אבטחת מידע
תוכן זה נשמר מעמוד אבטחת המידע של PetArk כדי שיהיה זמין גם לאחר סגירת האתר.
נכסים מוגנים
- נתוני משתמשים.
- תמונות רפואיות.
- טוקני גישה.
- לוגי מערכת.
איומים עיקריים
- פריצות ו-SQL Injection.
- XSS ו-CSRF.
- Brute Force ו-DDoS.
- דליפת API Keys.
בקרות הגנה
- הצפנה TLS 1.3 / AES-256.
- Zero Trust ו-MFA.
- גישה מוגבלת לצוות SRE בלבד.
- Rate limiting ו-IDS/IPS.
- תיעוד חריגות.
תוכנית תגובה לאירוע
1. זיהוי ואימות האירוע.
2. חסימת גישה או צמצום החשיפה.
3. ניתוח האירוע.
4. תיקון והחזרת השירות.
5. הודעה אם נדרש על פי חוק.
6. שיפור התשתיות ומניעת הישנות.
לשאלות נוספות ניתן לפנות אלינו דרך עמוד צור קשר.
أمن المعلومات
يتم حفظ هذا المحتوى من صفحة أمن المعلومات الخاصة بـ PetArk لكي يظل متاحًا حتى بعد إغلاق الموقع.
الأصول المحمية
- بيانات المستخدمين.
- الصور الطبية.
- رموز الوصول.
- سجلات النظام.
التهديدات الرئيسية
- الاختراقات وSQL Injection.
- XSS وCSRF.
- Brute Force وDDoS.
- تسرب API Keys.
ضوابط الحماية
- تشفير TLS 1.3 / AES-256.
- Zero Trust وMFA.
- وصول مقيّد لفريق SRE فقط.
- تحديد المعدل وIDS/IPS.
- تسجيل الحالات الشاذة.
خطة الاستجابة للحوادث
1. تحديد الحادث والتحقق منه.
2. حظر الوصول أو تقليل التعرّض.
3. تحليل الحادث.
4. المعالجة واستعادة الخدمة.
5. الإخطار إذا كان القانون يقتضي ذلك.
6. تحسين البنية التحتية ومنع التكرار.
لمزيد من الأسئلة، يمكنكم التواصل معنا عبر صفحة الاتصال.
Information Security
This content is saved from PetArk's information security page so that it remains available even after the site is closed.
Protected Assets
- User data.
- Medical images.
- Access tokens.
- System logs.
Main Threats
- Breaches and SQL Injection.
- XSS and CSRF.
- Brute Force and DDoS.
- Leakage of API Keys.
Protective Controls
- TLS 1.3 / AES-256 encryption.
- Zero Trust and MFA.
- Access restricted to the SRE team only.
- Rate limiting and IDS/IPS.
- Logging of anomalies.
Incident Response Plan
1. Identifying and verifying the incident.
2. Blocking access or reducing exposure.
3. Analyzing the incident.
4. Remediating and restoring the service.
5. Notifying if required by law.
6. Improving the infrastructure and preventing recurrence.
For further questions, you may contact us through the contact page.
Seguridad de la Información
Este contenido se guarda de la página de seguridad de la información de PetArk para que siga estando disponible incluso después de que se cierre el sitio.
Activos protegidos
- Datos de los usuarios.
- Imágenes médicas.
- Tokens de acceso.
- Registros del sistema.
Principales amenazas
- Intrusiones e inyección SQL (SQL Injection).
- XSS y CSRF.
- Brute Force y DDoS.
- Fuga de API Keys.
Controles de protección
- Cifrado TLS 1.3 / AES-256.
- Zero Trust y MFA.
- Acceso restringido únicamente al equipo de SRE.
- Rate limiting e IDS/IPS.
- Registro de anomalías.
Plan de respuesta a incidentes
1. Identificación y verificación del incidente.
2. Bloqueo del acceso o reducción de la exposición.
3. Análisis del incidente.
4. Corrección y restablecimiento del servicio.
5. Notificación si así lo exige la ley.
6. Mejora de las infraestructuras y prevención de la recurrencia.
Para más consultas, puedes ponerte en contacto con nosotros a través de la página de contacto.
Sécurité de l'Information
Ce contenu est enregistré à partir de la page de sécurité de l'information de PetArk afin qu'il reste disponible même après la fermeture du site.
Actifs protégés
- Données des utilisateurs.
- Images médicales.
- Jetons d'accès.
- Journaux système.
Principales menaces
- Intrusions et injection SQL (SQL Injection).
- XSS et CSRF.
- Brute Force et DDoS.
- Fuite de clés d'API (API Keys).
Contrôles de protection
- Chiffrement TLS 1.3 / AES-256.
- Zero Trust et MFA.
- Accès restreint à la seule équipe SRE.
- Rate limiting et IDS/IPS.
- Journalisation des anomalies.
Plan de réponse aux incidents
1. Identification et vérification de l'incident.
2. Blocage de l'accès ou réduction de l'exposition.
3. Analyse de l'incident.
4. Correction et rétablissement du service.
5. Notification si la loi l'exige.
6. Amélioration des infrastructures et prévention de la récurrence.
Pour toute autre question, vous pouvez nous contacter via la page de contact.
Информационная безопасность
Этот контент сохранен со страницы информационной безопасности PetArk, чтобы он оставался доступным даже после закрытия сайта.
Защищаемые активы
- Данные пользователей.
- Медицинские изображения.
- Токены доступа.
- Системные журналы.
Основные угрозы
- Взломы и SQL Injection.
- XSS и CSRF.
- Brute Force и DDoS.
- Утечка API Keys.
Средства защиты
- Шифрование TLS 1.3 / AES-256.
- Zero Trust и MFA.
- Доступ ограничен только командой SRE.
- Ограничение частоты запросов и IDS/IPS.
- Журналирование аномалий.
План реагирования на инциденты
1. Выявление и проверка инцидента.
2. Блокировка доступа или снижение риска раскрытия.
3. Анализ инцидента.
4. Устранение последствий и восстановление сервиса.
5. Уведомление, если этого требует закон.
6. Улучшение инфраструктуры и предотвращение повторения.
По дополнительным вопросам вы можете связаться с нами через страницу контактов.