ColdFusion 8 is Highly Secure
A security evaluation report was just released from Information Risk Managment, Plc. This report in short said that "ColdFusion 8 exhibits a high degree of resilience to application layer attacks with no compromise on functionality provisioned by the new features"
Read the full report for more details
Here is the conclusion they came to:
"IRM’s security evaluation of ColdFusion 8 revealed that the product has been well designed with security as a major consideration during development. The ColdFusion 8 model requires certain administrative tasks to be performed as a part of deployment in order to enforce a stringent security regime. Security management of these servers is essential in ensuring security of the overall deployment. It is important to follow Adobe’s best practice guides for securing these servers and applying appropriate security patches. Adobe also maintains resources on secure development of ColdFusion applications which can be found at the following URL:
http://www.adobe.com/devnet/coldfusion/security.html.
ColdFusion developers should strive to incorporate secure coding principles into their development methodologies as highlighted by Adobe. Overall IRM was impressed with Adobe’s integration of security processes in the development lifecycle, the result of which can be seen in ColdFusion 8, a product that withstands stringent security testing with relative ease. All of the new features incorporated in this release adhere to highest levels of application security enforcement without any compromise on functionality."
Very cool!

