
Parameterised queries or stored procedures, instead of dynamically generated queries, are used by web applications for database interactions.

Web application interaction with databases
Applicable to
Non Classified, Official, Protected, Secret, Top Secret


Dec 2023
Parameterised queries or stored procedures, instead of dynamically generated queries, are used by web applications for database interactions.
The existing control relating to the use of parameterised queries or stored procedures instead of dynamically generated queries was reworded.
Mar 2023
Parameterised queries or stored procedures, instead of dynamically generated queries, are used for database interactions.
An existing control relating to the use of parameterised queries or stored procedures for database interactions was reworded to reduce confusion.
Parameterised queries or stored procedures should be used for database interaction insteadof dynamically generated queries.