Protecting information.
WHAT TO USE FOR EVERY CONNECTION
Encryption, throughout, without exception.
WHY THROUGHOUT
A single unencrypted request can expose a session.
WHAT TO CONFIGURE
Redirection of unencrypted requests A policy instructing browsers to use encryption only Current protocol versions and configurations
WHAT TO MONITOR
Certificate expiry.
WHY
Automated renewal fails silently more often than expected, and expiry causes a complete outage.
WHAT TO ENCRYPT AT REST
Anything sensitive, and backups, which contain everything.
WHAT TO NEVER STORE
Card numbers Passwords in recoverable form More personal data than you need
WHAT TO MINIMISE
What you collect.
WHY
Data you do not hold cannot be exposed.
WHAT TO DEFINE
Retention periods, and apply them.
WHAT TO PROTECT
Database credentials and keys, outside the code and outside version control.
WHAT TO DO IF A SECRET WAS EVER COMMITTED
Rotate it, assuming compromise.
WHAT OBLIGATIONS MAY APPLY
Those relating to personal data. Take advice on your position.