• Open Daily: 10am - 10pm
    Alley-side Pickup: 10am - 7pm

    3038 Hennepin Ave Minneapolis, MN
    612-822-4611

Open Daily: 10am - 10pm | Alley-side Pickup: 10am - 7pm
3038 Hennepin Ave Minneapolis, MN
612-822-4611
NGINX for Professionals: Security & Compliance Handbook

NGINX for Professionals: Security & Compliance Handbook

Paperback

Series: Nginx: From Dummy to Professional, Book 4

General ComputersComputer Security

ISBN13: 9798189912177
Publisher: Independently Published
Published: Jul 30 2026
Pages: 248
Weight: 0.74
Height: 0.52 Width: 6.00 Depth: 9.00
Language: English
A security audit finding rarely looks like an incident. It's a line item in a spreadsheet, a control marked not effective, a remediation deadline three weeks out - and it very often traces back to NGINX configured for functionality first, with security bolted on afterward.

NGINX for Professionals: Security & Compliance Handbook treats security and compliance as the primary subject, not an afterthought chapter. Across 20 chapters, it moves from threat modeling and platform hardening through transport security, application-layer defense, identity and authorization, and - uniquely - a direct, practitioner-level mapping from PCI DSS, HIPAA, SOC 2, and GDPR requirements to actual, defensible NGINX configuration.

Inside you'll find:

  • A clear-eyed threat model: what NGINX can and cannot actually defend against
  • Full TLS hardening for security reviews, not just compatibility checklists
  • Mutual TLS and zero-trust architecture, including certificate lifecycle management at scale
  • A complete ModSecurity and OWASP Core Rule Set deployment walkthrough, from detection-only to production blocking
  • Bot management, rate limiting as a genuine security control, and API-specific attack surfaces
  • Direct compliance mapping tables for PCI DSS, HIPAA, SOC 2, and GDPR - built for real audit preparation, not vague generalities
  • Incident response runbook templates and a full DDoS mitigation chapter
Written for security engineers inheriting an NGINX estate they didn't design, platform engineers implementing controls a security team specifies, and engineering leads preparing for a real compliance audit. Includes a full appendix of ready-to-fill incident response runbook templates.

Also from

Gómez Fernández, Oscar

Also in

Computer Security