Hack Proofing your E-commerce Site: The Only Way to Stop a Hacker Is to Think Like One

The primary and most basic security tool of any organization is its security policy. The security policy is the backbone of the entire operation because it defines the rules by which business is conducted. These rules create the expected protocols to be followed by systems, applications, employees, and even clients.
Creation of the security policy is a large undertaking, but with careful attention to detail and some forethought into possible situations that could arise, it is a manageable and rewarding task. The security policy should be considered a "living document" in that it will be constantly revised and amended as new lessons are learned and as the organization evolves.
The security policy should also be used as a tool to assist with the creation, implementation, and configuration of technical tools such as firewalls, Intrusion Detection Systems (IDSs), and the like. These technological solutions should all reflect the security policy in their operation. They should be simply enforcing the rules set forth by the policy as acceptable and disallowing behaviors deemed by the policy as inappropriate.
Hopefully, the reason you're reading this book is to understand how to protect your e-commerce Web site so that your organization can profit from operating it. If there is no profit, then it's unrealistic to venture into the world of Internet commerce in the first place. This chapter focuses on creating the business policies that lead to profit by implementing security solutions for your site...