project a secure web 2...started on september 9, 2001 by mark curphey, it is an online community...

26
Project a Secure Web 2.0 (using Drupal) Paolo Ottolino PMP CISSP-ISSAP CISA CISM OPST ITIL paolo.ottolino (at) isc2chapter-italy.it May XX, 2016

Upload: others

Post on 12-Jul-2020

2 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Project a Secure Web 2...Started on September 9, 2001 by Mark Curphey, it is an online community dedicated to Web Application Security. OWASP works for creating freely-available materials

Project a Secure Web 2.0(using Drupal)

Paolo Ottolino PMP CISSP-ISSAP CISA CISM OPST ITIL paolo.ottolino (at) isc2chapter-italy.it

May XX, 2016

Page 2: Project a Secure Web 2...Started on September 9, 2001 by Mark Curphey, it is an online community dedicated to Web Application Security. OWASP works for creating freely-available materials

Agenda

Web 2.0 & CMS

Drupal Security

CMS Cyber Risk

Page 3: Project a Secure Web 2...Started on September 9, 2001 by Mark Curphey, it is an online community dedicated to Web Application Security. OWASP works for creating freely-available materials

Agenda

Web 2.0 & CMSNeeds, Functionalities, Selection

Page 4: Project a Secure Web 2...Started on September 9, 2001 by Mark Curphey, it is an online community dedicated to Web Application Security. OWASP works for creating freely-available materials

Web 2.0: Insecure by Design?

Page 5: Project a Secure Web 2...Started on September 9, 2001 by Mark Curphey, it is an online community dedicated to Web Application Security. OWASP works for creating freely-available materials

Web 2.0 & CMS: Logical Architecture

Page 6: Project a Secure Web 2...Started on September 9, 2001 by Mark Curphey, it is an online community dedicated to Web Application Security. OWASP works for creating freely-available materials

CMS Solution: Top 3 used products

Page 7: Project a Secure Web 2...Started on September 9, 2001 by Mark Curphey, it is an online community dedicated to Web Application Security. OWASP works for creating freely-available materials

Most wanted CMS Functionalities…

Page 8: Project a Secure Web 2...Started on September 9, 2001 by Mark Curphey, it is an online community dedicated to Web Application Security. OWASP works for creating freely-available materials

UK and EU Org & Biz use Drupal…

Page 9: Project a Secure Web 2...Started on September 9, 2001 by Mark Curphey, it is an online community dedicated to Web Application Security. OWASP works for creating freely-available materials

… but also US makes strong use of Drupal!

Page 10: Project a Secure Web 2...Started on September 9, 2001 by Mark Curphey, it is an online community dedicated to Web Application Security. OWASP works for creating freely-available materials

Full CMS Functionalities

Page 11: Project a Secure Web 2...Started on September 9, 2001 by Mark Curphey, it is an online community dedicated to Web Application Security. OWASP works for creating freely-available materials

Agenda

CMS Cyber RiskThreats, Vulnerabilities, Countermeasures

Page 12: Project a Secure Web 2...Started on September 9, 2001 by Mark Curphey, it is an online community dedicated to Web Application Security. OWASP works for creating freely-available materials

CMS Threats: Security Hacking

Page 13: Project a Secure Web 2...Started on September 9, 2001 by Mark Curphey, it is an online community dedicated to Web Application Security. OWASP works for creating freely-available materials

CMS Vulnerabilities: Open Web Application SecurityProject

Page 14: Project a Secure Web 2...Started on September 9, 2001 by Mark Curphey, it is an online community dedicated to Web Application Security. OWASP works for creating freely-available materials

CMS Vulnerabilities: OWASP Top10

Page 15: Project a Secure Web 2...Started on September 9, 2001 by Mark Curphey, it is an online community dedicated to Web Application Security. OWASP works for creating freely-available materials

CMS Risks: Risk-Threat-Vulnerability Map

Page 16: Project a Secure Web 2...Started on September 9, 2001 by Mark Curphey, it is an online community dedicated to Web Application Security. OWASP works for creating freely-available materials

CMS Risks: DevOps Security Strategy

Page 17: Project a Secure Web 2...Started on September 9, 2001 by Mark Curphey, it is an online community dedicated to Web Application Security. OWASP works for creating freely-available materials

CMS Risks: DevOps Security Strategy

Page 18: Project a Secure Web 2...Started on September 9, 2001 by Mark Curphey, it is an online community dedicated to Web Application Security. OWASP works for creating freely-available materials

Agenda

Drupal SecuritySecurity DevOps, Keeping Secure, Drupal 8

Page 19: Project a Secure Web 2...Started on September 9, 2001 by Mark Curphey, it is an online community dedicated to Web Application Security. OWASP works for creating freely-available materials

Drupal Security DevOps Strategy

Page 20: Project a Secure Web 2...Started on September 9, 2001 by Mark Curphey, it is an online community dedicated to Web Application Security. OWASP works for creating freely-available materials

Keeping Secure: CMS Patch Comparison

Page 21: Project a Secure Web 2...Started on September 9, 2001 by Mark Curphey, it is an online community dedicated to Web Application Security. OWASP works for creating freely-available materials

Keeping Secure: Drupal actors (1/2)

Page 22: Project a Secure Web 2...Started on September 9, 2001 by Mark Curphey, it is an online community dedicated to Web Application Security. OWASP works for creating freely-available materials

Keeping Secure: Drupal process (2/2)

Page 23: Project a Secure Web 2...Started on September 9, 2001 by Mark Curphey, it is an online community dedicated to Web Application Security. OWASP works for creating freely-available materials

Keeping Secure: Drupal process (2/2)

Page 24: Project a Secure Web 2...Started on September 9, 2001 by Mark Curphey, it is an online community dedicated to Web Application Security. OWASP works for creating freely-available materials

Drupal8: Cover the Lacking Functionalities…

Page 25: Project a Secure Web 2...Started on September 9, 2001 by Mark Curphey, it is an online community dedicated to Web Application Security. OWASP works for creating freely-available materials

Drupal 8: Welcome Easiness!

Page 26: Project a Secure Web 2...Started on September 9, 2001 by Mark Curphey, it is an online community dedicated to Web Application Security. OWASP works for creating freely-available materials

Grazie

Paolo OttolinoPMP CISSP-ISSAP CISA CISM OPST ITILpaolo.ottolino (at) isc2chapter-italy.it