Question

Do IFS have formal certification to Security Standards

  • 3 July 2020
  • 1 reply
  • 285 views

Badge +1

Have we gone through a process of certification of IFS Applications against some of the Security Standards like ISO/IEC 27034


1 reply

Userlevel 6
Badge +14

Pieter,

IFS implements a product security program based on ISO 27034 principles. Security is part of our Software Development Lifecycle model AQUA. This is realized through Security Development Practices, Security Architecture, Base Security Controls and Incident Management and Vulnerability Disclosure processes. Our Base Security Controls follow OWASP Top 10 industry best-practice recommendations. Internal security testing is done both through automated tools, manual testing as well as through regular 3rd party audits (Penetration Tests). IFS monitors the process maturity and targeted level of trust through utilization of OWASP Software Assurance Maturity Model (SAMM).

 

Regards,
Antony

Reply