Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 52 Current »

This document shares current curated security backlog with features and capabilities that are defined in Security Jira board. Please refer Bahmni Security Posture document to get a holistic perspective.

To update JIRA details below, please type “/JIRA“ under Documentation/JIRA column & search your Jira no, click Insert.
This will show the current status on Jira board.

Categories

Capabilities / Features

Documentation/JIRA

Bahmni Lite v 1.0 Release

1

Trivy Secret & Vulnerability Scanning

Analyze false positives or perform quick fixes on Critical vulnerabilities (First Pass)

BAH-2416 - Getting issue details... STATUS

DONE

2

Perform Vulnerability check in CI (build) using Trivy and fail for Critical issues. Add secret scanning using Trivy in all Bahmni repositories

BAH-2193 - Getting issue details... STATUS

DONE

3

Machine / Node hardening

OpenSCAP for nodes / machine monitoring

BAH-2142 - Getting issue details... STATUS

DONE

4

Apply daily critical security updates automatically (e.g EC2)

BAH-2412 - Getting issue details... STATUS
BAH-2382 - Getting issue details... STATUS

DEFERRED

5

Firewall

OpenSource / Free option for Bot Management and Traffic Control for Bahmni running on Docker / K8s

BAH-2413 - Getting issue details... STATUS

DEFERRED

6

Document AWS WAF and Bot Management recommendation for Bahmni Lite

BAH-2414 - Getting issue details... STATUS

DEFERRED

7

Security Quality Gates

Explore OWASP Zap for Bahmni Security Testing

BAH-1961 - Getting issue details... STATUS

DEFERRED

8

Automate Static Code Analysis using DeepSource / SonarQube → Documentation

BAH-1958 - Getting issue details... STATUS
BAH-1959 - Getting issue details... STATUS

DEFERRED

9

Data Protection

Protect patient documents behind Login (only for older RPM based installation since docker and k8s no longer have this issue)

BAH-2417 - Getting issue details... STATUS

DEFERRED

10

Encrypt documents at rest (S3/FileSystem/Connected Storage/etc) e.g. Patient Documents

BAH-2418 - Getting issue details... STATUS

DEFERRED

11

Identity Management

Mitigate default credentials risk

  • Ensure Change password on first login e.g. superman

  • Remove default creds from code e.g. .env, values.yaml etc

BAH-1960 - Getting issue details... STATUS

DEFERRED

12

Cloud/Infra

Document recommendations on General Cloud hygiene

DEFERRED

13

Document Approach on Reporting security incident (Slack, DL etc)

DONE

14

Source Code Fixes

Fix hip service critical vulnerabilities

BAH-2550 - Getting issue details... STATUS

ABDM REQUIRED

15

Fix hiu backend critical vulnerabilities

BAH-2551 - Getting issue details... STATUS

ABDM REQUIRED

16

Fix hiu-ui critical vulnerabilities

BAH-2552 - Getting issue details... STATUS

ABDM REQUIRED

17

Fix critical vulnerabilities in ABHA verification repo.

BAH-2553 - Getting issue details... STATUS

ABDM REQUIRED

18

Fix critical vulnerabilities in Hiu-db code

BAH-2554 - Getting issue details... STATUS

ABDM REQUIRED

19

Fix Critical Vulnerabilities in Appointments, Bahmni-lab, Bahmni-web, implementer-interface and patient-Documents images/jars

BAH-2557 - Getting issue details... STATUS

REQUIRED

20

Fix Critical Vulnerabilities in the crater-atomfeed repo

BAH-2786 - Getting issue details... STATUS

REQUIRED

  • No labels