alan-turing-institute / AssurancePlatform

Project to facilitate creation of Assurance Cases
MIT License
19 stars 6 forks source link

[epic] Ensure platform is ready for ethical hacking/testing #213

Open AoifeHughes opened 1 year ago

AoifeHughes commented 1 year ago

IT suggested penetration testing of platform, if we make accessible data storage through web app.

Needs to happen before end of July, but cannot happen before we have the new system up and running.

kallewesterling commented 1 year ago

Chris will initiate contact with AISH around best practices.

kallewesterling commented 11 months ago

Placed in "Needs more info" because contact was made with AISH around best practices, I believe (?) but what is the follow up needed here?

kallewesterling commented 9 months ago

@chrisdburr Can you clarify what/if we need to address this issue after the conversation with AISH, especially now that we have outsourced the login authentication to GitHub's OAuth?

chrisdburr commented 9 months ago

From IT's perspective, they would be happy with some form of penetration testing.

I also need to setup a conversation with legal, but I'd like to finish the work with Fruto and OCC first.

kallewesterling commented 9 months ago

Ok, thanks! I'll leave this in "Needs more info" and will move it to "Won't have" for now.

kallewesterling commented 5 months ago

Changing term in issue for sensitivity + making epic