System wide advice
Some advice applies to the entire E-Business deployment and the infrastructure in which it operates.
Keep software up to date: One of the principles of good security practice is to keep all software versions and patches up to date. For many reasons including good security practice, move to the latest version of Autoconfig and Patch Tools (AD).
Apply Critical Patch Updates (CPUs) as quickly as possible. These contain fixes to high priority security vulnerabilities, and go through rigorous testing before their release.
Restrict network access to critical services: Keep both the E-Business application middle-tier and the database behind a firewall. In addition, place a firewall between the middle-tier and the database. The firewalls provide assurance that access to these systems is restricted to a known network route, which can be monitored and restricted, if necessary.
Follow the principle of least privilege: The principal of least privilege states that users should...