Security Skill
Enterprise website & CRM protection architecture
Preview
# Security Architecture Skill Matrix: Enterprise Website & CRM Protection
An exhaustive, technical execution blueprint for securing web applications, production content management systems, and Customer Relationship Management (CRM) databases against modern threat vectors.
---
## 1. Perimeter Defense & Infrastructure Security
```
┌────────────────────────────────────────────────────────┐
│ THE ENTERPRISE SECURITY LAYER │
├────────────────────────────────────────────────────────┤
│ 1. Client Vector: TLS 1.3 / Strict Content-Security │
├────────────────────────────────────────────────────────┤
│ 2. Edge Routing: Cloudflare WAF / Managed Bot Shield │
├────────────────────────────────────────────────────────┤
│ 3. Core Gatekeeper: Identity Provider (OAuth2 / MFA) │
├────────────────────────────────────────────────────────┤
│ 4. Data Layer: AES-256 At-Rest / TLS 1.3 In-Transit │
└────────────────────────────────────────────────────────┘
```
### Network Edge & DNS Protections
* **Web Application Firewall (WAF):** Route all traffic through an enterprise edge matrix (e.g., Cloudflare, Akamai). Implement active rulesets to block SQL Injection (SQLi), Cross-Site Scripting (XSS), and automated brute-force attacks.
* **Rate Limiting Protocols:** Enforce strict request thresholds on sensitive authentication entry points (`/api/auth`, `/login`, `/crm/api`):
* *Threshold Target:* Maximum 5 authentication requests per IP address per 60-second window.
* **DDoS Mitigation:** Enable persistent edge protection to automatically absorb network layer 3/4 and application layer 7 flood patterns before they impact internal servers.
---
## 2. Authentication, Authorization & Identity Management
Protecting CRM data requires absolute isolation of access vectors.
### Multi-Factor Authentication (MFA) Mandate
* Enforce hardware-based MFA tokens (FIDO2/WebAuthn) or time-based one-time passwords (TOTP) across every single administrative, staff, and user account. Disable all fallback vector mechanisms (e.g., standard insecure SMS-based multi-factor delivery).
### Role-Based Access Control (RBAC) & Principle of Least Privilege
* **Zero Universal Accounts:** Every individual user agent must possess unique credentials.
* **Strict Scope Enforcement:** Divide permissions logically matching exact role footprints:
* *Viewer Scope:* Read-only authorization to client metrics. No export or token generation permissions allowed.
* *Manager Scope:* Standard operational manipulation. Export vectors restricted.
* *Admin Scope:* Database configuration capabilities. Access restricted strictly to verified technical networks.
---
## 3. Application Security & Code Hardening
### Secure API Layering
* **Token Authorization:** Protect CRM endpoints exclusively with transient JSON Web Tokens (JWT) signed using cryptographically sound algorithms (e.g., RS256) or opaque state-checked session variables.
* **Input Validation & Sanitization:** Treat every payload argument entering the application layer as untrusted. Use parametrized SQL statements or Object-Relational Mapping (ORM) drivers exclusively to eliminate SQLi risks.
### HTTP Security Header Payloads
Inject these exact security headers directly into your edge routing configurations or server responses:
```http
Content-Security-Policy: default-src 'self'; script-src 'self' https://trusted-cdn.com; object-src 'none'; frame-ancestors 'none'; upgrade-insecure-requests;
X-Frame-Options: DENY
X-Content-Type-Options: nosniff
Referrer-Policy: strict-origin-when-cross-origin
Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
```
---
## 4. Cryptographic Standards & Data Protection
### Data In-Transit Encryption
* Decommission legacy transport protocols (SSL v3, TLS 1.0, TLS 1.1). Enforce **TLS 1.3** as the absolute baseline minimum across all web frontends and API microservices.
### Data At-Rest Architecture
* **Database Level Encription:** Enforce full-disk encryption using the **AES-256** standard across all storage blocks hosting user identities or transactional CRM pipelines.
* **Cryptographic Secret Hashing:** Never store plaintext passwords. Hash credentials immediately upon entry using strong key-derivation architectures like **Argon2id** or **bcrypt** with high workload cost vectors.
---
## 5. Implementation Script (Vibe Coding Prompt Override)
When prompting your AI agent to build or update your CRM codebase, use this strict system instructions block:
```markdown
Refactor the web application server architecture and database layers to comply precisely with the Security Architecture Skill Matrix rules.
Ensure the output satisfies these technical parameters:
1. Inject standard security headers (CSP, X-Frame-Options, HSTS) into all server responses.
2. Bind authentication paths strictly to parameter-checked routes requiring valid MFA hooks.
3. Configure all relational database calls using parameterized query components or secure ORM models to isolate SQLi vulnerabilities.
4. Set up AES-256 file encryption logic for user profiles and establish Argon2id hashing algorithms for security credential fields.
5. Provide clean API rate-limiting middle-ware logic blocking brute-force attacks on sensitive endpoints.
```