T
T
tartakai2021-09-21 10:53:18
System administration
tartakai, 2021-09-21 10:53:18

What are the certificates for web servers?

There is a web server with a geographic information system installed on it. Customers sometimes ask, what is its security category? We proudly answer that the first. The trouble is that we don’t have any certificates for it and the server itself is quite full of holes.
Q: Are there any web server certification programs? In order to receive a document confirming the degree of security at the end.

Answer the question

In order to leave comments, you need to log in

2 answer(s)
V
Vasily Bannikov, 2021-09-21
@tartakai

We proudly answer that the first.

Claiming a security category, knowing that you have critical vulnerabilities, and without conducting any real research (at least internal ones) is a blatant lie.
And for this, in a good way, you need to drive with pissing rags.
Q: Are there any web server certification programs? In order to receive a document confirming the degree of security at the end.

Most likely, you are interested in FSTEC certification if your system will work with state secrets and all that.
https://softline.ru/about/blog/sertifikatsiya-fste...
But there are other options:
- IS audit (if the certificate is not needed, but you need to check the security)
- PCI DSS (if you are going to accept payments)
- Certification from the FSB (if you develop information protection tools)

N
Nikolay Savelyev, 2021-09-21
@AgentSmith

We proudly answer that the first.

Now proudly state your real name and company name.
I don't hear an answer.
This is understandable - I'm afraid of Zbw e dfc ytn

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question