Aerosol Posted January 13, 2015 Report Posted January 13, 2015 Security strategies? Trust - who can do what? Principle of least privilege - lock downpermissions as far as possible? Defense in depth - multi layered protectionto have fallbacks? Software updates - rule out obviousexploits in Drupal, PHP, operating system,browser etcOWASP Top 10? Open Web ApplicationSecurity Project? List of most critical securityrisks? Assessment of attack vector,weakness and impactread more: http://klau.si/sites/default/files/Cracking-Drupal-Devdays-2014.pdf Quote