2 more tips for Web 2.0 security

Here are more security considerations that apply when using Web 2.0 applications.

Respect access rights
Mashups bring a new dimension of trust not always present in traditional application-integration techniques. One agency’s mashup might require access to another organization’s application. To obtain that access, the agency asks the application’s owner to provide authentication credentials. However, the agency must pursue only those access rights that have been granted to a credentialed user or else they risk a breach in trust.

Bobbie Wilbur, director of Applications Solutions at the Center to Promote HealthCare Access, which implements and operates a mashup named One-e-App, said the organization takes care to stay within the bounds of user authentication credentials it receives from other application owners. One-e-App helps low-income families use one application interface to enroll in various government health, social and other services programs.

In a mashup, the party accessing a system should “be careful to use the user permission inherent in the receiving system as a guide to what should or should not be done,” Wilbur said.

Reduce insider threats
A Web 2.0 site that’s limited to internal users and hosted on an organization’s own network still faces risk. If the site lets those users connect remotely, there should be mechanisms in place that control access.
“Some kind of access-limiting method in the account-granting process is definitely a requirement,” said Ben Greenbaum, a senior research manager at Symantec Security Response.

Organizations can go about that in different ways, including preassigning credentials — for example, hardware tokens — to remote users, he added.

In addition, steps should be taken to address the insider threat. Greenbaum said a large percentage of attacks come from insiders. He suggested that any file uploaded by a user should be scanned for viruses before it’s made available to other users.

About the Author

John Moore is a freelance writer based in Syracuse, N.Y.

The Fed 100

Read the profiles of all this year's winners.

Featured

  • Then-presidential candidate Donald Trump at a 2016 campaign event. Image: Shutterstock

    'Buy American' order puts procurement in the spotlight

    Some IT contractors are worried that the "buy American" executive order from President Trump could squeeze key innovators out of the market.

  • OMB chief Mick Mulvaney, shown here in as a member of Congress in 2013. (Photo credit Gage Skidmore/Flickr)

    White House taps old policies for new government makeover

    New guidance from OMB advises agencies to use shared services, GWACs and federal schedules for acquisition, and to leverage IT wherever possible in restructuring plans.

  • Shutterstock image (by Everett Historical): aerial of the Pentagon.

    What DOD's next CIO will have to deal with

    It could be months before the Defense Department has a new CIO, and he or she will face a host of organizational and operational challenges from Day One

  • USAF Gen. John Hyten

    General: Cyber Command needs new platform before NSA split

    U.S. Cyber Command should be elevated to a full combatant command as soon as possible, the head of Strategic Command told Congress, but it cannot be separated from the NSA until it has its own cyber platform.

  • Image from Shutterstock.

    DLA goes virtual

    The Defense Logistics Agency is in the midst of an ambitious campaign to eliminate its IT infrastructure and transition to using exclusively shared, hosted and virtual services.

  • Fed 100 logo

    The 2017 Federal 100

    The women and men who make up this year's Fed 100 are proof positive of what one person can make possibile in federal IT. Read on to learn more about each and every winner's accomplishments.

Reader comments

Please post your comments here. Comments are moderated, so they may not appear immediately after submitting. We will not post comments that we consider abusive or off-topic.

Please type the letters/numbers you see above

More from 1105 Public Sector Media Group