{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,3]],"date-time":"2026-08-03T01:43:47Z","timestamp":1785721427319,"version":"3.56.0"},"reference-count":7,"publisher":"Breda Publishing Press","issue":"5","license":[{"start":{"date-parts":[[2021,5,1]],"date-time":"2021-05-01T00:00:00Z","timestamp":1619827200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Network Security"],"published-print":{"date-parts":[[2021,5]]},"abstract":"<jats:p> Security misconfigurations present serious trouble when security settings are not properly defined and implemented and default values are retained. Usually, this means the configuration settings do not comply with industry security standards such as the Center for Internet Security (CIS) benchmarks, OWASP Top 10 etc, which are critical to ensuring smooth business continuity, security maintenance and a reduction in business risk. <jats:sup>1,2<\/jats:sup> <\/jats:p><jats:p> Security misconfigurations present serious trouble when security settings are not properly defined and implemented and default values are retained. <\/jats:p><jats:p> For a seasoned cyber criminal, misconfigurations present easy targets, as it's often simple to detect misconfigured web servers, cloud instances and applications, which then become exploitable. Sergio Loureiro of SecludIT explains that it's important to ensure that your technology stack is built with security by design. <\/jats:p>","DOI":"10.1016\/s1353-4858(21)00053-2","type":"journal-article","created":{"date-parts":[[2021,5,26]],"date-time":"2021-05-26T03:44:51Z","timestamp":1622000691000},"page":"13-16","source":"Crossref","is-referenced-by-count":21,"title":["Security misconfigurations and how to prevent them"],"prefix":"10.70985","volume":"2021","author":[{"given":"Sergio","family":"Loureiro","sequence":"first","affiliation":[{"name":"SecludIT"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"51855","reference":[{"key":"bib1","unstructured":"\u2018CIS benchmarks\u2019. Center for Internet Security;  www.cisecurity.org\/cis-benchmarks\/ accessed May 2021"},{"key":"bib2","unstructured":"\u2018OWASP Top Ten\u2019. OWASP;  https:\/\/owasp.org\/www-project-top-ten\/ accessed May 2021"},{"key":"bib4","unstructured":"Srinivasan Jayaraman   \u2018Top vulnerability trends and how to fix them\u2019; \n20 Feb 2020: \nOutpost24>\nhttps:\/\/outpost24.com\/blog\/Top-vulnerability-trends-and-how-to-fix-them accessed May 2021"},{"key":"bib5","unstructured":"Filip Truta   \u2018Unsecured AWS bucket exposes personal data of 750,000 U.S. residents\u2019; \n10 Dec 2019: \nSecurity Boulevard>\nhttps:\/\/securityboulevard.com\/2019\/12\/unsecured-aws-bucket-exposes-personal-data-of-750000-u-s-residents\/ accessed May 2021"},{"key":"bib6","unstructured":"Tara Seals   \u2018AT&T, Verizon Subscribers Exposed as Mobile Bills Turn Up on the Open Web\u2019; \n5 Dec 2019: \nThreatPost>\nhttps:\/\/threatpost.com\/att-verizon-subscribers-exposed-mobile-bills\/150867\/ accessed May 2021"},{"key":"bib7","volume-title":"\u2018Is the cloud secure?\u2019","year":"2019"},{"key":"bib8","unstructured":"Alexander Getsin   \u2018Cloud penetration testing the Capital One breach\u2019; \n10 Oct 2019: \nCloud Security Alliance>\nhttps:\/\/cloudsecurityalliance.org\/blog\/2019\/10\/10\/cloud-penetration-testing-the-capital-one-breach\/ accessed May 2021"}],"container-title":["Network Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1353485821000532?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1353485821000532?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/www.magonlinelibrary.com\/doi\/pdf\/10.1016\/S1353-4858%2821%2900053-2","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,12,3]],"date-time":"2024-12-03T22:21:16Z","timestamp":1733264476000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.magonlinelibrary.com\/doi\/10.1016\/S1353-4858%2821%2900053-2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,5]]},"references-count":7,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2021,5]]}},"alternative-id":["10.1016\/S1353-4858(21)00053-2"],"URL":"https:\/\/doi.org\/10.1016\/s1353-4858(21)00053-2","relation":{},"ISSN":["1353-4858","1872-9371"],"issn-type":[{"value":"1353-4858","type":"print"},{"value":"1872-9371","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,5]]}}}