CDCgov / trusted-intermediary

Bringing together healthcare providers by reducing the connection burden.
Apache License 2.0
10 stars 5 forks source link

Production Security Approval #175

Closed JohnNKing closed 2 weeks ago

JohnNKing commented 1 year ago

Backlog Task

Work with our CDC security contact to perform Fortify scans on our code base.

Completion Criteria

Tasks

scleary1cs commented 7 months ago

Combine with #721?

Answer = no

scleary1cs commented 7 months ago

Ensure "additional automated security scanning (could be informed by the ISSO)." Per Eng Block on 1/17/24

scleary1cs commented 5 months ago

Need to be in citrix remote desktop:

https://docs.cdc.gov/docs/devsecops/services/code-scan/fortify

jcrichlake commented 5 months ago

I requested access to fortify from the cdc sharepoint form and am awaiting a response. After I hear back I can request access for everyone on the team

jcrichlake commented 5 months ago

I just emailed the SoftwareAssurance team at the cdc to follow up on the access to fortify scans. I haven't received any word from them so figured I'd give them a poke to get a status update.

jcrichlake commented 5 months ago

This is in progress and confirmed that the information I gave to the Fortify team is sufficient.

scleary1cs commented 1 month ago

This should be for both the intermediary and the ingestion service.

saquino0827 commented 1 month ago

Finished our first pass on Fortify. We marked what we thought were false positives and set the remaining issues as under review due to needing research or a group decision to be made.