Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

'Security overview for web sites' page suggestions #1013

Open
galund opened this issue Mar 4, 2025 · 0 comments
Open

'Security overview for web sites' page suggestions #1013

galund opened this issue Mar 4, 2025 · 0 comments

Comments

@galund
Copy link
Contributor

galund commented Mar 4, 2025

Some suggestions/critique regarding the security overview for web sites page:

general:

  • there's a lot on this page, and in some cases the info could be better put on a more specific page (that may or may not exist yet)
  • we should think about who we expect to be using this page, and when, in the development lifecycle

Specific:

Points 2 and 3 are about DNS and we have a page about DNS - tweaks in progress at the moment: we could move this guidance in there

point 2 - written quite generically, but can we not write specific guidance about how to configure Route 53?

point 7 seems to have a non-sequitur about access control in a point about CDNs (which is a really good point, but with point 8 could definitely live in a whole page about serving static assets properly)

point 14 re having a cut-down backup static origin: as far as services GDS will build is concerned, ISTM this is likely only to be worthwhile for GOV.UK proper, but maybe I'm having an imagination failure

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant