Ziemlich oft we come across businesses especially Start-ups and SMEs who have no control over their digital assets. Purely because it was created by an employee whose no longer with the organization, or was not handed over back to the company’s digital silo, causing an impact on time, costs and control for the business , and at times posing bottlenecks during very crucial situations when a change is needed. For business, time is money and anything that may make you lose time, in effect is CRITICAL. The motivation and purpose of writing this article, is driven from this need, to define a “Hygiene Checklist for Managing Digital Assets” , so that you as a business do not make the same mistake and can be better equipped for the same.
Since the context of Digital Assets can be huge, let me stick to the ones that pertain to the web and mobile applications that you run, and lets keep aside any other digital assets for the time being such as IT assets, digital physical assets etc.
Welche digitalen Assets werden von Webanwendungen verwendet und wie lässt sich der Besitz dieser Assets am besten verwalten? Welche Fragen sollten Sie als Geschäftsinhaber wissen, wenn Sie diese digitalen Assets besitzen, und welche Dos and Don'ts gelten hier?
- Hosting und DNS
Your app can be hosted in a shared hosting environment like GoDaddy, or a dedicated affordable VPS hosting like Contabo, DigitalOcean or Linode, or a cloud environment like AWS Ec2 or Azure. Whichever environment it is, its important that the ROOT account of hosting is under the ownership of a common business email, with 2-factor authentication linked to a mobile number that belongs to the business. The stakeholders of the business should get ALL notifications from the hosting account at all times, because if there are billing failures for consecutive 3 months your account can be terminated, or the data deleted and its a HUGE risk. Basically the email configured here has to be MONITORED at all times, and the data is too critical if you fail to do so.
And as important as the control on hosting, is the control on the DNS or domain name provider (Could be GoDaddy, a well-known domain naming platform, Mercaba or any others). The primary account with the domain registrar must be under the common business email, including the mobile number linked to it for 2-factor auth. The notifications for expiry of domain names must be set correctly so that you get timely alerts, and has to be tracked to avoid unexpected downtimes or outages.
- Ihre Webanwendung und API-Schnittstellen
Die Webanwendung befindet sich in Ihrer Hosting-Umgebung, es ist jedoch wichtig, dies zu wissen
- Wie viele Instanzen führen Sie aus und wie viele Instanzen werden Ihnen in Rechnung gestellt?
- Was ist der technische Stack, den jede Instanz ausführt, z. B. wenn dies der Fall ist? PHP oder Knoten oder Reagieren oder eine Kombination aus Stack für Backend und Frontend.
- Wo wird die Datenbank gehostet und wie viele Datenbanken betreiben Sie?
- Welche Integrationen von Drittanbietern gibt es für die App und haben Sie die Kontrolle über die Konten, die für jede dieser Integrationen verwendet werden?
- Nutzt die Anwendung andere Dienste wie Elastic Search, S3 oder andere Dienste, die zusätzlich berechnet/abgerechnet werden, und auf welcher Grundlage erfolgt die Abrechnung?
- Am wichtigsten ist, wer Zugriff auf die Hosting-Umgebung hat, wie diese kontrolliert wird und mit welchem Verfahren der Zugriff gewährt/entzogen wird. Idealerweise sollten Sie NIEMALS die Anmeldung des Root-Kontos weitergeben. Die beste Möglichkeit besteht darin, Benutzer hinzuzufügen/sie einzuladen, das Konto als einen bestimmten Benutzertyp basierend auf der erforderlichen Zugriffsebene zu verwenden. Oder gewähren Sie Zugriff auf einer SSH- oder bestimmten Ebene für die erforderliche Arbeit.
- Codebasis für Webanwendungen
Dies ist immer dann wichtig, wenn Sie ein Web betreiben oder mobile Applikation dass Sie über ein Quellcode-Repository-Konto für Ihr Unternehmen verfügen, sei es Github oder Bitbucket oder ähnliche Dienste. Die zum Erstellen des Kontos verwendete E-Mail-Adresse MUSS Eigentum des Unternehmens sein, und für jedes Projekt kann den Entwicklern die erforderliche Zugriffsebene gewährt werden. Es muss einen Prozess zum Hinzufügen bzw. Entziehen von Benutzern basierend auf den Ein-/Ausgängen zu Projekten geben. Und es ist auch möglich, jemandem Lesezugriff zum Anzeigen des Codes zu gewähren, wenn Sie mit einer neuen Entwicklungsfirma zusammenarbeiten und ihm Zugriff zum Überprüfen des Codes gewähren möchten.
