SocialFinanceDigitalLabs / sf-fons-platform

https://github.com/SocialFinanceDigitalLabs/sf-fons
1 stars 0 forks source link

Pen Testing setup #31

Open dotloadmovie opened 1 year ago

dotloadmovie commented 1 year ago

24th Jan update: All approved, costings sorted. Caroline must approve. @cyramic to obtain caroline's approval. Involve Jake too please :)

dotloadmovie commented 1 year ago

-what, precisely, they will be testing -how we sort interop with SSO for them if needed -presence of a suitable production URL -mobilisation time at the vendor end -... probably some other stuff I haven't thought of

daniel-hutt commented 1 year ago

Herts have asked for timelines and confirmation that any vulnerabilities will be rectified

cyramic commented 1 year ago

Pen testers have responded that we should only test the application when everything is fully up and running. My notes from our conversation are below:

I finally got through to Surecloud. Our previous contact left, and the one suggested to me after that also left so my messages were getting lost. Their suggestion was that the app sounds like it's relatively low-risk and suggested the following approach for our needs:

He saw the app we're developing as not having a lot of risk associated with it and suggested we wait until we have a version we would be happy to PEN test against. Then we can do the full tests at that point to minimise cost. Was there anything else we wanted to check? I'll be sending off the diagrams tomorrow once I give them a once-over just to make sure they're accurate.