Skip to content

Referencias — Unidad 2

ID Fuente Tipo
REF-U2-01 The PostgreSQL Global Development Group. PostgreSQL Documentation, secc. 5.8 “Privileges” y comandos GRANT/REVOKE. https://www.postgresql.org/docs/current/ddl-priv.html Documentación oficial
REF-U2-02 The PostgreSQL Global Development Group. PostgreSQL Documentation, secc. 20.1 “The pg_hba.conf File”. https://www.postgresql.org/docs/current/auth-pg-hba-conf.html Documentación oficial
REF-U2-03 The PostgreSQL Global Development Group. PostgreSQL Documentation, secc. 18.9 “Secure TCP/IP Connections with SSL”. https://www.postgresql.org/docs/current/ssl-tcp.html Documentación oficial
REF-U2-04 The PostgreSQL Global Development Group. PostgreSQL Documentation, apéndice F.26 “pgcrypto”. https://www.postgresql.org/docs/current/pgcrypto.html Documentación oficial
REF-U2-05 MongoDB, Inc. MongoDB Manual — “Role-Based Access Control in Self-Managed Deployments”. https://www.mongodb.com/docs/manual/core/authorization/ Documentación oficial
REF-U2-06 MongoDB, Inc. MongoDB Manual — “Configure MongoDB Instances for TLS/SSL Encryption”. https://www.mongodb.com/docs/manual/tutorial/configure-ssl/ Documentación oficial
REF-U2-07 OWASP Foundation. OWASP Cheat Sheet Series — “SQL Injection Prevention Cheat Sheet”. https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html Documentación oficial (organismo de seguridad)
REF-U2-08 OWASP Foundation. OWASP Cheat Sheet Series — “NoSQL Security Cheat Sheet”. https://cheatsheetseries.owasp.org/cheatsheets/NoSQL_Security_Cheat_Sheet.html Documentación oficial (organismo de seguridad)
REF-U2-09 Cámara de Diputados (México). Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP). http://www.diputados.gob.mx/LeyesBiblio/ref/lfpdppp.htm Documento normativo oficial
REF-U2-10 Cámara de Diputados (México). Ley General de Protección de Datos Personales en Posesión de Sujetos Obligados (LGPDPPSO). http://www.diputados.gob.mx/LeyesBiblio/ref/lgpdppso.htm Documento normativo oficial
REF-U2-11 Center for Internet Security (CIS). CIS PostgreSQL Benchmark. https://www.cisecurity.org/benchmark/postgresql Guía de configuración segura
REF-U2-12 U.S. Government Accountability Office (GAO). Data Protection: Actions Taken by Equifax and Federal Agencies in Response to the 2017 Breach (GAO-18-559), 2018-09-07. https://www.gao.gov/products/gao-18-559 Informe oficial gubernamental
REF-U2-13 The Register. “MongoDB ransom attacks soar, body count hits 27,000 in hours”, 2017-01-09. https://www.theregister.com/2017/01/09/mongodb/ Reportaje técnico especializado
Objetivo específico Referencias aplicables
OE-U2.1 — Principios de seguridad e inyección REF-U2-07, REF-U2-08
OE-U2.2 — Control de acceso REF-U2-01, REF-U2-05, REF-U2-13
OE-U2.3 — Protección de datos sensibles REF-U2-09, REF-U2-10
OE-U2.4 — Cifrado REF-U2-03, REF-U2-04, REF-U2-06
OE-U2.5 — Privacidad y cumplimiento REF-U2-09, REF-U2-10
OE-U2.6 — Hardening REF-U2-02, REF-U2-11, REF-U2-12, REF-U2-13