26
Project a Secure Web 2.0 (using Drupal) Paolo Ottolino PMP CISSP-ISSAP CISA CISM OPST ITIL paolo.ottolino (at) isc2chapter-italy.it May XX, 2016

Project a Secure Web 2 - DrupalCon · "Drupal powers twice as many federal government websites as every other CMS combined. That's more than six Drupal sites for every one WordPress

Embed Size (px)

Citation preview

Page 1: Project a Secure Web 2 - DrupalCon · "Drupal powers twice as many federal government websites as every other CMS combined. That's more than six Drupal sites for every one WordPress

Project a Secure Web 2.0(using Drupal)

Paolo Ottolino PMP CISSP-ISSAP CISA CISM OPST ITIL paolo.ottolino (at) isc2chapter-italy.it

May XX, 2016

Page 2: Project a Secure Web 2 - DrupalCon · "Drupal powers twice as many federal government websites as every other CMS combined. That's more than six Drupal sites for every one WordPress

Agenda

Web 2.0 & CMS

Drupal Security

CMS Cyber Risk

Page 3: Project a Secure Web 2 - DrupalCon · "Drupal powers twice as many federal government websites as every other CMS combined. That's more than six Drupal sites for every one WordPress

Agenda

Web 2.0 & CMSNeeds, Functionalities, Selection

Page 4: Project a Secure Web 2 - DrupalCon · "Drupal powers twice as many federal government websites as every other CMS combined. That's more than six Drupal sites for every one WordPress

Web 2.0: Insecure by Design?

Page 5: Project a Secure Web 2 - DrupalCon · "Drupal powers twice as many federal government websites as every other CMS combined. That's more than six Drupal sites for every one WordPress

Web 2.0 & CMS: Logical Architecture

Page 6: Project a Secure Web 2 - DrupalCon · "Drupal powers twice as many federal government websites as every other CMS combined. That's more than six Drupal sites for every one WordPress

CMS Solution: Top 3 used products

Page 7: Project a Secure Web 2 - DrupalCon · "Drupal powers twice as many federal government websites as every other CMS combined. That's more than six Drupal sites for every one WordPress

Most wanted CMS Functionalities…

Page 8: Project a Secure Web 2 - DrupalCon · "Drupal powers twice as many federal government websites as every other CMS combined. That's more than six Drupal sites for every one WordPress

UK and EU Org & Biz use Drupal…

Page 9: Project a Secure Web 2 - DrupalCon · "Drupal powers twice as many federal government websites as every other CMS combined. That's more than six Drupal sites for every one WordPress

… but also US makes strong use of Drupal!

Page 10: Project a Secure Web 2 - DrupalCon · "Drupal powers twice as many federal government websites as every other CMS combined. That's more than six Drupal sites for every one WordPress

Full CMS Functionalities

Page 11: Project a Secure Web 2 - DrupalCon · "Drupal powers twice as many federal government websites as every other CMS combined. That's more than six Drupal sites for every one WordPress

Agenda

CMS Cyber RiskThreats, Vulnerabilities, Countermeasures

Page 12: Project a Secure Web 2 - DrupalCon · "Drupal powers twice as many federal government websites as every other CMS combined. That's more than six Drupal sites for every one WordPress

CMS Threats: Security Hacking

Page 13: Project a Secure Web 2 - DrupalCon · "Drupal powers twice as many federal government websites as every other CMS combined. That's more than six Drupal sites for every one WordPress

CMS Vulnerabilities: Open Web Application SecurityProject

Page 14: Project a Secure Web 2 - DrupalCon · "Drupal powers twice as many federal government websites as every other CMS combined. That's more than six Drupal sites for every one WordPress

CMS Vulnerabilities: OWASP Top10

Page 15: Project a Secure Web 2 - DrupalCon · "Drupal powers twice as many federal government websites as every other CMS combined. That's more than six Drupal sites for every one WordPress

CMS Risks: Risk-Threat-Vulnerability Map

Page 16: Project a Secure Web 2 - DrupalCon · "Drupal powers twice as many federal government websites as every other CMS combined. That's more than six Drupal sites for every one WordPress

CMS Risks: DevOps Security Strategy

Page 17: Project a Secure Web 2 - DrupalCon · "Drupal powers twice as many federal government websites as every other CMS combined. That's more than six Drupal sites for every one WordPress

CMS Risks: DevOps Security Strategy

Page 18: Project a Secure Web 2 - DrupalCon · "Drupal powers twice as many federal government websites as every other CMS combined. That's more than six Drupal sites for every one WordPress

Agenda

Drupal SecuritySecurity DevOps, Keeping Secure, Drupal 8

Page 19: Project a Secure Web 2 - DrupalCon · "Drupal powers twice as many federal government websites as every other CMS combined. That's more than six Drupal sites for every one WordPress

Drupal Security DevOps Strategy

Page 20: Project a Secure Web 2 - DrupalCon · "Drupal powers twice as many federal government websites as every other CMS combined. That's more than six Drupal sites for every one WordPress

Keeping Secure: CMS Patch Comparison

Page 21: Project a Secure Web 2 - DrupalCon · "Drupal powers twice as many federal government websites as every other CMS combined. That's more than six Drupal sites for every one WordPress

Keeping Secure: Drupal actors (1/2)

Page 22: Project a Secure Web 2 - DrupalCon · "Drupal powers twice as many federal government websites as every other CMS combined. That's more than six Drupal sites for every one WordPress

Keeping Secure: Drupal process (2/2)

Page 23: Project a Secure Web 2 - DrupalCon · "Drupal powers twice as many federal government websites as every other CMS combined. That's more than six Drupal sites for every one WordPress

Keeping Secure: Drupal process (2/2)

Page 24: Project a Secure Web 2 - DrupalCon · "Drupal powers twice as many federal government websites as every other CMS combined. That's more than six Drupal sites for every one WordPress

Drupal8: Cover the Lacking Functionalities…

Page 25: Project a Secure Web 2 - DrupalCon · "Drupal powers twice as many federal government websites as every other CMS combined. That's more than six Drupal sites for every one WordPress

Drupal 8: Welcome Easiness!

Page 26: Project a Secure Web 2 - DrupalCon · "Drupal powers twice as many federal government websites as every other CMS combined. That's more than six Drupal sites for every one WordPress

Grazie

Paolo OttolinoPMP CISSP-ISSAP CISA CISM OPST ITILpaolo.ottolino (at) isc2chapter-italy.it