Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

FR White paper section? Security WP example. #644

Open
robinsowell opened this issue May 3, 2023 · 0 comments
Open

FR White paper section? Security WP example. #644

robinsowell opened this issue May 3, 2023 · 0 comments

Comments

@robinsowell
Copy link
Contributor

I get intermittent requests for white papers - typically on security and server recommendations. Not sure if docs would be the right spot, but... maybe?

Community Involvement in Risk Vulnerability Identification
Participant in HakerOne's vulnerability disclosure program https://hackerone.com/expressionengine?type=team
Security reporting guidelines and encouragement of users to report suspected vulnerabilities (https://github.com/ExpressionEngine/ExpressionEngine-User-Guide/blob/6.dev/docs/bugs-and-security-reports.md#security-reporting-guidelines)
 
Spam prevention
Native integration of Google reCaptcha (https://docs.expressionengine.com/latest/control-panel/settings/captcha.html#recaptcha-v3-settings)
Native spam module that uses machine learning to identify suspect content submissions (https://docs.expressionengine.com/latest/add-ons/spam.html#usage)
Ban access by IP, IP block, or referrer (https://docs.expressionengine.com/latest/add-ons/blocklist.html)
  
Tools for Website Administrators
Customizable Password Policies (https://docs.expressionengine.com/latest/control-panel/settings/security-privacy.html#password-security-policy)
User agent and IP Requirements for Login (https://docs.expressionengine.com/latest/control-panel/settings/security-privacy.html#require-user-agent-and-ip-for-login)
Recommendations for site hardening (https://docs.expressionengine.com/latest/security/general-tips.html#security-tips)
 
 Security and Privacy for End Users
Native tools to help achieve GDRP (General Data Protection Regulation) compliance (https://docs.expressionengine.com/latest/general/gdpr.html#gdpr-and-expressionengine)
Consent module for fine grained control over user consent to cookies (https://docs.expressionengine.com/latest/add-ons/blocklist.html)
Ability to anonymize user data (https://docs.expressionengine.com/latest/control-panel/member-profile.html#anonymize-user)
 
Automated Testing
Security checks built into automated testing. Here's an example of a Cross Site Scripting (XSS) check in our Cypress tests.

CVE (Common Vulnerabilities and Exposures) Reports
There have been no known critical level CVE exploits reported in our 20 year history
https://www.cvedetails.com/vulnerability-list/vendor_id-7662/Expressionengine.html

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant