How can entrepreneurial teams protect their websites at a low cost?, How to make your own business successful

5 minutes
two hundred and eighty-one
zero

Give a brief answer.

Generally speaking, many security experts will tell you that there is no absolute security. If hackers must keep an eye on your company for a long time and have targeted penetration, few can be spared.

It's frustrating to say so. However, we can't wait for death. Even if all companies are hacked, we also hope that we can be the last one hacked. At the same time, if appropriate measures are taken, it is possible to minimize losses.

For entrepreneurial teams, the business development speed is fast, and the operation and maintenance strategy and R&D process may not be standardized, which will bring many problems to the security work. The most common are:

1. The code is updated frequently and quickly, and adding security checks is an additional burden

2. The test environment and production environment are chaotic, and the programmer, test, operation and maintenance may all have the authority of the server

3. Lack of necessary strategies and processes, resulting in many problems such as SVN permissions being given indiscriminately, leaving employees still have permissions, employees opening ports on the server at will and exposing them

The above problems have brought many difficulties to safety work, and entrepreneurial teams generally do not have full-time Safety Engineer Of the post.

According to my experience, the degree of attention that general companies attach to safety has a great relationship with whether the company has ever had a safety incident. If a company has never encountered safety problems before, it will not have any determination to invest in safety; In contrast, if a company has been attacked by hackers and caused some losses, its attitude towards security issues will turn 180 degrees.

Whether in textbooks or in my professional experience, I have identified one fact: Safe work It needs to expand from top to bottom. Numerous lessons have taught us that bottom-up security work is doomed to failure.

So how to effectively carry out safety work? The most important premise is that the company's management can attach strategic importance to security issues. If the top management itself has a strong sense of security, and even knows a lot of technical knowledge of attack or defense, the security work is often very effective and can save a lot of money.

For entrepreneurial teams, I have the following suggestions on how to carry out safety work:

1. Regularly ask a third-party security company to do Safety assessment

In this way, you can reduce the input of human costs and let more professional people do professional things at the same time.

2. Consider using open source or commercial WAF (Web application firewall), or IPS( Intrusion prevention system

The advantage of using WAF is that you can change the code as little as possible and buy time for patching. Because sometimes it is troublesome to change code, and some Third party procedures It is more troublesome to change the code of.

3. Reasonably tighten various authorities

Including database, server Application background , SVN and other permissions, which are only open to those who need to use them.

4. Properly keep all journal

It includes various application logs, Web logs, server logs, etc. Real time remote collection is required. The reason for remote collection is that some hackers tamper with logs first after intrusion.

5. Give some safety training to employees

Basic safety awareness is still needed. Hackers often call customer service or send emails to cheat. At the same time Weak password Many management backends are hacked out because of weak passwords. Programmers also need to have some basic qualities to eliminate common unsafe code writing.

6. Consider finding a reasonable and reliable security solution

The solution generally considers three aspects: code safety How to implement, how to formulate network security policies, and how to strengthen the operating system.

If you want to run the whole security system, you also need to develop a security operation strategy, such as regularly scanning websites, audit logs and codes, and developing emergency response processes.

That's about it. It says that it is almost the same as that of ordinary companies. It's really not easy to do a good job in safety. If conditions permit, you'd better recruit professional people.

Back to the original question of "low cost".

All the above points are free of charge. Regular safety assessment can be carried out by scanning Substitution, but the effect is worse. Another way to take advantage of this is to collect loopholes from the security community and give rewards. The cost is not very high, but the effect is surprisingly good.

This article is written by: Chief Editor Published on Software Development of Little Turkey , please indicate the source for reprinting: //hongchengtech.cn/blog/3155.html
Kuke_WP editor
author

Related recommendations

1 year ago (2024-02-20)

Industry Fit! Preferred element of WMS warehouse management system, wms warehouse software

Enterprise managers often think that warehouses are inefficient, high cost places, and belong to heavy asset operations. With the development of enterprise business, if the warehouse needs to be expanded in traditional ways, the cost is relatively high. At the same time, it also faces problems such as lack of operating experience. In the operation link, the process of warehouse, allocation, human resource matching and management is very complicated, and the team's professional ability is also highly required
seven hundred and eighty-three
zero
1 year ago (2024-02-19)

Supply chain billing system management (I): system overview, what are the supply chain management fees

In recent years, with the continuous development of e-commerce industry and increasing business, everyone has started to distribute goods online, and the supply chain billing system needs to manage more and more things. How to manage the billing system? The author summarizes some contents about settlement based on his own practical experience, hoping to enlighten you. After working on the warehouse management system for several years, I was transferred to work as a supplier
five hundred and fifty-six
zero
1 year ago (2024-02-19)

Multi merchant system management - store background design, what is the meaning of multi merchant classification

Simply understood, multi merchants are a large mall. The platform can manage merchants who settle in the mall. The merchants who settle in the mall have independent backstage. They can log in and add goods to the shelves by themselves, manage stores by themselves and other information functions. Then how to design the backstage of the store? Let's see the author's sharing. I hope it can help you. 1、 Introduction The backstage of the store is an important part of the e-commerce platform
six hundred and forty-eight
zero
1 year ago (2024-02-19)

Jiangyang District of Luzhou City took the lead in the city's full coverage training on domestic waste classification management regulations, Luzhou waste treatment

Source: Original Draft On January 10, the People's Congress of Jiangyang District, Luzhou City and the District Government jointly carried out a training on the regulations of the Regulations on the Classified Management of Domestic Waste in Luzhou City (the Regulations for short), and invited Lei Zhengyun, the chairman of the Legislative Affairs Committee of the Municipal People's Congress, to give a live lecture, so as to guide the comprehensive and systematic grasp of the contents and legal functions and responsibilities of the Regulations, deeply understand the specific specifications of the Regulations, and quickly set off
three hundred and seventeen
zero
1 year ago (2024-02-19)

Simeng CMS (smcms) content management system, Simeng Central Primary School

SMCMS (Simon CMS) is a content management system developed based on the microbee http rapid development framework. Product development follows the concept of simplicity, security, high concurrency and efficiency. Enterprise level web content management software for high-end users is designed to help users solve the increasingly complex and important web content creation, maintenance, publishing and response
three hundred and sixty-one
zero
1 year ago (2024-02-19)

Does the website have to install a content management system?, What apps are needed to install software on the website

1: The role of the website is to let companies or enterprises display their own windows, but also to let more customers or potential customers know their work and products. Through the website, customers can understand their products and services more intuitively, and can also provide more services to meet customer needs. 2: The role of the content management system The content management system can help
four hundred and fifty-six
zero

comment

0 people have participated in the review

Scan code to add WeChat

contact us

WeChat: Kuzhuti
Online consultation: