Vaak we come across businesses especially Start-ups and SMEs who have no control over their digital assets. Purely because it was created by an employee whose no longer with the organization, or was not handed over back to the company’s digital silo, causing an impact on time, costs and control for the business , and at times posing bottlenecks during very crucial situations when a change is needed. For business, time is money and anything that may make you lose time, in effect is CRITICAL. The motivation and purpose of writing this article, is driven from this need, to define a “Hygiene Checklist for Managing Digital Assets” , so that you as a business do not make the same mistake and can be better equipped for the same.
Since the context of Digital Assets can be huge, let me stick to the ones that pertain to the web and mobile applications that you run, and lets keep aside any other digital assets for the time being such as IT assets, digital physical assets etc.
Wat zijn de digitale activa die webapplicaties gebruiken en hoe kun je het eigendom hiervan het beste beheren. Wat zijn de vragen die je als bedrijfseigenaar moet weten als je eigenaar bent van deze digitale activa en wat zijn de Dos en Don'ts hier.
- Hosting en DNS
Your app can be hosted in a shared hosting environment like GoDaddy, or a dedicated affordable VPS hosting like Contabo, DigitalOcean or Linode, or a cloud environment like AWS Ec2 or Azure. Whichever environment it is, its important that the ROOT account of hosting is under the ownership of a common business email, with 2-factor authentication linked to a mobile number that belongs to the business. The stakeholders of the business should get ALL notifications from the hosting account at all times, because if there are billing failures for consecutive 3 months your account can be terminated, or the data deleted and its a HUGE risk. Basically the email configured here has to be MONITORED at all times, and the data is too critical if you fail to do so.
And as important as the control on hosting, is the control on the DNS or domain name provider (Could be GoDaddy, a well-known domain naming platform, Mercaba or any others). The primary account with the domain registrar must be under the common business email, including the mobile number linked to it for 2-factor auth. The notifications for expiry of domain names must be set correctly so that you get timely alerts, and has to be tracked to avoid unexpected downtimes or outages.
- Uw webapplicatie en API-interfaces
De webapplicatie bevindt zich in uw hostingomgeving, maar het is belangrijk om te weten
- Hoeveel instanties gebruik je en hoeveel krijg je gefactureerd?
- Wat is de technische stack waarop elke instantie draait, bijvoorbeeld als het PHP of Knooppunt of Reageer op of een combinatie van stack voor backend en frontend.
- Waar wordt de database gehost en hoeveel databases draait u.
- Wat zijn de integraties van derden voor de app en heb je controle over de accounts die voor elk van deze worden gebruikt.
- Maakt de applicatie gebruik van andere services zoals Elastic Search, S3 of iets anders dat extra in rekening wordt gebracht en op welke basis dat gebeurt.
- Het belangrijkste is wie toegang heeft tot de hostingomgeving, hoe dit wordt gecontroleerd en wat het proces is dat wordt gebruikt om toegang te verlenen/intrekken. Idealiter zou u NOOIT de login van de root-account moeten delen, de beste manier is om gebruikers toe te voegen/uit te nodigen om de account te gebruiken als een specifiek type gebruiker op basis van het vereiste toegangsniveau. Of geef toegang op een ssh of specifiek niveau voor het werk dat gedaan moet worden.
- Webtoepassingscodebestand
Het is belangrijk wanneer je een web- of mobiele toepassing dat u een account voor broncodeopslag bijhoudt voor uw bedrijf, zij het Github of Bitbucket of vergelijkbare diensten. Het e-mailadres dat wordt gebruikt voor het aanmaken van de account MOET eigendom zijn van het bedrijf en voor elk project kan het vereiste toegangsniveau aan de ontwikkelaars worden gegeven. Er moet een proces zijn om gebruikers toe te voegen/intrekken op basis van het betreden/verlaten van projecten. En het is ook mogelijk om iemand leestoegang te geven om de code te bekijken, als u wilt samenwerken met een nieuw ontwikkelbedrijf en hen toegang wilt geven om de code te controleren.
Voor extra bescherming, is het goed om een extra beschermingslaag toe te voegen voor de master/hoofd branch die de productiecode heeft, zodat het goedkeuring vereist voor iedere code samenvoeging naar deze branch, en de branch te beschermen tegen verwijderen etc. Als je manieren ziet om branchbeveiliging voor Git in te schakelen, zul je hier goede inzichten over krijgen.
- Integraties van derden
De meeste webapplicaties hebben tegenwoordig veel integraties met derden, waarvan Google Maps, Google Analytics, Payment Gateways, SMS Gateways voor OTP-validatie, Mailchimp voor nieuwsbriefinschrijvingen etc. de meest voorkomende zijn. Het is belangrijk om ervoor te zorgen dat alle accounts die door het bedrijf worden gebruikt, afkomstig zijn van het gemeenschappelijke zakelijke e-mailadres, met 2-factor authenticatie gekoppeld aan een mobiel nummer dat bij het bedrijf hoort. Zorg er ook voor dat alle API-sleutels die worden gebruikt voor integratie worden gegenereerd met de specifieke projectnaam en worden gegeven aan het ontwikkelings-/integratieteam. Het wordt een probleem als je ontwikkelaars toestaat om hun accounts te gebruiken, deze credentials aan te maken en het gebruik ervan toe te staan, zelfs in het geval van een google map of een gratis service. Op een gegeven moment zal het bedrijf moeten overschakelen naar de betaalde accounts op basis van gebruik, en het zal dan lastig zijn om naadloos over te schakelen of het account te upgraden.
- Google Analytics , Social Logins of andere
Its good to always plan and integrate analytics on all digital assets you run, especially if its customer facing. And the business should own the Google Analytics account that you would be using, the same way the business should own all the social media accounts it uses for all its integrations.
- Back-ups en snapshots
Hoewel back-ups en snapshots deel uitmaken van de hostingstrategie, is het afhankelijk van het type hosting belangrijk om te controleren of je deze altijd beschikbaar hebt. Cloudplatforms zoals AWS en Azure onderhouden snapshots, maar niet alle hostingproviders onderhouden misschien continu gegevensback-ups en het is altijd een goede strategie om regelmatig back-ups OP AFSTAND te maken.
Als het aankomt op mobiele apps
- PlayStore en Apple Store referenties
These are credentials used by developers to publish the apps to the Google Play Store or Apple’s App Store, and it has to be owned by the business, and not allow developers to use their own. That way you always have control over App analytics and updates, and you get notified of any deprecated versions and upgrades that maybe needed for the apps. The respective developers can be given access by invite only, to the projects they work on and nothing further is needed here.
- Pushmeldingen - Credentials
De meeste mobiele apps gebruiken een externe service voor pushmeldingen, bijvoorbeeld Firebase of andere. Welke je ook gebruikt, het is belangrijk dat je controle hebt over de account die hier wordt gebruikt.
- Code voor mobiele toepassingen
Mobile App Code Base net als webtoepassingen code moet worden onderhouden in een versiebeheerprogramma zoals Git of BitBucket. Dezelfde regels die gelden voor het beheer van webcodes zijn ook hier van toepassing.
In this era, we cannot take digital assets lightly as they are the lifeline of the business at all times, and its extremely important to understand how to protect and safeguard it at all times. The above is just a start, from a hygiene and must-do perspective and as we dig deeper there are further best practices and standards that can be followed. But the most important CHECK is to ensure that we have this in place to start with!
MET ONS WILT OVERLEGGEN....CONTACT ONS NU!