EHDEN / ehden-roadmap

0 stars 0 forks source link

Automated testing of known security vulnerabilities of EHDEN tools #15

Open SulevR opened 3 years ago

SulevR commented 3 years ago

Motivations

By our Security Policy draft, the tools that are used by EHDEN for providing Services must conform to a basic level of security such as OWASP Top 10. Though EHDEN is not responsible for the development and executions of all these tools, EHDEN shall ensure that these tools are tested to conform to a basic level of security.

Therefore, we do need at least some automated testing for ensuring that no common security vulnerabilities are found from these tools.

Proposal for Implementation

Erasmus MC has some experience in running Netsparker automated tests towards our web applications. It was quite easy to run and:

Contributions

Describe how community members can contribute

Someone has to install Netsparker (and pay the licence fee) and run the automated tests regularly and respond to the findings. One option is to just forward the findings to the tool developers.

Describe which persons are committed to implement

PRijnbeek commented 3 years ago

This tool development was agreed upon in the WP4 team and is moved to In Progress