april - june - 2023retailbusinesreview.com8SECURING E-COMMERCE IN THE RETAIL INDUSTRYIn My OpinionBy Ken Collins, Director Information Security, Sunbelt RentalsByThe world has quickly shifted from brick and mortar to a digital landscape, and the result is a booming e-commerce world. This has been a trend for the past two decades, and COVID-19 has made this model not only a convenience, but also a necessity. For the retail world -- including tool and equipment rental --a quality e-commerce platform provides not only goods and services but, more importantly, it offers a seamless, easy-to-use customer experience. Critical to this experience is the security of the customer's data, transactions, and delivery. In the digital world, information can be disseminated quickly. Stolen data can have a significant impact on consumers and retailers.Adapting security to an e-commerce modelTo safeguard against security breaches, asset loss, and fraud, assess the risk involved with the e-commerce platform. It's all about the customer, the data, and the transaction -- and looking at each facet to ensure everything is done in a controlled, predictable manner. This is challenging, because e-commerce platforms are entire ecosystems consisting of databases, mobile and web applications, inventory, and financial systems. From a mobile app perspective, security must account for the fact that an outside interface connects to a retail outlet's system to complete transactions. It is imperative that the app design prevents an outside adversary from manipulating the application to a negative impact against the company. Before developing an app, threat modeling needs to be completed in order to determine potential risk in the design. After development, complete penetration testing needs to occur to evaluate security flaws. Adversaries frequently use low-tech tactics to accomplish their objectives. High and critical findings must be remediated before release to production to mitigate a potential risk. With third-party software, place emphasis on third-party risk management. Out-of-the-box tools for transactions require looking at actions between one vendor and another to see if there are any risks to the process. It's important to review vendor policies, penetration tests, and overall security posture. Choose a vendor based on quantitative and qualitative data.Implementing security best practicesThere are several best practices to consider for e-commerce security. Bake security into the development life cycle for the e-commerce site or app, and adhere to a secure software development framework. In general, fixing security flaws found late in the development lifecycle
<
Page 7 |
Page 9 >