<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: E-Commerce assignment..?</title>
	<atom:link href="http://www.kw-market.com/online-grocer/e-commerce-assignment/feed" rel="self" type="application/rss+xml" />
	<link>http://www.kw-market.com/online-grocer/e-commerce-assignment</link>
	<description>All About Internet Grocery, Healthy Buying, and Where and How to Buy Groceries Online!</description>
	<lastBuildDate>Sat, 26 Jun 2010 01:06:59 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: frazdav</title>
		<link>http://www.kw-market.com/online-grocer/e-commerce-assignment/comment-page-1#comment-3261</link>
		<dc:creator>frazdav</dc:creator>
		<pubDate>Sat, 10 Apr 2010 08:15:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.kw-market.com/online-grocer/e-commerce-assignment#comment-3261</guid>
		<description>There are many elements of a security plan for a business like this.  Here are a couple of key points that can be areas of focus for you:
1. Restrict administrative access to web and back-end application, mid-range, and database servers with password protection, Access Control Lists (ACLs), and other measures. Enable services only when required.
2. Segment web server infrastructure from other, internal, assets like databases, mail servers, LAN hardware, etc.  Utilize a DMZ architecture and permit port 80/443 access to this network zone only.
3.  Implement perimeter security measures like firewalls and intrusion detection/prevention platforms.
4. e-business is useless if the services are unavailable or slow.  Plan for high availability by implementing redundant systems with no single point of failure.  Web server load balancers and redundant infrastructure items are important components of this strategy.
5. Encryption (via SSL (https)) is a key measure for the protection of the clients of this business.
6. Retain all device and server logs.  These will assist in troubleshooting, event or intrusion investigation, and in audits.
7. Implement a patch testing and deployment procedure to limit vulnerabilities in server and device operating systems.

There is certainly a lot more to this, but this should give you a little to start with.&lt;br&gt;&lt;b&gt;References : &lt;/b&gt;&lt;br&gt;</description>
		<content:encoded><![CDATA[<p>There are many elements of a security plan for a business like this.  Here are a couple of key points that can be areas of focus for you:<br />
1. Restrict administrative access to web and back-end application, mid-range, and database servers with password protection, Access Control Lists (ACLs), and other measures. Enable services only when required.<br />
2. Segment web server infrastructure from other, internal, assets like databases, mail servers, LAN hardware, etc.  Utilize a DMZ architecture and permit port 80/443 access to this network zone only.<br />
3.  Implement perimeter security measures like firewalls and intrusion detection/prevention platforms.<br />
4. e-business is useless if the services are unavailable or slow.  Plan for high availability by implementing redundant systems with no single point of failure.  Web server load balancers and redundant infrastructure items are important components of this strategy.<br />
5. Encryption (via SSL (https)) is a key measure for the protection of the clients of this business.<br />
6. Retain all device and server logs.  These will assist in troubleshooting, event or intrusion investigation, and in audits.<br />
7. Implement a patch testing and deployment procedure to limit vulnerabilities in server and device operating systems.</p>
<p>There is certainly a lot more to this, but this should give you a little to start with.<br /><b>References : </b></p>
]]></content:encoded>
	</item>
</channel>
</rss>

