There should be a Web Publishing Policy in place that governs the appropriate dissemination of information on company websites, social media pages, and other public forums.
Control Type: Administrative
Control Function: Preventive
Description: Almost every organization today has websites, social media pages, and other public facing hubs that host content relating to the organization's goods and services. Publicly accessible is essential for marketing, customer communication, and maintaining good public relations. However the potential value of this content makes it a prime target for adversaries. An adversary will often perform passive reconnaissance on an organization's public facing platforms to gather intelligence with which to formulate attacks. If web services are unsecured, threat actors can launch attacks that take advantage of vulnerabilities to cause destruction to the Internet platforms and even pivot into other digital assets:
Common web based attacks include:
- Website defacement
- Directory traversal
- SQL injection
- Cross-Site Scripting (XSS)
- XML injection
As a first line of defense for protecting an organization's data online, there should be a web publishing policy in place that governs the dissemination of any data relating to the organization.. This will not fully prevent threat actors from taking advantage of vulnerabilities in web services, but it will help eliminate potentially sensitive information from the organization's digital footprint.
Content that should not be published online includes:
- Any internal, confidential, or restricted business data.
- Protected Health Information (PHI)
- Details on business security controls
- Very specific details on hardware and software platforms used in the business environment
- Information that hints at present vulnerabilities in digital infrastructure
- Internal business policies and procedures
- Plans, blueprints, diagrams, and photographs of the business's physical property and assets
- Personally Identifiable Information (PII) about employees, customers, or other stakeholders. Contact information for employees should be limited to their name, business phone number/email address. No personal contact information of any kind should be connected with business webpages.
- Information on the composition or preparation of hazardous materials or toxins
- Sensitive information relating to homeland security
- Information related to government contracts
- Schedules and associated locations of internal business events
- Investigative records
- Financial records that have not been published and are not expected to be
- Policies and procedures regarding emergency response, disaster recovery, and business continuity
- Copyrighted material without the explicit permission of the owner
A Web Publishing Policy should contain the following:
- List of information that is restricted from online dissemination.
- Scope of the policy, including what constitutes company data and what constitutes a public forum.
- Target audience (primarily employees that manage or interact with public facing platforms, such as webmasters, multimedia creators, social media managers, and customer service representatives).
- Specific ramifications of non-compliance, both external and internal.
- Roles and responsibilities for ensuring compliance with the policy.
- Procedures for vetting information before online publishing
- Points of contact for questions or concerns regarding any aspect of the policy
