It differs from a mobile app, which is installed from the App Store or Google Play, and from an e-commerce website, which is primarily for selling online. For security, OWASP publishes the ASVS, which provides a basis for testing web application technical security controls and a list of requirements for secure development.
Short answer
You describe your process, your users and the expected features: your request is reviewed by the Courtier TI team, then entrusted to the IT services company that will prepare your quote. The scope, steps and schedule are set with you.
What the quote should cover
- Needs analysis and the feature list for the first version
- User roles and their access rights
- Mockups and the user journey
- Architecture, hosting and integrations with your software
- Testing, including security testing, and the target ASVS level
- Ownership of the source code, accounts and documentation
- Post-launch maintenance: fixes, updates, enhancements
The steps of a web application project
- Analysis of the current process and users' needs
- Definition of priority features and roles
- Mockups and validation of the journey
- Development in stages, with regular demos
- Functional and security testing
- Launch, user training and follow-up
Custom or existing software
Before developing, check whether existing software, configured or connected to your tools, meets the need. Custom development is mainly justified when your process is specific to your business, when no software covers it properly, or when you want to offer a distinct service to your clients.
The cost of an application does not end with development: hosting, monitoring, component updates and enhancements continue for as long as it is used. A first version limited to essential features lets you validate the tool with users before going further.
Security and access control
The Canadian Centre for Cyber Security's baseline cyber security controls recommend that organizations ensure they understand the ASVS level they need to meet for each of their websites (BC.11.2). Ask for the target level to be stated in the quote, along with a description of the planned tests. For an application that processes sensitive data, penetration testing before launch can be planned.
The same controls recommend provisioning accounts with the minimum functionality necessary for tasks (BC.12.1). In a web application, this means clear roles: what a client, an employee or an administrator can see and change. Quebec's Act respecting the protection of personal information in the private sector points the same way: personal information is accessible to an employee only if it is necessary for the performance of their duties (s. 20).
Personal data
If the application collects, uses, communicates, keeps or destroys personal information, its development is a project covered by section 3.3 of the Act: a privacy impact assessment is required, and the person in charge of the protection of personal information must be consulted from the outset of the project. The same section requires that the project allow computerized personal information collected from the person concerned to be communicated to them in a structured, commonly used technological format.
If hosting or processing takes place outside Québec, section 17 requires an assessment before the communication and a written agreement. The provider that hosts or maintains the application for you acts under a mandate or contract that must be in writing and specify the protection measures (s. 18.3). The Quebec Law 25 for SMBs guide covers these obligations in more detail.
Code ownership, access and maintenance
Have the contract specify who owns the source code, or failing that which licence you are granted, and where the code will be stored. The domain name, hosting accounts and administrator access should be in your company's name, with enough documentation for another provider to take over the application if needed.
The quote should separate initial development from maintenance and describe what is included: security fixes, component and server updates, backups, error monitoring, small enhancements. If the application is hosted in the cloud, the Cloud server page describes what to plan for.
Questions to ask yourself before requesting a quote
- What process should the application simplify, and for whom?
- Could existing software meet the need?
- Which user roles are needed?
- Which software must the application exchange data with?
- What personal information will it process?
- Who will maintain the application after launch?
Pitfalls to avoid
- Starting development without describing the current process
- Source code and hosting accounts in the provider's name
- Identical access rights for all users
- No security level or tests specified in the quote
- Forgetting the privacy impact assessment
- A quote with no maintenance component
What to specify in your request
- The target process and the application's users
- Essential features and those that can wait
- The software it must communicate with
- The personal or sensitive data planned
- Your hosting requirements, if any
- Your approximate budget and date constraints, if any
You can then describe your project: the team will contact you to clarify your needs and provide a quote.
Frequently asked questions
How is it different from a mobile app or an e-commerce website?
A web application is used in a browser, with no installation from an app store. An e-commerce website is primarily for selling online, while a custom web application supports a specific process, such as a client portal or an internal tool.
What is OWASP ASVS?
It is a standard published by OWASP that provides a basis for testing web application technical security controls and a list of requirements for secure development. The Canadian Centre for Cyber Security recommends understanding the ASVS level to meet for each website (BC.11.2).
Who owns the code of a custom application?
That depends on the contract. Require ownership of the source code or a clearly defined licence, access to the code repository and sufficient documentation, as well as hosting accounts and a domain name in your company's name.
Is a privacy impact assessment required?
Yes, if the application involves collecting, using, communicating, keeping or destroying personal information: section 3.3 of Quebec's Act requires one for any such information system development project. It is proportionate to the sensitivity and amount of the information.
Can we start with a simple version?
Yes. A first version limited to essential features lets you validate the application with users. Have it planned in the quote, along with the next steps envisaged and how the code will be able to evolve.