A new NIST publication, called ‘Guide to Secure Web Services’ (NIST Special Publication 800-95), provides details on how to make Web 2.0 more secure while maintaining its flexible and convenient features.
The publication recommends several steps to make Web services more secure. One recommended measure for content providers is to replicate their data and services at backup sites. This would improve the availability of services in the event of denial of service (DoS) attacks intended to shut down a target website.
Another recommendation is better and more uniform logging of visitors and actions on Web sites.
The publication also outlines several existing security techniques for making web services more secure, such as adding encryption to data transmitted through XML.
The publication is free of charge and available at http://csrc.nist.gov/publications/nistpubs/800-95/SP800-95.pdf