DrupalCon Los Angeles 2015: Defense in Depth: Lessons learned securing 100,000 Drupal Sites
About this talk
This talk addresses the essential strategies for securing websites in light of various vulnerabilities such as Heartbleed, Shell Shock, and Drupalgeddon. The speaker begins with an overview of the risks related to website security, emphasizing the need for a comprehensive approach that encompasses both the operating system and JavaScript. The session also delves into best practices for security, including compliance and risk management, the security triad of confidentiality, integrity, and availability, as well as evaluating hosting options. Key topics discussed involve securing operating systems, configuring Nginx and Apache, understanding the security of contributed modules in Drupal, and employing effective measures against DDoS attacks. Additional focus is placed on data encryption, key management, protection of personally identifiable information (PII), and user password security practices.