<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>FireBlog by FireHost &#187; eCommerce</title>
	<atom:link href="http://www.fireblog.com/tag/ecommerce/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.fireblog.com</link>
	<description>Secure Hosting Blog</description>
	<lastBuildDate>Fri, 16 Dec 2011 00:52:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Security, Speed, and Scalability for E-commerce: A Guide to Getting Started</title>
		<link>http://www.fireblog.com/security-speed-and-scalability-for-e-commerce-a-guide-to-getting-started/</link>
		<comments>http://www.fireblog.com/security-speed-and-scalability-for-e-commerce-a-guide-to-getting-started/#comments</comments>
		<pubDate>Fri, 19 Mar 2010 13:00:21 +0000</pubDate>
		<dc:creator>FireHost Evangelist</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[eCommerce]]></category>
		<category><![CDATA[PCI Compliant Hosting]]></category>
		<category><![CDATA[Secure Cloud Hosting]]></category>
		<category><![CDATA[Secure eCommerce Development]]></category>

		<guid isPermaLink="false">http://www.fireblog.com/?p=3156</guid>
		<description><![CDATA[All new E-commerce businesses should address one vital question first and foremost: Will you collect and store payment card information on your Web site or offload credit card processing to a PCI Compliant merchant like Paypal? The answer to this question is paramount and should be well thought out when you are planning and developing your E-commerce Web application.]]></description>
			<content:encoded><![CDATA[<p>All new E-commerce businesses should address one vital question first and foremost: Will you collect and store payment card information on your Web site or offload credit card processing to a PCI Compliant merchant like Paypal? The answer to this question is paramount and should be well thought out when you are planning and developing your E-commerce Web application.</p>
<p>When feasible, outsourcing the storage and handling of credit cards to a trusted, capable, and PCI compliant payment processing provider is the most secure and most budget-friendly course of action. Even when you outsource payment processing (the riskiest piece of running an E-commerce business), you still must ensure your hosting environment can deliver speed and scalability that meets user expectation and includes security measures that protect your shoppers from a damaging hacker encounter.</p>
<p>Here are the tools and services that you should be looking for:</p>
<p><em><strong>Web Hosting Security Basics – the minimum requirements you need to transact business <span style="text-decoration: underline;">securely</span> online</strong></em></p>
<p><em>Redundant firewall protection</em> &#8212; Firewalls help stop cyber attacks before they can penetrate the network perimeter. Having firewalls tuned and working in tandem helps ensure protection for your E-commerce environment.</p>
<p><em>Web application protection</em> – In addition to traditional firewalls, you’ll need a Web application firewall (we call them WAFs). This technology helps protect E-commerce organizations from application-level attacks like SQL injections and Cross Site Scripting (XSS) attacks. Application-level attacks is where the hacker is attacking the website itself; your contact forms, login boxes, etc. Traditional firewalls are helpless to these kinds of attacks and WAFs are required.</p>
<p><em><span id="more-3156"></span>DoS/DDoS mitigation</em> &#8212; (Distributed) Denial of Service attacks hit your Web site with a flood of robot-directed, fake visitors that consume all available resources, lockup your server, and take your Web site offline. DoS/DDoS mitigation devices help ward off such events by providing a barrier between your server and the IP flood.</p>
<p><em>SSL VPN (</em><em>Secure Sockets Layer virtual private network</em>) – It’s a mouthful, but it’s important to take note. SSL VPNs create a secure connection for remote users that will be administering the Web applications and hosting environment.</p>
<p><em>Vulnerability Monitoring</em> – Vulnerability monitoring services scan your Web application code around the clock looking for unexpected changes and malicious code that matches known “diseases” in the threat database. When a potential problem is uncovered, you’ll be notified so you can resolve the problem.</p>
<p><em>Antivirus protection – </em>Antivirus software works much the same way as vulnerability monitoring, however the target for AV scans is different. Rather than reviewing Web application code, Antivirus software reviews files and services stored on the physical server.</p>
<p><em>Two factor authentication</em> – 2FA requires website administrators to go thru two layers of security before obtaining access to the hosting environment. Two factor authentication helps prevent the most common cause of data theft – password leaks. Two factor is unique because it challenges you with something you know and something you have.</p>
<p><em>Encrypted backup, service monitoring and response – </em>While these protective measures are available from most Web hosting companies, they’re not ALWAYS included. Make sure you know what you’re getting.</p>
<p><strong> </strong></p>
<p><em><strong>Performance wish list – Cadillac hosting solutions that provide <span style="text-decoration: underline;">speed</span> and <span style="text-decoration: underline;">scalability</span> for for SMBs on a Camry budget:</strong></em></p>
<p><strong> </strong></p>
<p><em>High Availability</em> – The Web is the front door for your E-commerce site. When your Web site is offline, it is like bolting the door shut and surrounding your office building with caution tape. Really, it’s that serious.  This is very discouraging to online shoppers. High availability hosting helps ensure your Web site is NEVER offline, even for necessities like patching, hardware upgrades, and other required maintenance.</p>
<p><em>CDN (Content Delivery Network)</em> – CDN performs several important functions for online retailers. First, content delivery networks make Web site content available to users around the world. The service also helps ensure multi-media components (product photos, videos, demonstrations) load quickly for every user, regardless of where he/she is located. Finally, CDN provides additional throughput when your Web site receives an unexpected spike in traffic. Oprah, bring it on!</p>
