1. Bicom Systems
  2. Solution home
  3. SERVERware
  4. HOWTOs SERVERware 5

Bicom security policies (products)

1. Is the pentest performed regularly? 

2. Compliance with OWASP / NCSC Secure Coding Practices.

3. A policy/process should be in place, containing how security options are handled when the service is being implemented and managed.



Communicator


”For gloCOM Desktop and gloCOM web, we never had a pen test.

For gloCOM GO we had pen test last year performed by the company selected from one of our customers and we fixed all the issues. I am not sure if I can find that report.

We have internal security policies for all new products and services and we revise them during and after implementation.

We try to write code to be OWASP compliant however we have no official compliance certificate or audit performed by third-party companies.

We monitor and track all code through strict code reviews between multiple developers that ensure OWASP/NSCC are met."


PBXware



"No penetration testing is performed on annual basis. From time to time customers perform some limited tests. I gave some pointers to our Hosting Department to try to tackle this problem on our Hosting. For instance, to perform regular Network scan for open ports, which can easily identify exposed services. I guess they could make a summary report of these findings. 


I made a quick test. In the PBXware team, not many know what OWASP is. But some of the items from the OWASP list they already check and are aware of (just not aware of the OWASP acronym). This means to me that we lack official training for all developers in regard to “Best Development Security practices”. 


Keep in mind Security is an ongoing process and keeps changing all the time. Even OWASP is reshuffling its list for the year 2021. 


PBXware is an old application, it goes back 15+ years ago, and it is known that there are problems identified from the OWASP list. I wrote the Platform Security document recently (not to be shared externally) that explains some of the problems.

The last one is not very clear. If they mean, a policy on how we react to security-related issues, we do not have a such policy for PBXware. It is all on a “best effort” basis."



Networking team



"We’ve started doing NMAP scans for all POPs. We’ve already detected several VPSs with unusual open services and have notified the Hosting team. Anyway, I have scan reports for all of our POP and I can share them with you. However, if the customer requires something specific to be scanned you can let me know and we can perform scans more often and provide them with regular reports. The last scan has detected some outdated services on different VPSs and on some of our infrastructure that could possibly be exploited. But updating for most of those services could be a little bit tricky and could possibly cause some other issues. 


Considering pentesting (app pentesting, code review) I am not aware of any. However, I agree that it is really important to have these, for all of our products. 


Regarding, OWASP, I am met with top security risks, and I know how they are exploited, however, I am still learning to use different tools like BurpSuite and ZAP so I’ll be hopefully able to do a pentest on web apps. The same goes for VOIP pen-testing. I can make some form of training to introduce devs to OWASP but I would not go into the depth of code review as that’d require a bit more coding knowledge than I currently possess. However, I can try to research it a bit more and make some tips and a list of top practices to share with devs."