Minimizing and Protecting Web Applications

You should also minimize the number of web applications open to the Internet since each one increases the risk to an organization and can be used by attackers to trick employees into providing sensitive information such as usernames and passwords allowing access to the organization's internal network. If possible, these applications should only be accessible after authenticating to an IPsec VPN.

Figure 13-14 Phishing email tricking the user into visiting a spoofed web application

