3 ms·
I imagine most of it will boil down to this: Follow OWASP, encrypt in motion and at rest, use key-manager appliance, implement access logging and store separat
by jefe_ 9y ago
I imagine most of it will boil down to this:
Follow OWASP, encrypt in motion and at rest, use key-manager appliance, implement access logging and store separate from systems, backups of data, define lifetime of data, physical controls to data storage facilities, access controls in system, manage multi-tenancy as the situation requires, sensible password policies / multi-factor authentication, background checks on employees, train staff on security, perform regular scans, restrict ports, intrusion detection system, penetration testing, have plans for business continuity and disaster recovery and practice implementing them, be aware when third party libraries are being used and have a policy for applying software/os patches.