The Benefits and Security Risks of Web-Based Applications for Business by Kathleen Kotwica

The Benefits and Security Risks of Web-Based Applications for Business by Kathleen Kotwica

Author:Kathleen Kotwica
Language: eng
Format: epub
ISBN: 9780124169876
Publisher: Elsevier Science
Published: 2013-06-02T16:00:00+00:00


While the threats described above come from outsider attacks, insiders may also generate risks. Internal company wikis and blogs may contain sensitive information on product development or corporate news that should not be shared with the public. Shared links could expose such information to competitors. Outsiders hacking into an inadequately secured intranet could result in exposure as well.

Summary

The use of web-based applications in the business setting—despite the security risks outlined in this report—is not going away. Security professionals must learn to play an enabling, yet protective, role in helping their organizations utilize these applications.

A thorough risk assessment is the first step in determining how to mitigate risk to any organization. How is the organization using web-based applications? What are its assets? What are the threats to these assets? How can these threats be prioritized? The answers to these questions will help security decide which steps to take to mitigate risk, and which risks to mitigate.

Some risk mitigation strategies that businesses should implement when using web-based applications in the workplace include:

• Avoid using web-based applications for sites that will handle sensitive transactions

• Examine online traffic, both outgoing and incoming

• Deploy strong, layered network security applications

• Create a policy for network use and information protection that addresses web-based application vulnerabilities

• Educate employees on the use of internal and external web-based applications

• Purchase web-based applications with security features



Download



Copyright Disclaimer:
This site does not store any files on its server. We only index and link to content provided by other sites. Please contact the content providers to delete copyright contents if any and email us, we'll remove relevant links or contents immediately.