Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Overly permissive firewalls #177

Open
TonyWildish-BH opened this issue Oct 10, 2024 · 0 comments
Open

Overly permissive firewalls #177

TonyWildish-BH opened this issue Oct 10, 2024 · 0 comments
Assignees
Labels
bug Something isn't working EPIC - Pen-test fixes Fixing security issues found during penetration testing MVP Things that need to be considered for the MVP release

Comments

@TonyWildish-BH
Copy link
Collaborator

The penetration testing report showed that (page 32):

Firewall rules were identified that allowed traffic to be permitted from communication with systems that they are unlikely to require access to.

A number of Network Security Groups were defined within the Azure Trusted Research Environment that controlled traffic to Internet-facing resources, or within private Virtual Networks.

N.B., this may not apply to the SDE, since the pen-test swept up everything in the tenancy, but it needs verifying.

This is a medium level risk, but is something we must fix before the next pen-test.

@TonyWildish-BH TonyWildish-BH added bug Something isn't working MVP Things that need to be considered for the MVP release EPIC - Pen-test fixes Fixing security issues found during penetration testing labels Oct 10, 2024
@TonyWildish-BH TonyWildish-BH self-assigned this Oct 11, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working EPIC - Pen-test fixes Fixing security issues found during penetration testing MVP Things that need to be considered for the MVP release
Projects
None yet
Development

No branches or pull requests

1 participant