Security best practices for Adobe Experience Manager Edge Delivery Services
This article provides recommended security practices for Adobe Experience Manager (AEM) Edge Delivery Services (EDS). Organizations often evaluate authentication, content protection, endpoint security, and DDoS mitigation capabilities when deploying EDS. To resolve the issue, implement authentication and follow EDS security best practices.
Description description
Environment
Adobe Experience Manager (AEM) Edge Delivery Services (EDS), all versions
Issue/Symptoms
Organizations evaluating AEM EDS for secure content delivery may have the following concerns:
- Understanding how to implement authentication and protect content from unauthorized access.
- Clarifying the security implications and recommended mitigations for EDS endpoints.
- Ensuring alignment with organizational security requirements and architectural standards.
- Confirming the availability and level of built-in DDoS protection for EDS.
- Seeking guidance on additional security controls, safeguards, or best practices for EDS.
Root cause
These concerns arise from the need to secure content delivered through EDS endpoints and to ensure that the solution meets organizational security and compliance requirements.
Resolution resolution
Follow the steps below to resolve the issue:
- Review the AEM Authentication Setup for Sites documentation to implement authentication for EDS endpoints.
- Ensure that only Fastly EDS endpoints, such as
.aem.liveand.aem.page, are exposed publicly and protected by authentication. - Restrict EDS origin sites to accept traffic only from the Fastly CDN to prevent direct public access.
- Be aware that EDS delivery endpoints are rate-limited to 200 requests per second per project and originating IP address, and EDS admin API endpoints are rate-limited to 10 requests per second per project and originating IP address.
- Review the EDS Security Overview for details about the multiple defense layers provided by the CDN infrastructure.
- Confirm that EDS follows the same compliance policies as Adobe Experience Manager (AEM) as a Cloud Service, including applicable security frameworks.
- Access security testing and assurance reports through the Adobe Trust Center.
- Regularly review Adobe documentation for updates to security features and best practices.
recommendation-more-help
experience-cloud-kcs-help-kbarticles