Phase: Implementation; System Configuration
Avoid storing information under the FTP root directory.
Phase: System Configuration
Access control permissions should be set to prevent reading/writing of sensitive files inside/outside of the FTP directory.