Copied to clipboard

Flag this post as spam?

This post will be reported to the moderators as potential spam to be looked at


  • Nicholas Westby 2054 posts 7104 karma points c-trib
    Jul 29, 2019 @ 17:50
    Nicholas Westby
    0

    Umbraco Warm and Fuzzies for: Security, Availability, Integrity, Confidentiality, Privacy

    A client is interested in a "CMS that is SOC 2 compliant". Here's some info on SOC 2 compliance:

    Screenshot of Site Explaining SOC 2

    Source: https://www.imperva.com/learn/data-security/soc-2-compliance/

    More useful information: https://www.blissfully.com/guides/soc-2-compliance/

    While I doubt Umbraco the software, Umbraco HQ the organization, or Umbraco Cloud the platform are actually SOC 2 compliant at this point, I think what the client is really after is something that gives them the warm and fuzzies, like this page: https://www.progress.com/sitefinity-cms/platform/security

    In essence, they want to see something that assures them that their data and their customer's data is being managed well.

    I'm wondering if you all have information on this. Some examples of things that would be useful:

    • Umbraco Software A link to a page that shows that the Umbraco software manages data well.
    • Umbraco HQ A link to a page that shows that the Umbraco HQ has practices to ensure that the software they build manages data well.
    • Umbraco Cloud A link to a page that shows that Umbraco Cloud manages data well.

    Here's one example that shows that Umbraco Cloud takes security seriously: https://umbraco.com/products/umbraco-cloud/security/

    That itself does not seem sufficient. I'm looking for more examples that show Umbraco manages data well (more for the software itself, and the company).

  • bob baty-barr 1180 posts 1294 karma points MVP
    Jul 29, 2019 @ 18:55
    bob baty-barr
    1

    does the GDPR stuff make any difference here? https://umbraco.com/about-us/privacy/gdpr/

  • Nicholas Westby 2054 posts 7104 karma points c-trib
    Jul 30, 2019 @ 01:40
    Nicholas Westby
    0

    Hi Bob,

    That does help, thanks. If anybody has additional info, that would also help.

  • Thomas Morris 35 posts 133 karma points MVP 2x c-trib
    Jul 30, 2019 @ 09:16
    Thomas Morris
    1

    There's a more general security overview here that details what Umbraco do from a security point of view. https://umbraco.com/products/umbraco-cms/security/

    Highlights:

    • steps to disclose
    • umbraco core, regular pen tests, code practices and reviews, reference to OWASP, https, error handling
    • back office security, password rules, encryption, support for OAuth
    • previous alerts and patch notes

    It's probably worth mentioning that Umbraco is only part of the picture in this, being that you'll be developing against Umbraco with your own custom implementation, it's highly likely there are steps that you'll need to adhere to as well.

  • Nicholas Westby 2054 posts 7104 karma points c-trib
    Jul 30, 2019 @ 18:14
    Nicholas Westby
    0

    Hi Thomas,

    That looks pretty useful. Thank you. Here's a summary of the resources I have so far:

  • Mike Taylor 155 posts 353 karma points
    Aug 02, 2019 @ 08:25
  • Thomas Morris 35 posts 133 karma points MVP 2x c-trib
    Aug 01, 2019 @ 14:50
    Thomas Morris
    1

    Came across this guide recently as well, which details how to prep for being SOC 2 compliant.

    https://www.strongdm.com/best-guide-soc-2-type-1-audit/

  • This forum is in read-only mode while we transition to the new forum.

    You can continue this topic on the new forum by tapping the "Continue discussion" link below.

Please Sign in or register to post replies