Securing your system
The following highlights simple steps you can take to increase the security of your Apteco system.
Secure your connections¶
Use HTTPS on your web server¶
Using HTTPS (Hypertext Transfer Protocol Secure) is one of the first things you can do to increase the security of your system. When you enable HTTPS, it encrypts all traffic between the FastStats Server and the user's application, including user IDs, passwords, and job requests. Additionally, if you purchase a site certificate instead of self-certifying, it guarantees users that the site they're connecting to is yours.
How to use a secured web service¶
When you use HTTPS, it's not necessary to have authenticated users access the web service. You can permit anonymous access instead.
You will need to:
- Obtain an SSL certificate
- Install the certificate on site
- Set IIS to require SSL
Identify users¶
- Define a required password structure, for example: minimum 10 characters with at least 1 numeric character.
- Apply a maximum session length, for example: 10 minutes.
- Apply an inactivity timeout period, for example: 10 minutes.
Define appropriate user rights¶
-
Export / Browse / Copy & Paste: You can control which variables users can select, view, and export from a system. You can also prevent users from copying and pasting data to a separate application.
-
Determine which functions are available: It may not be necessary for the full functionality of the application to be available to all users.
-
Determine what tables / columns / rows are available: In a multi-source data system, it may not be necessary for all users to be able to access, view, and extract all data. FastStats lets administrators control data access by table, column, and row.
-
Restrict administrator rights: You can assign user rights through either the Administrative Web Pages or the Tools available within the FastStats application.
Encrypt sensitive data¶
Encrypt text fields in the system¶
Encrypting text variables provides an additional layer of security for sensitive data if an attacker compromises the build, web, or system host server. If someone reads the data files of the encrypted variables, they're unintelligible. It's impossible to use encrypted variables in a selection. If you need the variables for selection purposes, you should create and use a coded version instead. Encrypting text variables also renders them non-readable in a data grid, preventing over-the-shoulder data compromise.
Require encrypted, password-protected, zipped file downloads¶
Upon export, the system automatically decrypts encrypted variables before transfer. For this reason, if you have data sensitive enough to require encryption, you should also require password-encrypted, zipped file transfers. You can find this setting in the Security tab within the system's web service configuration.