00:01
See, first we are going to see here authentication system implement a single sign on sso solution to simplify and centralize authentication for all systems.
00:22
Use multi -factor authentication for all users especially for those with access to sensitive data.
00:31
Then external website security use https with a valid ssl certificate for secure communication.
00:52
Regularly update and patch the web server and application.
00:56
Implement a web application firewall to protect against common web attacks.
01:05
Conduct regular vulnerability assessments and penetration tests.
01:10
Then internal website security restrict access to the internal internet website to authorize employees only.
01:26
Use https with a valid ssl certificate for secure communication.
01:31
Regularly update and patch the web server and application.
01:36
Implementation of waf to protect against common web attacks.
01:41
Then secure remote access for engineering employees.
01:57
Here implement a virtual private network solution for secure remote access.
02:10
Require mfa for vpn access.
02:18
Limit remote access to necessary resources only.
02:23
Then firewall and basic rules recommendations.
02:37
Implement a next generation firewall intrusion prevention system capabilities.
02:51
Configure firewall rules to allow only necessary traffic and block all other traffic and then regularly review and update firewall rules.
03:07
Then wireless security use wvpa3 encryption for wireless network separate guest and employee wireless networks.
03:21
Implement a network access control solution to ensure only authorized devices can connect to the network.
03:28
Then vlan configuration recommendations.
03:36
Segment the network into separate vlans for different departments and functions...