DrupalCon Barcelona 2015: Defense in Depth: Lessons learned securing 100,000 Drupal Sites
About this talk
This talk addresses the complexities of website security in light of vulnerabilities like Heartbleed, Shell Shock, and Drupalgeddon. The speaker examines security from multiple angles, emphasizing the importance of protecting every component of the software stack, from the operating system to JavaScript. Key topics include the security triad of Confidentiality, Integrity, and Availability, evaluating hosting options, and securing software configurations, specifically for Nginx, Apache, and Drupal. The session also covers best practices for password security, data encryption, and management of personally identifiable information (PII), along with real-world scenarios to illustrate effective mitigation strategies. This presentation is a follow-up to a previous session at Drupalcon Los Angeles.