Zion security
  • zion security blog
  • Whitepapers
  • zion university - training for your company
Request free ScanSafe trial
 
 

Selecting a secure open source content management system

 

Authors:

Christophe Joos – Sales & Marketing Manager – christophe.joos@zionsecurity.com

Erwin Geirnaert – CEO & Co-founder – erwin.geirnaert@zionsecurity.com

Maarten Aerts – Software Security Expert – maarten.aerts@zionsecurity.com

© ZION SECURITY 2009

All trademarks used are properties of their respective owners.

Foreword

When people come to me for advice on CMS’s, the most recurrent question nowadays must be “What content management solution would you propose?”.

And as a matter of fact, selecting an open source CMS can be a tough call. Web agencies, as Emakina, must take into account a wide range of requirements, meeting the specific and varying needs of their top tier clients.  Among those, security has become a mandatory requirement a client even no longer needs mentioning. So there’s little or no room for error.

As we have learned to protect our houses and real life environment for thieves and burgles, the same is applicable for the web. The web has always been vulnerable for attacks. And alongside with the new possibilities the web has to offer, the hackers constantly improve their techniques, which have become quite sophisticated.

I would like to emphasize that one must remain aware of the fact that open source solutions are more prone to attacks then other solutions.  There is a higher degree of vulnerability as the code can be accessed by anyone, giving hackers the opportunity to fully analyze the core of the application. Therefore constant vigilance is required and fast and regular security patches are indispensible for the CMS one chooses.

The issue of security and open source CMS is something we consider as quite important at Emakina and is something that requires some extra attention, so this white paper should be mandatory reading for anybody involved in CMS selection, -development and -usage.

I hope this white paper can be an eye-opener and valuable aid for you too.

Adrien Fonzé – Drupal Expert at Emakina

 

 
whitehat     Splunk F5 scansafe     Trusteer     qualys