<p><em>Virtualization</em> – Virtualized servers are quickly scalable, but you need to make sure they are secure. Deploying upgrades, installing patches, and migrating hardware can happen in minutes if not seconds of scheduled downtime rather than the lengthy outages synonymous with traditional dedicated hosting of the past.</p>
<p>Successful E-commerce companies will require all of these performance features at some point. Migrating your Web application is always a risky and time-consuming proposition. While you&#8217;re small and agile you should align with vendors that can:</p>
<p>1) Provide security and protection for E-commerce retailers on a budget</p>
<p>2) Provide content acceleration for E-commerce startups with rich multi-media components and/or global distribution, and</p>
<p>3) Provide scalable server resources on demand with built-in business continuity planning</p>
<p>For E-commerce startups, developing a reliable Web application and backing it with a hosting environment to ensure maximum uptime, infinite scalability, and protection from hackers can feel the like the most daunting task. Considering your long-term needs from the start can save you a world of pain, time, and money later when everything comes together, and your online business soars.</p>
<p><em>A <a href="http://www.ecommercetimes.com/story/69577.html" target="_blank">version of this article</a> appeared in eCommerce Times on March 19, 2010.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.fireblog.com/security-speed-and-scalability-for-e-commerce-a-guide-to-getting-started/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>UK Imposes Strict Data Loss Policies</title>
		<link>http://www.fireblog.com/uk-imposes-strict-data-loss-policies/</link>
		<comments>http://www.fireblog.com/uk-imposes-strict-data-loss-policies/#comments</comments>
		<pubDate>Fri, 15 May 2009 14:00:31 +0000</pubDate>
		<dc:creator>FireHost Evangelist</dc:creator>
				<category><![CDATA[Cloud Hosting]]></category>
		<category><![CDATA[Online Backup]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Application Protection]]></category>
		<category><![CDATA[Business Continuity]]></category>
		<category><![CDATA[CMS]]></category>
		<category><![CDATA[Content Management Solution]]></category>
		<category><![CDATA[CRM]]></category>
		<category><![CDATA[Customer Relationship Management]]></category>
		<category><![CDATA[eCommerce]]></category>
		<category><![CDATA[FireVault]]></category>
		<category><![CDATA[UK Data Loss Policy]]></category>

		<guid isPermaLink="false">http://www.fireblog.com/?p=949</guid>
		<description><![CDATA[Following serious breaches in data security, most notably a loss of 25 million records on two unencrypted discs from Britain's Revenue &#038; Customs, the United Kingdom is implementing strict data loss policies on governmental organizations in the UK. Although your company may not deal in national secrets, your company should consider similar measures to prevent data loss, which can prevent the loss of confidential information, trade secrets, and vital business and customer records.]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-1219" title="uk-data-loss1" src="http://www.fireblog.com/wp-content/uploads/2009/05/uk-data-loss1.jpg" alt="uk-data-loss1" width="220" height="231" />Following serious breaches in data security, most notably a <a href="http://www.computerweekly.com/Articles/2008/06/27/231267/hmrc-left-the-door-open-to-data-loss.htm" target="_blank">loss of 25 million records on two unencrypted discs</a> from Britain&#8217;s Revenue &amp; Customs, the United Kingdom is implementing strict data loss policies on governmental organizations in the UK.</p>
<p>These new strict data loss prevention measures include file encryption, digital rights management, storage policies, data classification, and new staff security procedures. For the interesting specifics, <a href="http://www.computerweekly.com/Articles/2009/04/24/235776/stamp-out-data-loss.htm" target="_blank">click here</a>.</p>
<p>Although your company may not deal in national secrets, your company should consider similar measures to prevent data loss, which can prevent the loss of confidential information, trade secrets, and vital business and customer records.</p>
<p><span id="more-949"></span></p>
<p><a href="http://www.firehost.com/" target="_blank">Protecting your business</a> online means you have consciously taken a look at the cost risk and business risk of having all your data compromised. Can you afford to have your lead-generating website down for a period of time? Is there a competitor that would benefit from knowing your company&#8217;s intellectual property? Can you afford to have your clients&#8217; entrusted data hacked and made public, or worse exploited?</p>
<p>With growing eCommerce and so many companies using Content Management Solutions and Customer Relationship Management solutions, protecting your company in its industry requires industry-leading security measures. Some advanced security measures are not found with over 90% of hosting providers including advanced web application firewalls, dynamic intrusion detection, and sophisticated traffic analysis software. Proper security hardware, software, dedicated personnel and proactive protection prevents malicious hackers from stealing information from you and your clients.</p>
<p>Another part of protecting your business online is reviewing your business continuity plan. What happens when a fire occurs in your building destroying your local computers or servers, or a natural disaster or a virus takes out a vital source of information? You can protect your records, files, and databases using <a href="http://www.firevault.com" target="_blank">FireVault</a>, which encrypts and backs up your data from any number of computers and servers to a secure, cloud sever in the U.S. or UK.</p>
<p>Be leary of hosting companies that provide only hacker reports as their measure of protection. Your business cannot afford to wait until after a breach occurs to be told there&#8217;s a problem. The damage is done. Real secure hosting protects you proactively, mitigating and eliminating attacks starting at the HTTP level against your data before they get to your servers. The consequences of inaction could be insurmountable for businesses of any size. Online threats require businesses of all sizes to ensure they <a title="Secure Web Hosting" href="http://www.firehost.com/company/contact" target="_blank">have secure web hosting</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.fireblog.com/uk-imposes-strict-data-loss-policies/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

