The post has been translated automatically. Original language: Russian
Placing the equipment in a reliable data center covers only part of the security issues — then the responsibility is divided between the provider and the team itself.
On the infrastructure side, it is worth clarifying: — network segmentation and isolation between clients; — availability of protection against DDoS attacks at the channel level; — backup policy on the provider's side if its managed services are used; — how to respond to security incidents and how quickly the customer learns about them.
From the side of the team itself, the basic minimum looks like this: — multi-factor authentication for access to control panels and servers; — regular software updates and patch management; — differentiation of employee access rights based on the principle of minimum necessary privileges; — data encryption during both storage and transmission; — regular testing of the backup recovery procedure is not the fact of the backup itself, but rather checking that it is actually possible to recover from it.
A separate recommendation is to fix in the document who exactly — the provider or the client — is responsible for each item. In practice, it is the unclear division of responsibility that causes incidents, not the lack of technology.
Размещение оборудования в надёжном ЦОД закрывает только часть вопросов безопасности — дальше ответственность делится между провайдером и самой командой.
Со стороны инфраструктуры стоит уточнять: — сегментацию сети и изоляцию между клиентами; — наличие защиты от DDoS-атак на уровне канала; — политику резервного копирования на стороне провайдера, если используются его managed-сервисы; — порядок реагирования на инциденты безопасности и то, как быстро клиент о них узнаёт.
Со стороны самой команды базовый минимум выглядит так: — многофакторная аутентификация для доступа к панелям управления и серверам; — регулярное обновление ПО и патч-менеджмент; — разграничение прав доступа сотрудников по принципу минимально необходимых привилегий; — шифрование данных как при хранении, так и при передаче; — регулярное тестирование процедуры восстановления из бэкапа — не сам факт наличия бэкапа, а именно проверка, что из него реально можно восстановиться.
Отдельная рекомендация: закрепить в документе, кто именно — провайдер или клиент — отвечает за каждый пункт. На практике именно нечёткое разделение ответственности становится причиной инцидентов, а не отсутствие технологий.