnerability assessment and penetration testing separately, with one line of contrast.
- Classify controls as preventive, detective or corrective to show structure quickly.
- Close case answers with the legal duty of reasonable security practices and the role of documented audits.
- Use the company's facts from the question in every paragraph so the answer reads as advice, not theory.
Practice questions from Softwares and Software Security
- Zenith Analytics develops a data-cleaning algorithm in India and wants protection for the software. Which statement reflects the position un…
- Which activity is characteristic of a secure SDLC, as distinct from an ordinary SDLC?
- A company secretary is told that a software team has finished writing code for a payroll module and now plans to run unit, integration and s…
- Under the Indian Copyright Act, 1957, a computer programme is protected as which type of work?
- A Pune start-up downloads a software library released under a permissive open-source licence such as the MIT licence. Which statement best d…
Software Security Controls and Best Practices: frequently asked questions
What are the main software security measures?
The main measures are patch management, access control, encryption, code review, security testing and security audits. Backups, logging and staff training support them. Together they give defence in depth.
What is the difference between vulnerability assessment and penetration testing?
Vulnerability assessment scans for and lists known weaknesses. Penetration testing is an authorised simulated attack that exploits weaknesses to show their real impact. Assessment is broader, while penetration testing is deeper.
Why is patch management important in cyber security?
Patches fix known flaws, and attackers target systems that stay unpatched. A regular, tested and recorded patch cycle closes these gaps quickly. It also shows reasonable care if a breach is later examined.
How does software security link to law?
Under the IT Act, 2000, a body corporate handling sensitive personal data must keep reasonable security practices. Failure that causes wrongful loss can lead to compensation. Documented controls and audits help show compliance.