Build your professional network on facebook via our app Go to app
 
 1 of 5 in Topic  Next >>
Topic : E-Business Security
  Rate : 
Posted in Community :

Online Business

 
Industry : Internet Functional Area : Application Software
Activity:  1 comments  268 views  last activity : 07 06 2010 20:18:04 +0000
Share
 
 
 

E-Business systems possess a higher degree of risk than mainstream applications, and thus require a greater degree of security. Because of this risk, security should be considered as a fundamental aspect of an e-business system design. The following guidelines will be beneficial while designing e-business systems.

Physical Security
1)The servers should be kept in a secure room with restricted access. Be wary of potential access points such as windows, dropped ceilings, large air ducts, and raised floors. Server racks and machine cases should be locked when possible. The room should provide proper environmental conditions and safety for the equipment. Servers should not be placed directly on the floor in case of flooding. An approved fire extinguisher should be kept near the server room.

2)Physical security of hard copies and data storage media containing sensitive customer information must be maintained. Windows, doors, and file cabinets should be locked in areas where sensitive information is stored. Where feasible, safes should be used to store especially sensitive data such as credit card information, checks, and currency. Access control to sensitive areas must be maintained and limited to individuals who require access as a result of their job.

3)High availability hardware should be used in all e-business servers (e.g. high quality components, redundant storage and power supplies, mirrored servers, error correcting memory, multiple NICs). Uninterruptible power supplies should be used on all servers and tested regularly.

4)Backups should be performed on a frequent and regular basis, and the backup media should be kept in a secure location. The backup media should be rotated and moved off-site as frequently as possible.

5)Modems should not reside in e-business servers unless absolutely necessary. If a modem is installed, it should be kept powered off or disabled except when needed. For added security, the modem should be configured to utilize features such as automatic call back and data encryption. Firewalls will not protect against attacks by way of the modem.

6)To provide more reliable and secure network access, servers and sensitive PCs should utilize switched network ports, not a shared medium such as coaxial cable or a repeated segment. Visible ports and exposed network cabling should not be present in vulnerable or public areas.

Data Storage
Sensitive information, especially credit card data, should never be stored on the web server. The data collected by the web server should be passed to another physical machine for storage. Ideally, the data collected by an e-business web site should be stored in a location that is not directly accessible to the Internet. Sensitive information should be stored encrypted when possible. Be wary of sensitive data that may be stored in a web server’s cache or log files.

 
1 comments on "Guidelines for e-business Security"
  Commented by  Viktor Stephen, Consultant/Partner, Get.Next.Job    | 02 07 2009 07:24:27 +0000
thanks for sharing. 
Add your comment on "Guidelines for e-business Security"

Rate:
Submit
Leading Executive Search and Staffing Organisaion
  • Create a confidential Career Profile and Resume/C.V. online
  • Get advice for planning their career and for marketing of experience and skills
  • Maximize awareness of and access to the best career opportunities
Viewers also viewed
in my view the aviation security,particularly airport security,should be funded from from the...
 
28 referals 4 comments, 31 views
it's a game vs it's a business
 
646 referals 36 arguments, 900 views
Now, This will be an interesting debate, "Out of every 10 people born in this world , 9 work for...
 
643 referals 115 arguments, 5287 views
more...  
Recent Knowledge (72)
India is a free nation. People have rights but still women are struggling to come up. There is a...
 
0 referals 6 comments, 73 views
The following is a reproduction of from an article I wrote in 2004. 1.  Harnessing the vast...
 
735 referals 18 comments, 325 views
Kingfisher is a big banner and we see this brand doing many things including lavish waste of...
 
2283 referals 32 comments, 452 views
more...  
More From Author
Government should increase Internet police services so who keep a check on the activities going on the Indian websites 24X7. These people will always get to know if any illegal access is going on and can provide enough proofs against a country which...
Its not safe to keep confidential data and important data in the hard disk as there is risk of its crashing or data loss.  So its preferable to keep 2-3 backups of the datas in external storage devices or CDs.
Dear Shashank, it would have been great had you been framed the sides clearly so that others can also contribute. Certification of good courses value a lot. It adds waightage on your resume. In India, we have good teachers of the world and these days...
more...