Access your Pro+ Content below.
Choosing the right Web application firewall
This article is part of the March 2009 issue of Information Security magazine
Enterprises rushing to meet PCI compliance requirements may find themselves in a quandary when it comes to choosing a Web application firewall (WAF). How do you know what to look for? How do you deploy and manage the appliance or software effectively? How do you fit it into your existing infrastructure? We'll highlight the key considerations when evaluating products so your company is in compliance. Step by step: Choosing a WAF Follow these basic steps when choosing the appropriate Web application firewall for your application: Use security policy objectives to define what controls your WAF must have. Review the types of risk each product covers. Test performance and scalability. Evaluate the vendor's technical support. Assess whether you have the required in-house skills to maintain and manage it. Balance security, throughput, and overall cost. -- Michael Cobb A Web application firewall or application-layer firewall is an appliance or software designed to protect web applications against attacks and data leakage. It sits ...
Access this Pro+ Content for Free!
Features in this issue
Smaller organizations need to be more resourceful, and we'll explain how risk management, automation and managed security services, among others, can help.
On-demand computing services can save large enterprises and small businesses a lot of money, but security and regulatory compliance become difficult.
PCI DSS is requiring companies to buy Web application firewalls. We'll show how you how to pick the WAF that's right for you, and how to use it so your company is compliant -- and more secure.
How much information is too much information, and how will you monitor and manage the use of Web 2.0 inside your organization?
The Jericho Forum is expected to release a framework of security considerations for organizations moving business to the cloud.
Columns in this issue
The Obama Administration is conducting a review of the government's cybersecurity policies and process. We should be encouraged that security could move beyond the useless paper exercise it is today
As enterprises outsource more services and share data, they must be vigilant about the security of third parties.
Effective data classification in the enterprise requires a simple approach.