Guidelines on Securing Public Web Servers
Figure 8.4: Outsourced Web Server Hosting
The advantages of outsourcing from a security standpoint are as follows:
DoS attacks aimed at the Web server have no effect on the organization's production
network.
Compromise of the Web server does not directly threaten the internal production
network.
Outsourcer may have greater knowledge in securing and protecting Web servers.
The network can be optimized solely for the support and protection of Web servers.
The disadvantages of outsourcing from a security standpoint are as follows:
Requires trusting a third party with Web server content.
It is difficult to remotely administer the Web server or remotely update Web server
content.
Less control can be provided over the security of the Web server.
Web server may be affected by attacks aimed at other Web servers hosted by the
outsourcer on the same network.
Outsourcing often makes sense for smaller organizations that cannot afford the necessary
expertise to support the necessary Web server staff. It may also be appropriate for larger
68