Back

Security Skill

Enterprise website & CRM protection architecture

Preview

# Security Architecture Skill Matrix: Enterprise Website & CRM Protection

An exhaustive, technical execution blueprint for securing web applications, production content management systems, and Customer Relationship Management (CRM) databases against modern threat vectors.

---

## 1. Perimeter Defense & Infrastructure Security

```
┌────────────────────────────────────────────────────────┐
│             THE ENTERPRISE SECURITY LAYER              │
├────────────────────────────────────────────────────────┤
│ 1. Client Vector: TLS 1.3 / Strict Content-Security    │
├────────────────────────────────────────────────────────┤
│ 2. Edge Routing: Cloudflare WAF / Managed Bot Shield   │
├────────────────────────────────────────────────────────┤
│ 3. Core Gatekeeper: Identity Provider (OAuth2 / MFA)   │
├────────────────────────────────────────────────────────┤
│ 4. Data Layer: AES-256 At-Rest / TLS 1.3 In-Transit    │
└────────────────────────────────────────────────────────┘
```

### Network Edge & DNS Protections
*   **Web Application Firewall (WAF):** Route all traffic through an enterprise edge matrix (e.g., Cloudflare, Akamai). Implement active rulesets to block SQL Injection (SQLi), Cross-Site Scripting (XSS), and automated brute-force attacks.
*   **Rate Limiting Protocols:** Enforce strict request thresholds on sensitive authentication entry points (`/api/auth`, `/login`, `/crm/api`):
    *   *Threshold Target:* Maximum 5 authentication requests per IP address per 60-second window.
*   **DDoS Mitigation:** Enable persistent edge protection to automatically absorb network layer 3/4 and application layer 7 flood patterns before they impact internal servers.

---

## 2. Authentication, Authorization & Identity Management

Protecting CRM data requires absolute isolation of access vectors.

### Multi-Factor Authentication (MFA) Mandate
*   Enforce hardware-based MFA tokens (FIDO2/WebAuthn) or time-based one-time passwords (TOTP) across every single administrative, staff, and user account. Disable all fallback vector mechanisms (e.g., standard insecure SMS-based multi-factor delivery).

### Role-Based Access Control (RBAC) & Principle of Least Privilege
*   **Zero Universal Accounts:** Every individual user agent must possess unique credentials. 
*   **Strict Scope Enforcement:** Divide permissions logically matching exact role footprints:
    *   *Viewer Scope:* Read-only authorization to client metrics. No export or token generation permissions allowed.
    *   *Manager Scope:* Standard operational manipulation. Export vectors restricted.
    *   *Admin Scope:* Database configuration capabilities. Access restricted strictly to verified technical networks.

---

## 3. Application Security & Code Hardening

### Secure API Layering
*   **Token Authorization:** Protect CRM endpoints exclusively with transient JSON Web Tokens (JWT) signed using cryptographically sound algorithms (e.g., RS256) or opaque state-checked session variables.
*   **Input Validation & Sanitization:** Treat every payload argument entering the application layer as untrusted. Use parametrized SQL statements or Object-Relational Mapping (ORM) drivers exclusively to eliminate SQLi risks.

### HTTP Security Header Payloads
Inject these exact security headers directly into your edge routing configurations or server responses:

```http
Content-Security-Policy: default-src 'self'; script-src 'self' https://trusted-cdn.com; object-src 'none'; frame-ancestors 'none'; upgrade-insecure-requests;
X-Frame-Options: DENY
X-Content-Type-Options: nosniff
Referrer-Policy: strict-origin-when-cross-origin
Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
```

---

## 4. Cryptographic Standards & Data Protection

### Data In-Transit Encryption
*   Decommission legacy transport protocols (SSL v3, TLS 1.0, TLS 1.1). Enforce **TLS 1.3** as the absolute baseline minimum across all web frontends and API microservices.

### Data At-Rest Architecture
*   **Database Level Encription:** Enforce full-disk encryption using the **AES-256** standard across all storage blocks hosting user identities or transactional CRM pipelines.
*   **Cryptographic Secret Hashing:** Never store plaintext passwords. Hash credentials immediately upon entry using strong key-derivation architectures like **Argon2id** or **bcrypt** with high workload cost vectors.

---

## 5. Implementation Script (Vibe Coding Prompt Override)

When prompting your AI agent to build or update your CRM codebase, use this strict system instructions block:

```markdown
Refactor the web application server architecture and database layers to comply precisely with the Security Architecture Skill Matrix rules.

Ensure the output satisfies these technical parameters:
1. Inject standard security headers (CSP, X-Frame-Options, HSTS) into all server responses.
2. Bind authentication paths strictly to parameter-checked routes requiring valid MFA hooks.
3. Configure all relational database calls using parameterized query components or secure ORM models to isolate SQLi vulnerabilities.
4. Set up AES-256 file encryption logic for user profiles and establish Argon2id hashing algorithms for security credential fields.
5. Provide clean API rate-limiting middle-ware logic blocking brute-force attacks on sensitive endpoints.
```
GitHub
LinkedIn
Instagram