Ask HN: server security intro/reference?
Last couple days I've been perusing security related posts here, and following links.
And I have to say: gaaa!
Admin/security is a firehose.
My problem is that waiting until I know that I know enough would mean that I'll never get anything done, I'll always be waiting to be better. In development the idea of waiting to learn something until you need it makes sense. In admin/security that approach can be fatal.
What I'd like to see, if you're aware of any, is a resource or resources that allow you to approach things with a strategy of layered importance. An overview of where you're going, where the details are then arranged as:
- If nothing else, do these few N things first and absolutely.
- Next, certainly do these things as soon as you can.
- Finally, for uber control and confidence, consider these.
I guess knowing how people break things down into categories and areas of focus would be helpful too.The question is mainly about server security, but if you want to throw something in about app security/integrity, and recovery from a server or app breach, that would be appreciated too.
Thanks. I think I'll go breath into a paper bag for awhile.
[edit: formatting]