Document Management

Electronic Medical Records, Document Scanning, Microfilm Conversion Etc.

  Home   Sitemap   Develop Your Domain Names   

Custom Search


Best Practices Document Management Article


 

Best Practice Document For Web Server Deployment

Network filtering:

Place your web server(s) in a DMZ. Set your firewall to drop connections to your web server on all ports but http (port 80) or https (port 443).

Host based security:

Remove all unneeded services from your web server, keeping FTP (but only if you need it) and a secure login capability such as secure shell. An unneeded service can become an avenue of attack.

Limit the number of persons having administrator or root level access.

Apply relevant security patches as soon as they are announced and tested on a pre-production system.

Disallow all remote administration unless it is done using a one-time password or an encrypted link.

If the machine must be administered remotely, require that a secure capability such as secure shell is used to make a secure connection. Do not allow telnet or non-anonymous ftp (those requiring a username and password) connections to this machine from any untrusted site. It would also be good to limit these connections only to a minimum number of secure machines and have those machines reside within your Intranet.

Configuring the Web service/application:

If you must use a GUI interface at the console, remove the commands that automatically start the window manager from the .RC startup directories and then create a startup command for the window manager. You can then use the window manager when you need to work on the system, but shut it down when you are done. Do not leave the window manager running for any extended length of time.

Run the web server in a chroot-ed part of the directory tree so it cannot access the real system files.

Run the anonymous FTP server (if you need it) in a chroot-ed part of the directory tree that is different from the web server's tree.

Remove ALL unnecessary files such as phf from the scripts directory /cgi-bin.

Remove the "default" document trees that are shipped with Web servers such as IIS and ExAir.

Apply relevant security patches as soon as they are announced and tested on a pre-production system.

Auditing/logging:

Log all user activity and maintain those logs either in an encrypted form on the web server or store them on a separate machine on your Intranet, or write to "write-once" media.

Monitor system logs regularly for any suspicious activity.

Install some trap macros to watch for attacks on the server (such as the PHF attack).

Create macros that run every hour or so that would check the integrity of passwd and other critical files.

When the macros detect a change, they should send an e-mail to the system manager, write a message to logs, set off a pager, etc..

Content management:

Do all updates from your Intranet. Maintain your web page originals on a server on your Intranet and make all changes and updates here; then "push" these updates to the public server through an SSH or SSL connection. If you do this on a hourly basis, you can avoid having a corrupted server exposed for a long period of time.

Write a script to download HTML pages and check against a template, if changes are noted, upload the correct version.

Intrusion Detection:

Scan your web server periodically with tools like ISS, Nmap, Nessus or Satan to look for vulnerabilities.

Have intrusion detection software monitor the connections to the server. Set the detector to alarm on known exploits and suspicious activities and to capture these sessions for review. This information can help you recover from an intrusion and strengthen your defenses.


Somnath has been working as a Security Analyst at iViZ Techno Solutions, India and have successfully carried out numerous assignments on vulnerability assessment, penetration testing, web application security, Threat modeling, PCI DSS Compliance for various Banking sector firms, financial institutions, Govt. organizations, Defense, Software development Companies, leading BPOs and various small-mid-large industries.He holds security certifications like OSCP and CNSM.

Article Source: ArticlesBase.com

Related Best-practices-document-management Videos


Next page: Billing Software Voip


Bookmark/Share This Page:


Bookmark and Share

Custom Search

Recommended Products

Recommended Products

Recommended Products


Recommended Products

Comments

Grantfoundation
I recently came across your blog and have been reading along. I thought I would leave my first comment. I don't know what to say except that I have enjoyed reading. Nice blog. I will keep visiting this blog very often.

Alena

http://grantfoundation.net
By Alena - Website
2nd January 2010 - 12:33am

Paperless Office
It looks like some of the issues you are encountering when you file could be solved by using software to keep track of your files. You can try The Paper Tiger Filling system to help you better keep track of your files. Give it a try! We are BBB A-Rated business and are always looking for ways to help people file!
By Janet B - Website
25th January 2010 - 9:26am

Document Filing
Hi there. It looks like some of your organizational and filing needs could be solved with the use of some clever software! There are a lot of options for filing software. We do document management and filing for a living with clever twist. The Paper Tiger Filing System is a proven tool and we are ready to help you in any way we can to meet your filing needs!
By Janet B - Website
2nd February 2010 - 11:14am

PlanWell
We offer Construction Document Management and a Digital PlanRoom called PlanWell, which enables us tol manage your construction documents from the bidding process to the closeout of your project.

We organize, index, and store your digitized plans and specifications for viewing and ordering by prospective bidders. All addendums are updated to ensure only the most accurate documents are available on-line.
Only authorized users with a unique user name and password will be able to log into the plan room.
At any given time during the construction process, you will have access to the critical management reports indicating who ordered plans.

Leave a Reply

By Deirdre - Website
30th June 2010 - 1:40pm

Name:

Email:

Website URL:

Title / Subject:

Hide my email

Comments:

 


Best Practices Document Management News


The Claims Modernization Opportunity - Insurance & Technology


The Claims Modernization Opportunity
Insurance & Technology
Examples of best-practice claims technologies include analytics, fraud detection, geographic information systems (GIS), estimatics, mobile applications and ...

Read more...


Learn the secrets of successful SAP archiving - IT-Director.com


Learn the secrets of successful SAP archiving
IT-Director.com
Macro 4's solutions for application performance, document management and application availability are easy to use, fast to implement and deliver value ...

Read more...


Permalink: Best Practices Document Management | | Copyright © 2010 documentmanagement.cjfinsanewebhosting.com All Rights Reserved


Web Counter