1) Was Statuspage included in the penetration testing outlined by the pen test report available on the web site? That is, can we assume it was pen tested and all results are included in the report?
2) Does Atlassian have additional information on how their development practices and policies for Statuspage reflect their commitment to secure engineering? I found the CAIQ self assessment for Jira and Confluence Cloud, HipChat and Bitbucket cloud offerings, but Statuspage is more elusive.
I'm interested in these areas:
- Education/Awareness,
- Project Planning,
- Threat Modeling,
- Security Requirements,
- Secure Coding, and
- Security Testing.
This would answer questions like:
- Do developers receive secure coding education?
- How is Statuspage tested besides its external pen testing?
- Are there secure coding standards in place which Atlassian can share?
- Can Atlassian share its Threat Model for Statuspage, or give more information on how threat modeling is used in design and development and testing of the product?