Application Security encompasses measures taken to prevent exceptions in the application software or the underlying operating system security policy (vulnerability (computer science)) through flaws in the applications software design, capability maturity model, or software deployment.
Applications only control the use of resources access control to them, and not which resources are granted to them. They, in turn, determine the use of these resources by users of the application thru application security.