11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Checklist: Securing Data Access 719Exception ManagementCheck DescriptionADO.NET exceptions are trapped <strong>and</strong> logged.Database connections <strong>and</strong> other limited resources are released in case of exception orcompletion of operation.ASP.NET is configured with a generic error page using the element.Deployment ConsiderationsCheck DescriptionFirewall restrictions ensure that only the SQL Server listening port is available on thedatabase server.A method for maintaining encrypted database connection strings is defined.The application is configured to use a least-privileged database login.SQL server auditing is configured. Failed login attempts are logged at minimum.Data privacy <strong>and</strong> integrity over the network is provided with IPSec or SSL.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!