Home > Essential fortification checklist
Security School:
EMAIL THIS

Essential fortification checklist

06 Jun 2007 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

by Michael Cobb

This checklist is a companion to the primer, Web site attacks and how to defeat them, part of SearchSecurity.com's Intrusion Defense School lesson, Web attack defense and prevention.

  Essential fortification checklist
Try out the many free tools available from Microsoft before deciding which additional security products your IIS server needs.
Subscribe to the newsgroups and forums that cover any products you purchase in order to stay up-to-date.
Don't install any of the samples and examples that come with a new product on your production server.
Secure your most important resources first, and check that your choice of product does indeed protect them.
Develop a Network Service Access Policy to define the features that your firewall must have.
Deploy an intrusion-detection system to provide security against imperfect products, and new and old vulnerabilities. Monitoring your system will help you catch a hacker regardless of what vulnerability they exploit to gain access.
Log files are only useful if you read them. Get a log analyzer, or a product that includes one, to automate the auditing and analysis of your network logs.
Choose an antivirus tool that centralizes control and can interact with other security products.
Implement Change Control and Back-Up Policies, and supplement them with restoration software to recover from Web defacements.
Get senior management on board as part of your security awareness training program to educate your staff about the need for security and their security-related duties.
Stress test your Web site to see if it can handle peak loads, and consider adding SSL-accelerator hardware if you're running an e-commerce site.
Decide whether you need strong authentication for those clients or users that need access to very sensitive information on your server, and issue them security tokens.
Find holes before hackers do by using a vulnerability scanner.
Download the CIS Scoring Tool, and check if your IIS configuration matches industry best practice.
If you don't have enough qualified security staff in-house, consider outsourcing some duties such as site monitoring.
Keep your documentation up to date. Use a network documentor if you're managing a big enterprise network.


Security School

Download the primer: Web site attacks and how to defeat them (.pdf).

Return to Intrusion Defense School.



Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary




Search Additional Security Research and Solutions
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts