Access control / 访问控制
Administrative server access uses SSH keys rather than passwords and is restricted to an approved source address. Application production authorization will not be enabled until role-based access control and MFA requirements are implemented and verified. Authorization credentials must not be stored in source code or client-facing pages.
服务器管理访问使用 SSH 密钥而非密码,并限制为批准的来源地址。在基于角色的访问控制和 MFA 要求实施并验证前,不启用应用生产授权。授权凭证不得存入源代码或面向用户的页面。
Network protection / 网络保护
Cloud security-group and host firewall rules expose only HTTPS/HTTP and restrict SSH to an approved administrative address. SSH intrusion prevention, malware scanning and security audit logging are enabled. The application and its future data services use a dedicated cloud environment separated from the company's other deployments.
云安全组和主机防火墙仅公开 HTTPS/HTTP,SSH 仅允许批准的管理地址访问。系统已启用 SSH 入侵防护、恶意软件扫描和安全审计日志。本应用及其后续数据服务使用独立云环境,与公司其他部署隔离。
Data protection / 数据保护
Production connections require encrypted transport. Application databases and caches are designed for private service-network access and are not intended to be directly exposed to the public internet. Data access is logged where appropriate for operational security and troubleshooting.
生产连接要求加密传输。应用数据库与缓存通过私有服务网络访问,不直接暴露到公网;必要的访问记录用于安全运营和故障排查。
Secure operations / 安全运维
Automatic operating-system security updates, daily malware scans, SSH intrusion monitoring and audit logging are enabled. Security incidents involving Amazon information are escalated under the incident-response procedure, including notification to security@amazon.com within 24 hours when required.
系统已启用操作系统自动安全更新、每日恶意软件扫描、SSH 入侵监控和审计日志。涉及 Amazon 信息的安全事件按事件响应程序升级处理,并在 Amazon 规定适用时于 24 小时内通知 security@amazon.com。
Report a security concern / 报告安全问题
Email wwy1211w08w@163.com with the subject “Security Report”. Do not include passwords, access tokens or other secrets.
请以“Security Report”为主题发送邮件,且不要在邮件中包含密码、访问令牌或其他机密信息。