dcsimg

Find an IT Download

Guide to Website Security

Basic guidelines that can be applied to websites to reduce the attack surface or mitigate the effects of a compromise.


256 KB | 3 files | null PDF

Every community organization, corporation, business, or government agency relies on an outward-facing website to provide information about themselves, announce an event, or sell a product or service. Consequently, public facing websites are often the most targeted attack vectors for malicious activity. Web server attacks include:

  • Exploitation of software bugs in the Web server
  • Denial of Service (DoS) or Distributed Denial of Service (DDoS) attacks
  • Compromising "backend" data through command injection attacks, such as Structured Query Language (SQL) injection; Lightweight Directory Access Protocol (LDAP) injection; and cross-site scripting (XSS)
  • Website defacement for malicious purposes
  • Using compromised Web server capabilities to attack external entities
  • Using a compromised Web server to distribute malware.

There are a number of challenges associated with securing a Web server because not only does the operating system need to be secured but so do the associated Web applications and services running on the device. One of the most difficult aspects is often keeping abreast of new and emerging vulnerabilities to both the Operating system and the Web applications as well as keeping those systems patched and up to date.

This TIP provides basic guidelines and security safeguard concepts that can be applied to public facing websites to reduce the attack surface area or mitigate the effects of a compromise.

The attached zip file includes:

  • Intro Page.pdf
  • Terms and Conditions.pdf
  • WebsiteSecurity.pdf

Related IT DOWNLOADS

Recent IT Downloads
Building a GRC Program: Assessing Stakeholder Needs and Readiness

This table outlines the top needs of each stakeholder group that can help guide your conversat...Read More

Recent IT Downloads
Guide to Cyber Threat Information Sharing

This publication provides guidelines for establishing and participating in cyber threat inform...Read More

Recent IT Downloads
Trustworthy Email

This document provides recommendations and guidelines for enhancing trust in email, including ...Read More

Recent IT Downloads
Software Quality Assurance: Integrating Testing, Security, and Audit

This excerpt focuses on the conceptual aspects of defect management, including the basic conce...Read More