# ============================================================ # ENTERPRISE SECURITY STANDARD # CodeIgniter 3 HMVC # PHP 5.6 # MariaDB 10 # ERP Security Standard # Version 1.0 # ============================================================ Purpose This document defines mandatory security standards for the ERP system. Security shall always prioritize Confidentiality Integrity Availability Auditability Traceability Least Privilege ============================================================ SECURITY PRINCIPLES ============================================================ Default Deny Least Privilege Need To Know Defense In Depth Secure By Default Fail Secure ============================================================ AUTHENTICATION ============================================================ Every user shall authenticate. Password shall never be stored in plain text. Use password_hash() when available. Otherwise use strongest supported algorithm. Force password complexity. Session timeout mandatory. ============================================================ AUTHORIZATION ============================================================ Every request shall validate User Role Permission Module Access Action Permission No hidden access. ============================================================ ROLE MANAGEMENT ============================================================ Support Role Permission Menu Access Button Access API Access Approval Level ============================================================ SESSION ============================================================ Never store Business Object Large Dataset Accounting Data Tax Calculation Password Session ID shall regenerate after login. ============================================================ INPUT VALIDATION ============================================================ Validate Required Length Data Type Business Rule Never trust client input. ============================================================ OUTPUT ENCODING ============================================================ Escape HTML. Prevent XSS. Never output raw user input. ============================================================ SQL SECURITY ============================================================ Use Query Builder. Use Parameter Binding. Never concatenate SQL. Never execute dynamic SQL from user input. ============================================================ FILE UPLOAD ============================================================ Validate Extension Mime Type File Size Virus Scan (if available) Rename uploaded files. Store outside public folder whenever possible. ============================================================ FILE DOWNLOAD ============================================================ Validate Permission. Log download activity. Prevent direct access. ============================================================ PASSWORD ============================================================ Minimum Length 8 Characters Password Expiration Optional Password History Recommended ============================================================ ACCOUNT LOCK ============================================================ Lock account after repeated failed login. Log failed login attempts. ============================================================ AUDIT TRAIL ============================================================ Record Login Logout Create Update Delete Approval Posting Configuration Change ============================================================ LOGGING ============================================================ Log Authentication Failure Authorization Failure Database Error Business Error Security Event Critical Exception ============================================================ SENSITIVE DATA ============================================================ Protect Password Bank Account NPWP NIK Salary Financial Data Tax Data ============================================================ API SECURITY ============================================================ Validate Authentication Authorization Input Rate Limit (if supported) ============================================================ CONFIGURATION ============================================================ Never hardcode Password API Key Secret Key Database Credential SMTP Credential ============================================================ ERROR MESSAGE ============================================================ Never expose SQL Error Stack Trace Internal Path Configuration ============================================================ CSRF ============================================================ Enable CSRF protection. Validate every POST request. ============================================================ XSS ============================================================ Escape output. Sanitize input. Validate HTML when allowed. ============================================================ DIRECTORY SECURITY ============================================================ application/ Not publicly accessible. uploads/ Restricted. logs/ Restricted. backup/ Restricted. ============================================================ DATABASE SECURITY ============================================================ Application User Least Privilege No SUPER privilege. Separate production and development accounts. ============================================================ BACKUP SECURITY ============================================================ Backup shall Be encrypted. Be access controlled. Be periodically tested. ============================================================ SECURITY REVIEW CHECKLIST ============================================================ Authentication Authorization Input Validation Output Encoding Session Logging Audit Trail SQL Injection XSS CSRF Sensitive Data Configuration ============================================================ FORBIDDEN ============================================================ Plain Text Password Hardcoded Password Hardcoded API Key Dynamic SQL SQL Injection Disabled Authentication Disabled Authorization Public Backup Public Log File Public Configuration ============================================================ SUCCESS CRITERIA ============================================================ Security shall Protect Data Protect Users Protect Business Support Audit Meet Compliance ============================================================ END OF DOCUMENT ============================================================