|
BackgroundInformation security has taken a high profile in recent years, and rightly so, as it has a bearing on all of us. This website is intended to provide a guide for IT professionals to understand the key issues around security, and it is hoped to be useful to a wider audience. It also aims to provide particular detail to anyone involved in developing and operating web applications. Read the full introduction HotspotsSome of the main hotspots in information security: Desktop Security Bulk Data Theft Web Applications Network Security There are many others, such as denial-of-service (DOS) attacks, voice over IP (VOIP) and telephony attacks, and social engineering. This site may be extended in the future. TechniquesHere are some general techniques for thinking about security: Components, Interfaces and Security Boundaries Security objectives High level Ultra secure - compromise cost & convenience Highly secure - cost no object, but needs to be convenient Good security Stop common attacks [is this a viable level?] Security not important Threat profile Keep outsiders out Restrict people to accessing their own stuff App specific requirements areas people can access a can request; b must approve© 1998 - 2008 Paul Johnston, distributed under the BSD License Updated:21 Feb 2008 |