21 July 2009

Web Site Design and Architecture

The design and architecture of web sites and the supporting application software and systems is an important step in a well-managed development programme.

Photograph of roadwork barriers lying on the ground between two no-parking traffic cones

Design reviews can be used to identify security-related problems with the fundamental structure (architecture) which no amount of secure coding will solve. And, it's not just about adding network and application firewalls and intrusion protection systems (IDS)—in many cases a better (less complex, more robust) design can be achieved by considering security issues such as authentication, authorisation and integrity, and the privacy issues of data subjects themselves.

Even if you, or your development agency, don't have a formal process, you should try to build reviews into the project's requirements and ensure that software designs, architecture and data flow diagrams are itemised deliverables that require sign-off. Then any changes to these should be re-assessed, agreed and approved.

Posted on: 21 July 2009 at 09:32 hrs

Comments Comments (1) | Permalink | Send Send | Post to Twitter

Comments

Comments are filtered automatically and should appear shortly after they been checked.

It is beneficial to realise what application building components really are and not overload them with functions they weren't design to perform. It might be even better to think in abstract terms like persistence, encryption, randomness, authorization rather than cookies, SHA and session id.
A good example of achieving increased security through application design would be URL dispatchers/rewriting. In a typical LAMP setup URLs are constructed out of operating system path, which has a side effect of revealing application design. URL rewriting makes them truly universal resource locators and nothing more than that.
1 Added by Karol Kowalski Posted on 23 July 2009 at 10:29 hrs
Post a comment
Confirm acceptance and understanding of the terms of use
New posts to this thread will be sent to your email address
Web Site Design and Architecture
http://www.clerkendweller.com/2009/7/21/Web-Site-Design-and-Architecture
ISO/IEC 18004:2006 QR code for http://clerkendweller.com

Page http://www.clerkendweller.com/2009/7/21/Web-Site-Design-and-Architecture
Requested by 38.107.179.220 on Tuesday, 7 February 2012 at 21:17 hrs (London date/time)

Please read our terms of use and obtain professional advice before undertaking any actions based on the opinions, suggestions and generic guidance presented here. Your organisation's situation will be unique and all practices and controls need to be assessed with consideration of your own business context.

Terms of use http://www.clerkendweller.com/page/terms
Privacy statement http://www.clerkendweller.com/page/privacy
© 2009-2012 clerkendweller.com