Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

May Invicti findings #3902

Closed
4 tasks
jadudm opened this issue May 29, 2024 · 5 comments
Closed
4 tasks

May Invicti findings #3902

jadudm opened this issue May 29, 2024 · 5 comments
Assignees
Labels
compliance Stuff which may relate to a specific requirement or timelines for resolution eng

Comments

@jadudm
Copy link
Contributor

jadudm commented May 29, 2024

See here.

Due 120 days after report was issued (05/24/2024).

Rounds up #3900 and #3899.

Findings

Assigning @ChrisB-16 to shepherd our responses through to the assessment team. Let's check these off when we confirm that the assessors have acknowledged.

@jadudm jadudm added this to FAC May 29, 2024
@jadudm jadudm converted this from a draft issue May 29, 2024
@jadudm jadudm added compliance Stuff which may relate to a specific requirement or timelines for resolution eng labels May 29, 2024
@danswick danswick changed the title May Invicti: Content Type (#4) May Invicti findings Jul 30, 2024
@danswick
Copy link
Contributor

Re: the nosniff header, I checked manually and it appears to be present on our pages and is a cloud.gov default. I'm not sure why the Invicti scan isn't seeing it.

This was referenced Jul 30, 2024
@danswick danswick moved this from Backlog to In Progress in FAC Jul 30, 2024
@danswick
Copy link
Contributor

@ChrisB-16 will compare against the August findings and scan results to determine if we can close here. We may need to compare the test date to the most recent deploy. Some of the above findings may not have existed in prod by the scan day.

@danswick
Copy link
Contributor

@ChrisB-16 to summarize current findings here.

@ChrisB-16
Copy link
Contributor

This May Invicti VM scan review can be closed. There was no Criticals/ Highs/ Medium findings. The Low findings are being tracked and will be addressed during future patch release for supporting IT software. The ongoing FAC ATO continuous monitoring efforts will track updates and if any new applicable VM finding is discovered.

1 similar comment
@ChrisB-16
Copy link
Contributor

This May Invicti VM scan review can be closed. There was no Criticals/ Highs/ Medium findings. The Low findings are being tracked and will be addressed during future patch release for supporting IT software. The ongoing FAC ATO continuous monitoring efforts will track updates and if any new applicable VM finding is discovered.

@github-project-automation github-project-automation bot moved this from In Progress to Done in FAC Oct 22, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
compliance Stuff which may relate to a specific requirement or timelines for resolution eng
Projects
Status: Done
Development

No branches or pull requests

3 participants