Skip to content

Commit a4d1cc4

Browse files
Update enhancements/platform/security-and-trust-promise.md
Co-authored-by: Joshua Reese <[email protected]> Signed-off-by: Tom Daly <[email protected]>
1 parent 589b47b commit a4d1cc4

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

enhancements/platform/security-and-trust-promise.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -172,7 +172,7 @@ nitty-gritty.
172172
- Secret Management: We do not store secrets in plain text. We use a vault to inventory, secure, and store secrets wherever posisble.
173173

174174
#### Infrastrucuture Security
175-
- Network and System Hardening: Datum will apply the principle of least privilege to the openness of our network and systems. Netowrk and systems are hardened by changing vendor passwords, removing unneccesary packages and software, locking down network addresses and ports, and utilizing security brokers (Reverse Proxy, Zero Trust Network Access, etc.) where appropriate.
175+
- Network and System Hardening: Datum will apply the principle of least privilege to the openness of our network and systems. Network and systems are hardened by changing vendor passwords, removing unnecessary packages and software, locking down network addresses and ports, and utilizing security brokers (Reverse Proxy, Zero Trust Network Access, etc.) where appropriate.
176176
- Segementation: Datum will employ network segmentation for containing the compromise domains of sensisitive internal systems, thereby limiting a bad actor's potential lateral movement capabilities in our systems. Datum will provide strong segmentation amongst organizations and their projects. Datum will not permit remote attachment to its networks where broad scope access is granted (e.g. traditional VPN technologies).
177177
- DDoS Resilience: Datum will employ current practices to harden its infrastructure from Denial of Service (DoS) attacks by leveraging first party mitigration techniques (BGP RTBH, Flowspec, Overprovisioning, L4 and L7 Filtering) plus 3rd party mitigations as required.
178178
- Event Logging: Datum will employ event logging to monitor critical system infrastructure and its associated behaviors.

0 commit comments

Comments
 (0)