Project a Secure Web 2.0 (using Drupal) Paolo Ottolino PMP - - PowerPoint PPT Presentation

project a secure web 2 0
SMART_READER_LITE
LIVE PREVIEW

Project a Secure Web 2.0 (using Drupal) Paolo Ottolino PMP - - PowerPoint PPT Presentation

Project a Secure Web 2.0 (using Drupal) Paolo Ottolino PMP CISSP-ISSAP CISA CISM OPST ITIL paolo.ottolino (at) isc2chapter-italy.it May XX, 2016 Agenda Web 2.0 & CMS CMS Cyber Risk Drupal Security Agenda Web 2.0 & CMS Needs,


slide-1
SLIDE 1

Project a Secure Web 2.0

(using Drupal)

Paolo Ottolino PMP CISSP-ISSAP CISA CISM OPST ITIL paolo.ottolino (at) isc2chapter-italy.it May XX, 2016

slide-2
SLIDE 2

Agenda

Web 2.0 & CMS Drupal Security CMS Cyber Risk

slide-3
SLIDE 3

Agenda

Web 2.0 & CMS

Needs, Functionalities, Selection

slide-4
SLIDE 4

Web 2.0: Insecure by Design?

slide-5
SLIDE 5

Web 2.0 & CMS: Logical Architecture

slide-6
SLIDE 6

CMS Solution: Top 3 used products

slide-7
SLIDE 7

Most wanted CMS Functionalities…

slide-8
SLIDE 8

UK and EU Org & Biz use Drupal…

slide-9
SLIDE 9

… but also US makes strong use of Drupal!

slide-10
SLIDE 10

Full CMS Functionalities

slide-11
SLIDE 11

Agenda

CMS Cyber Risk

Threats, Vulnerabilities, Countermeasures

slide-12
SLIDE 12

CMS Threats: Security Hacking

slide-13
SLIDE 13

CMS Vulnerabilities: Open Web Application SecurityProject

slide-14
SLIDE 14

CMS Vulnerabilities: OWASP Top10

slide-15
SLIDE 15

CMS Risks: Risk-Threat-Vulnerability Map

slide-16
SLIDE 16

CMS Risks: DevOps Security Strategy

slide-17
SLIDE 17

CMS Risks: DevOps Security Strategy

slide-18
SLIDE 18

Agenda

Drupal Security

Security DevOps, Keeping Secure, Drupal 8

slide-19
SLIDE 19

Drupal Security DevOps Strategy

slide-20
SLIDE 20

Keeping Secure: CMS Patch Comparison

slide-21
SLIDE 21

Keeping Secure: Drupal actors (1/2)

slide-22
SLIDE 22

Keeping Secure: Drupal process (2/2)

slide-23
SLIDE 23

Keeping Secure: Drupal process (2/2)

slide-24
SLIDE 24

Drupal8: Cover the Lacking Functionalities…

slide-25
SLIDE 25

Drupal 8: Welcome Easiness!

slide-26
SLIDE 26

Grazie

Paolo Ottolino

PMP CISSP-ISSAP CISA CISM OPST ITIL paolo.ottolino (at) isc2chapter-italy.it