Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Question for a security expert...Question for a security expert...
Previous
 
Next
New Post
3/14/2008 9:38 AM
 

I've really enjoyed reading all this input. It's given me a new level of understanding in data security. These posts have even inspired the 'higher ups' to review our security practices in all areas of our data collection and storage prompting several improvements that have been given top priority, so a huge thanks to all here.

Our company has a pretty extensive server room where we host the database servers, as far as I know we have one firewall with DMZ. The server room is physically accessible via one video monitor/ lock system and a second security door. We run dozens of apps off the db servers which is were our renewed audit of security is currently focusing to ensure integrity. Network is also being reviewed as we have a pretty extensive one.

As we get further into this I can see that it isn't a matter of just turning on CAPTCHA and inserting a SSL cert. This will be a long project of its own needing some dedicated thought and planning. I'm glad I asked here first!


Michael Emond
City of Manchester NH
www.manchesternh.gov
 
New Post
3/14/2008 9:49 AM
 

One additional option is a separate database or even server for this data.  Makes securing the SQL side easier, though not as easy in DNN and especially XMod.

FWIW, we don't take SSN's online.  When an applicant comes in for a physical interview, they need to bring SSN and proof of residency information, plus sign the application.  The online sec tion only allows them to "express an interest" and send in a resume, not "apply" for the position.  May or may not be feasible in your organization.

Jeff

 
New Post
3/14/2008 11:05 AM
 

That's actually a pretty good idea. I'll check with our hr dept to see if that's a process they'd be interested in adopting. Thanks.


Michael Emond
City of Manchester NH
www.manchesternh.gov
 
New Post
3/14/2008 2:37 PM
 

Except that it's getting to the point where an applicant will need a criminal history check, credit check, driver's license, birth certificate, passport and body cavity search just to fill in the paperwork.  :)

Jeff

 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Question for a security expert...Question for a security expert...


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out