|
 |
| |
Authentication
and Authorization |
| |
Access Control |
| |
- role-based access,
- object-level access
|
| |
Federated Identity Management |
| |
Policy-based Provisioning |
 |
|
 |
|
Intrusion
Detection Systems/Intrusion Prevention
Systems (IDS/IPS) |
| |
|
| |
Firewalls |
| |
OS Hardening |
 |
|
 |
| |
Securing Web
Applications |
| |
- Intelligent Risk Assessment
- Policies
- Platform Research, Modular Architecture
& Delegation (Layering)
- Input Validation (to prevent
cross-site scripting attacks)
- Vigilance
|
| |
Securing Database Access |
| |
- Use of Bind Variables in Dynamic
Queries (to prevent SQL injection)
- Use Functions, Stored Procedures
and Packages in place of stand-alone
SQL statements embedded in application
code
- Timely Deployment of Vendor-supplied
Hot Fixes and Patches
- Monitoring Audit and Event Logs
|
 |
|
 |
| |
Emphasis on
24/7 availability |
| |
- Project plan for loss of critical
infrastructure, critical application
- Backups
- Failover
|
 |
|