<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Website Security Design Resources in Welcome</title>
    <link>https://community.isc2.org/t5/Welcome/Website-Security-Design-Resources/m-p/4236#M262</link>
    <description>&lt;P&gt;Try anything and everything you can find from OWASP:&lt;/P&gt;&lt;DIV class="f kv _SWb"&gt;&lt;A href="https://www.owasp.org/" target="_blank"&gt;https://www.owasp.org/&lt;/A&gt;&lt;DIV class="action-menu ab_ctl"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="action-menu ab_ctl"&gt;They have a lot of resources, including vulnerability scanners.&amp;nbsp;The specific cases you list (setting up user accounts, username format, password reset) are fairly broad. I'd suggest you invest a little time first in studying database design, which might have an influence in all&amp;nbsp;those areas. Security is a function of quality. Build it right and you have a good chance at making it secure. Build it haphazardly and all bets are off.&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Mon, 11 Dec 2017 22:11:15 GMT</pubDate>
    <dc:creator>JoePete</dc:creator>
    <dc:date>2017-12-11T22:11:15Z</dc:date>
    <item>
      <title>Website Security Design Resources</title>
      <link>https://community.isc2.org/t5/Welcome/Website-Security-Design-Resources/m-p/4234#M261</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm trying to learn about user interactive web-design, from a security perspective.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not just the obvious things like password length and complexity, but for example...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- different methods for setting up online user accounts for existing client or customers&lt;/P&gt;&lt;P&gt;- types of username format (eg, e-mail address or site generated ID)&lt;/P&gt;&lt;P&gt;- various password reset mechanisms&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Different web-sites may have different ways of performing these functions, dependant on whether security or convenience is upmost.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are there any resources or best practices available, which outline the common scenarios and solutions?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for reading...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2017 21:50:44 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Welcome/Website-Security-Design-Resources/m-p/4234#M261</guid>
      <dc:creator>TonyDS</dc:creator>
      <dc:date>2017-12-11T21:50:44Z</dc:date>
    </item>
    <item>
      <title>Re: Website Security Design Resources</title>
      <link>https://community.isc2.org/t5/Welcome/Website-Security-Design-Resources/m-p/4236#M262</link>
      <description>&lt;P&gt;Try anything and everything you can find from OWASP:&lt;/P&gt;&lt;DIV class="f kv _SWb"&gt;&lt;A href="https://www.owasp.org/" target="_blank"&gt;https://www.owasp.org/&lt;/A&gt;&lt;DIV class="action-menu ab_ctl"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="action-menu ab_ctl"&gt;They have a lot of resources, including vulnerability scanners.&amp;nbsp;The specific cases you list (setting up user accounts, username format, password reset) are fairly broad. I'd suggest you invest a little time first in studying database design, which might have an influence in all&amp;nbsp;those areas. Security is a function of quality. Build it right and you have a good chance at making it secure. Build it haphazardly and all bets are off.&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 11 Dec 2017 22:11:15 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Welcome/Website-Security-Design-Resources/m-p/4236#M262</guid>
      <dc:creator>JoePete</dc:creator>
      <dc:date>2017-12-11T22:11:15Z</dc:date>
    </item>
  </channel>
</rss>

