E-commerce organizations will adopt one of two strategies in respect of their e-commerce site functionality: they will either own (and be responsible for) their server platform, or they will contract with an organization that supplies that service, who usually also provides some form of web retailer package that can be integrated with their website and with an Online Payment Service. The security issues in each case are different: if the servers are owned in-house, security has to be tackled in-house; if the website is outsourced, then the quality of the provider's security is the issue. Organizations need to take specific steps to protect ('harden') their web servers from attack. There are a number of baseline security measures that should be documented. The starting point, if the organization is Essentials for e-commerce 113 running its web servers in-house, is to apply the CIS benchmarks to their configuration. These can be downloaded from www.cisecurity.org and they r...
- الحصول على الرابط
- X
- بريد إلكتروني
- التطبيقات الأخرى