Get Support Now    |     Purchase Support Hours    |     Contact Us
  Search
10 Simple Things that make any DNN site better

Get our PDF tutorial "10 Things" we think will make lots of DNN sites better. Its a great list that includes "how we do it" for all 10!

Email:

Get DotNetNuke Support
Guaranteed DNN help

Guaranteed? You bet! If you're not happy with our work give Don Bishop a call at 717.718.1208 x101. If we can't remedy the situation we'll refund your money.  It’s that simple. Guaranteed!

Need Support Right Now?
If you want to contact us immediately, give us a call.

717.718.1208

E-Commerce Website Security

Posted By: Todd Bollinger on 10/03/2011

E-Commerce is short for Electronic Commerce and refers to the buying and selling of products and services over the Internet or other networks.  An increasing number of businesses have created e-commerce websites due to the rising popularity of using the Internet to make online purchases.

But also increasing is the risks of running a e-commerce website for a business; new ways to infiltrate and steal customer information from e-commerce websites are contently being discovered.

Security Threats to E-Commerce

  • Web site vandalism or defacement
  • Denial of service attacks
  • Theft of customer information
  • Theft of intellectual property
  • Sabotage of data or networks
  • Financial fraud, Consumer Fraud
  • Forgery, illegal interception
  • Commercial/Corporate Espionage

The first step toward reducing the risk of e-commerce security threats is to identify the vulnerable areas where security threats can happen.  The main vulnerable areas for a website are: Hardware Security, Software Security, and Environment Security. 

Hardware Security

Hardware security includes any devices used in running the e-commerce website like network devices and servers. Protecting the network with a properly configured firewall device that is only allowing ports needed for accessing the e-commerce website is an essential part of network security.  Servers used in hosting the website such as the web server and database server should be isolated from other networks using a network DMZ to reduce possible intrusion from compromised computers on other networks behind the firewall.

Software Security

Software security includes any software used in running the e-commerce website such as the operating system, web server software (IIS, Apache) and database software.  The operating system should be configured for security through the process of operating system hardening.  Software should be contently be kept updated as patches are routinely released to fix holes in security.  The website itself should be hardened against common attacks like cookie poisoning, hidden-field manipulation, parameter tampering, buffer overflow, and cross-site scripting.  Website pages, where sensitive information like credit card numbers are being entered, should be encrypted and secured with an SSL certificate.

Enviroment Security

Environment security is the area around the hardware running the e-commerce website and includes human resources.


 

Secure physical access to network and server devices by using fences, locks, or other methods. Network, server, and software access credentials should be highly complex and well guarded (no post-it notes).

Once a staff member has left the company or moved to a different position, remove all access privileges for that person that is no longer needed.  Staff members should also be trained against social engineering where sensitive information could be given to attackers posing as a trustworthy person over the phone or email.


3rd Party Hosting

If your e-commerce website is hosted by a 3rd party, contact them and discuss all of the security areas to see if they are in place.

Security is Ever Ongoing
 
The security threats to E-Commerce websites are constantly changing as new threats are discovered every day.  To stay secure takes an ongoing dedication to monitor and make adjustments to security for all of the main vulnerable areas.  It's better to be over prepared against possible security threats, then under prepared and losing your customer's trust in your company when an attack occurs.

 

Comments
Your Name:
Your eMail Address:
Your Comment:
CAPTCHA image
Enter the code shown above in the box below

Contact Spiffy For DNN Support!

If you need DotNetNuke support contact us to talk about your site. No obligation!  Click here to get DNN support now. 

Spiffy Web Team
4 Kent Rd Ste. 200
York, PA 17402
Phone: 717.718.1208
Toll Free: 800.932.3380
Fax: 717.600.2341

Follow Spiffy!

Follow us on Twitter, Facebook and YouTube to get updates when we post great new blog entries and new videos that can help you learn about DotNetNuke! We also throw in a few great downloads and specials offers ever now and then too, there's no downside!

            

Copyright 2009-2011 Affinigent, Inc.
Site Map    |     Terms of Service    |     Link to Us    |     Homepage    |     Mobile Site    |     Login
Follow Us on Facebook, Twitter and You Tube