Posts Tagged ‘eCommerce’

Security, Speed, and Scalability for E-commerce: A Guide to Getting Started

by FireHost Evangelist on March 19th, 2010

All new E-commerce businesses should address one vital question first and foremost: Will you collect and store payment card information on your Web site or offload credit card processing to a PCI Compliant merchant like Paypal? The answer to this question is paramount and should be well thought out when you are planning and developing your E-commerce Web application.

When feasible, outsourcing the storage and handling of credit cards to a trusted, capable, and PCI compliant payment processing provider is the most secure and most budget-friendly course of action. Even when you outsource payment processing (the riskiest piece of running an E-commerce business), you still must ensure your hosting environment can deliver speed and scalability that meets user expectation and includes security measures that protect your shoppers from a damaging hacker encounter.

Here are the tools and services that you should be looking for:

Web Hosting Security Basics – the minimum requirements you need to transact business securely online

Redundant firewall protection — Firewalls help stop cyber attacks before they can penetrate the network perimeter. Having firewalls tuned and working in tandem helps ensure protection for your E-commerce environment.

Web application protection – In addition to traditional firewalls, you’ll need a Web application firewall (we call them WAFs). This technology helps protect E-commerce organizations from application-level attacks like SQL injections and Cross Site Scripting (XSS) attacks. Application-level attacks is where the hacker is attacking the website itself; your contact forms, login boxes, etc. Traditional firewalls are helpless to these kinds of attacks and WAFs are required.

(more…)

UK Imposes Strict Data Loss Policies

by FireHost Evangelist on May 15th, 2009

uk-data-loss1Following serious breaches in data security, most notably a loss of 25 million records on two unencrypted discs from Britain’s Revenue & Customs, the United Kingdom is implementing strict data loss policies on governmental organizations in the UK.

These new strict data loss prevention measures include file encryption, digital rights management, storage policies, data classification, and new staff security procedures. For the interesting specifics, click here.

Although your company may not deal in national secrets, your company should consider similar measures to prevent data loss, which can prevent the loss of confidential information, trade secrets, and vital business and customer records.

(more…)

© Copyright 2010 FireHost Inc. Privacy Policy Legal Information