Für zusätzlichen Schutz ist es sinnvoll, eine zusätzliche Schutzschicht für den Master-/Hauptzweig hinzuzufügen, der den Produktionscode enthält, sodass für jede Codezusammenführung in diesem Zweig eine Genehmigung erforderlich ist, und den Zweig vor Löschung usw. zu schützen. Wenn Sie Möglichkeiten dazu sehen Wenn Sie den Zweigschutz für Git aktivieren, erhalten Sie gute Einblicke dazu.
- Integrationen von Drittanbietern
Heutzutage verfügen die meisten Webanwendungen über zahlreiche Integrationen von Drittanbietern. Die häufigsten davon sind Google Maps, Google Analytics, Zahlungsgateways, SMS-Gateways für die OTP-Validierung, Mailchimp für Newsletter-Abonnements usw. Es ist wichtig sicherzustellen, dass alle vom Unternehmen verwendeten Konten vorhanden sind stammen aus der üblichen geschäftlichen E-Mail-Adresse, wobei die 2-Faktor-Authentifizierung mit einer Mobiltelefonnummer verknüpft ist, die zum Unternehmen gehört. Um außerdem sicherzustellen, dass alle für die Integration verwendeten API-Schlüssel mit dem spezifischen Projektnamen generiert und dem Entwicklungs-/Integrationsteam übergeben werden. Es wird ein Problem sein, wenn Sie Entwicklern erlauben, ihre Konten zu verwenden, diese Anmeldeinformationen zu erstellen und deren Verwendung zuzulassen, selbst wenn es sich um eine Google Map oder einen kostenlosen Dienst handelt. Irgendwann muss das Unternehmen je nach Nutzung auf die kostenpflichtigen Konten umsteigen, und es wird dann mühsam sein, das Konto nahtlos zu wechseln oder zu aktualisieren.
- Google Analytics, Social Logins oder andere
Its good to always plan and integrate analytics on all digital assets you run, especially if its customer facing. And the business should own the Google Analytics account that you would be using, the same way the business should own all the social media accounts it uses for all its integrations.
- Backups und Snapshots
Obwohl Backups und Snapshots Teil der Hosting-Strategie sind, ist es je nach Art des Hostings wichtig zu prüfen, ob diese jederzeit verfügbar sind. Cloud-Plattformen wie AWS und Azure verwalten zwar Snapshots, aber möglicherweise führen nicht alle Hosting-Anbieter kontinuierliche Datensicherungen durch, und es ist immer eine gute Strategie, regelmäßige REMOTE-Sicherungen durchzuführen.
Wenn es um mobile Apps geht
- PlayStore- und Apple Store-Anmeldeinformationen
These are credentials used by developers to publish the apps to the Google Play Store or Apple’s App Store, and it has to be owned by the business, and not allow developers to use their own. That way you always have control over App analytics and updates, and you get notified of any deprecated versions and upgrades that maybe needed for the apps. The respective developers can be given access by invite only, to the projects they work on and nothing further is needed here.
- Push-Benachrichtigungen – Anmeldeinformationen
Die meisten mobilen Apps nutzen einen Drittanbieterdienst für Push-Benachrichtigungen, zum Beispiel Firebase oder andere. Welches auch immer Sie verwenden, es ist wichtig, die Kontrolle über das hier verwendete Konto zu haben.
- Codebasis für mobile Anwendungen
Mobile App Code Base genau wie Web Applikationen Die Codebasis muss in einem Tool zur Codeversionskontrolle wie Git oder verwaltet werden Bit Bucket. Auch hier gelten die gleichen Regeln wie für die Webcode-Verwaltung.
In this era, we cannot take digital assets lightly as they are the lifeline of the business at all times, and its extremely important to understand how to protect and safeguard it at all times. The above is just a start, from a hygiene and must-do perspective and as we dig deeper there are further best practices and standards that can be followed. But the most important CHECK is to ensure that we have this in place to start with!
MÖCHTEN UNS MIT UNS BERATEN….KONTAKTIERE UNS JETZT!