15.5 Ensuring Web Security Properties

Here we examine the challenge of achieving the CIA properties on websites. We examine confidentiality and integrity here. A separate section discusses availability and a final section examines web privacy.

Web Confidentiality

Web services face a range of confidentiality problems and related security objectives. Although many web servers offer their contents to any and all potential visitors, some try to restrict access. Any site that collects confidential information from visitors is obliged to protect that information. We examine these cases here.

Serve Confidential Data

Most sites address this problem by identifying trustworthy users. If the user is authorized to retrieve the information, ...

Get Elementary Information Security, 3rd Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.