How to keep data secure on a Windows 2003 web server
Posted on 2006-07-11
We have a Windows 2003 web server hosting IIS and Apache.
We access it via a terminal service session
We will need to store sensetive data on this first server and then send it out via ISDN
One option is to add a second server which will retain the data sent to it from the first server and have a one way communication via secure VPN, this seems a bit overkill to keep data secure and we'd want this second server to be a disaster recovery for the first. This may cause all sorts of complications like how do we access this second server for maintenance, how does it kick in while still being secure etc
I think we should remove terminal services add secure VPN connections and then add users accounts
for each user (As apposed to one shared account for every administrator).
Then add an account that only has access to this data and only two people know the details of.
Please advise on different setup methods to achieve the best solution using the best technologies.
We must have this data as secure as possible and try to keep it on the web server.
Any advise on securely backiing up this data would also be appreciated.