Any Security Specs for Concrete5?

Permalink
Is there any documentation or some kind of outline on the things that C5 has in place to keep everything secure. Is there some kind of documentation that C5 offers describing certain measures that are taken to safeguard a website and meet common security standards? What are some steps that we could take to provide extra security to our clients' websites, their files and their databases? What does C5 do to safeguard against attacks such as SQL injections.

Thanks in advance for any advice and/or documentation you can provide.

 
adamjohnson replied on at Permalink Reply
adamjohnson
This question was addressed in the latest Ustream "Totally Random" episode:

http://www.ustream.tv/recorded/13704193...

Also check out the Security Wall add on:

http://www.concrete5.org/marketplace/addons/security-wall/...
frz replied on at Permalink Reply
frz
I'm working on a page for the site on this too.
frz replied on at Permalink Reply
frz
surefyre replied on at Permalink Reply
surefyre
Franz, is it possible to get a slightly more technical page for security, also, that can be used as part of justifications for using C5.

Stuff like Zend-ness in the core, authentication, defences against common attacks, recommended extra hardening steps, etc?

It'd defo help in my current encouraging of a large UK local authority to get C5 to the top of the list for a Wordpress platform replacement for the main site which is large and complex and has totally outgrown the limited capabilities of WP.

Cheers
G
frz replied on at Permalink Reply
frz
That's a good idea in the big picture but it might take us more than a
minute to get to it.

Meanwhile, tell em the DoD in the US has approved concrete5 for use in the
military - that should help. Also you could point out that cambridge.organd
mini.co.uk are built with concrete5 - so they're in good company.


best wishes

Franz Maruna
CEO - concrete5.org
http://about.me/frz
surefyre replied on at Permalink Reply
surefyre
Brilliant stuff, Franz, thanks as ever for the snappy response, too!

g

G

Linked In <http://uk.linkedin.com/in/guyeastwood> - G+<http://plusya.com/guy>
- Fonovation Limited <http://www.fonovation.com> - Surefyre
Design<http://www.surefyre.com>


On 12 July 2013 15:15, concrete5 Community <discussions@concretecms.com>wrote: