Find White Papers
Home
About Us
List Your Papers
    
> Clearswift > 10 Steps to Web Security

10 Steps to Web Security

White Paper Published By: Clearswift

This short guide summarizes ten steps to web security. Do them all, and you'll be better protected than 98% of enterprises out there. But the target never stands still. More than the steps listed here, it's important to focus on the principles behind the steps, including: policy, vigilance, simplification, automation and transparency.



Tags : 
clearswift, web security, internet security, security

Clearswift
Published:  Jun 09, 2008
Type:  White Paper
Length:  14 pages

Essential Steps to
Web SecurityA Clearswift Best-Practice GuideIntroduction
Web 2.0 brings Threat 2.0.
The web is changing fast from a one-way medium for 'brochure-ware' to a highly interactive, sophisticated and increasingly mission-critical platform.
The new, 'Web 2.0' applications - from social networking to tagging, blogging and presence-aware services like IM - reflect the new web-enabled relationships forming between individuals and enterprises.
But each new development of the web brings with it a new species of parasite. Spyware, adware, keyloggers, blogspam and IM viruses seem to sprout up within days of any new trend.
Clearly, it's never been more important to protect your enterprise from the hazards of uninhibitedbrowsing.
This short guide summarizes ten steps to web security. Do them all, and you'll be better protected than 98% of enterprises out there. But the target never stands still. More than thesteps listed here, it's important to focus on the principles behind the steps, including: policy, vigilance, simplification, automation and transparency.
Putting these principles into action starts with the steps listed here. But it can never end there.At Clearswift, we invest massive resources into staying on top of every emerging Internet-bornethreat. Keep in touch and we'll keep you up to date.Step 1
Policy, policy and policy.
All web security muststart with policy.
 Policy focuses your attention -on thethings you need to stop and the things you'rehappy to allow
 Policy drives up compliance -when everyone understands what's unacceptable,responsible web use becomes the norm
 Policy enforces fairness - by making therules clear to all
 Policy facilitates prosecution -of the guilty and defense against regulations demanding due diligence
It's not difficult: create a sensible policy; make sure everyone understands and agrees with it;and enforce it with technology at every gateway.
MIMEsweeper web security products enforce your web security policy by filtering all webtraffic in both directions. Any traffic that breaches policy is automatically blocked and areport or alert is generated.Step 2
Now fine tune the policy.
When it comes to policy, one size does not fit all. Your policy should reflect the way you do business. A music company may allow all MP3 files while an engineering department may needto upload and download CAD files.
For most companies, these basic web rules are fairly fundamental:
 Block viruses Prevent and log Spyware call home activity Disable executables Only allow ActiveX from trusted sites Forbid intolerant content (e.g. racial, sexual or religious discrimination) Prevent access to inappropriate sites (e.g. porn and gambling sites) Inhibit loss of confidential or sensitive data
After this kind of thing, policy becomes highly tailored. You may want to allow certain departments or individuals specific privileges while denying them to the rest of the organization.
Or you may want to set times of day when certain activities are allowed (e.g. web shopping during lunch breaks). Or identify specific files that must never be uploaded or sent out throughwebmail.
The point is this: your policy should dictate your technology, not the other way around. If your filtering tools don't let you do what you want to do, find better tools.
MIMEsweeper offers the most granular policy management in the industry. We pioneeredpolicy-based content security and still lead the way.Step 3
Attack spyware from multiple angles.
Spyware is one of the more insidious (and annoying)web hazards. Fight it from three directions:
 Stop it at the gateway - with automated filtering and spyware profiling
 Stop it at the desktop - by scanning regularly to eradicated embedded spyware
 Stop it 'calling home' - so newly installedspyware can't get back to base for instructions
The MIMEsweeper Web Appliance uses Aluria spyware profiles to stop spyware at thegateway. Spyware downloads and call-homes are blocked by the MIMEsweeper Web Appliance using Aluria's anti-spyware and the award-winning MIMEsweeper content filtering technology.Step 4
Block undesirable URLs.
Millions of dubious websites spring up daily. You can'tkeep track of them all. But we can.
Use a comprehensive URL filter to... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search