Building a Secure Site on the Internet
Building and maintaining a secure site on the Internet includes many more tasks than simply installing your operating system, however securely you may do so. Overall security is a combination of secure software and careful human planning and administration. You will need to be concerned with all of the following tasks:
- Planning
Securing an Internet site must be a carefully planned and coordinated process. It’s not just a matter of clicking on screens and working it out as you go. Figure out the goals and tactics ahead of time, and then implement security, step-by-step. It’s also important to understand that you need one encompassing plan that includes all aspects of the process, rather than several small and uncoordinated planning efforts.
- Policies
In order to achieve a high level of security, you need policies that define the main aspects of running an Internet site. This is not a book on policies, but keep in mind that before you start building a secure system, you need to have the appropriate policies in place. Start by reading the Site Security Handbook (RFC 2196); it’s an excellent introduction to this topic.
- Access control
Access control protects systems from unauthorized use; there are several different types:
- Physical access control
Physical access control[8] is often overlooked, but it’s an extremely important outer level of protection. Large organizations often have big computer rooms that are both bomb-proof and earthquake-proof, ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access