THANK YOU FOR SUBSCRIBING
Enterprise Security Magazine | Thursday, February 17, 2022
All developing technologies come with their own security vulnerabilities in a world of decentralized record-keeping. To reduce the risk, businesses must adopt best practices
Fremont, CA: Individuals must take increased responsibility for their online security in a world of distributed record-keeping and decentralized applications, and organizations must neutralize dangers that extend far beyond their own walls and intellectual assets. This starts with a security attitude in both cases. Security leaders must strike a balance between a technology-agnostic approach to security strategy and a comprehensive understanding of the threats that new tools or architectures enable.
Businesses should implement the following blockchain-specific mitigations:
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Blockchain specific governance
Determine how new users or organizations join or leave the network, as well as techniques for removing bad actors, managing faults, protecting data, and resolving inter-party conflicts. Frameworks for guiding design decisions and incorporating compliance regimes should also be included.
On-chain vs. off-chain data security
Although data reduction is a general best practice for identifying what data is stored on-chain, sidechains, hash data, data in transit, cloud storage, and so on, all require additional security precautions.
Smart contracts
Smart contracts, also known as chaincode, are blocks of code in a blockchain that initiate transactions based on predetermined criteria. They present a new point of vulnerability because their integrity determines the operation's reliability and the findings' credibility.
Blockchain application security
On the blockchain, applications are how data and many use cases are accessed. They're a weak spot that should be protected with strong user authentication and endpoint security. This may involve different levels of access that could alter over time in permissioned blockchains, where access and use are just open to vetted or known users.
Trusted third party and auditors
Only trustworthy parties should undertake security assessments, penetration tests, and audits of smart contracts, source code, and blockchain infrastructure. Use these to protect against emerging dangers like cryptographic algorithm compromises and to prepare for new attack types and automated agents.
More in News