Guidelines on Securing Public Web Servers
compromise a host or network. Effective security solutions recognize no silver
bullet exists for information system security.
Work Factor
Organizations should understand what it would take to break the
system or network's security features. The amount of work necessary for an attacker
to break the system or network should exceed the value that the attacker would gain
from a successful compromise.
Compromise Recording
Records and logs should be maintained so that if a
compromise does occur, evidence of the attack is available to the organization. This
information can assist in securing the network and host after the attack and assist in
identifying the methods and exploits used by the attacker. This information can be
used to better secure the host or network in the future. In addition, this can assist
organizations in identifying and prosecuting attackers.
8