PHP & MySQL® Web Development All-in-One Desk Reference for Dummies®
by Janet Valade, Tricia Ballad, Bill Ballad
1.3. Developing a Security Policy
One of the authors has a colleague who, although he is an extremely talented developer, absolutely hates to write documentation of any kind. Actually, hate is too gentle of a word. This person loathes documentation, because it takes him away from the challenge and fun of programming.
When you sense trouble brewing, a well-written security policy can prove to be a very effective counter weapon. Why? The best policies not only outline the way things should be done but also help to clarify and define the best resolutions for when problems do occur. Face it: No matter how lucky you are, inevitably you're going to find yourself directly under the spotlight of a security-related issue, or you'll be identified as a principle member of a security-related investigation. If you've taken the time to develop a strong security policy, you can make these situations far less unpleasant because you'll be able to specifically address not only how you did things but also how you you'll do things to get yourself (and others) out of the spotlight, without loss of trust or (in the worst case!) employment.
NOTE
If you're asking yourself, "Hey, aren't security policies the types of document written by the 'higher ups' or administrators?" you're asking a very good question. However, if you're in business on your own as an e-commerce Web site or application developer, you're more than likely as high up in the chain as anyone else is going to be, and you need to take the ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access