Security Requirement to scan for passwords in Jazz products
Hi,
My customer has a requirement that they must scan all source code in RTC, requirements in RRC and Test artefacts in RQM for plain text passwords to ensure that someone has not embedded password text into artefacts stored in Jazz. Specifically they want to scan for:
- Keyword search to find indicators of where a password may be present for keywords such as “password” or “passwd”.
- Pattern search passwords – this is a regular expression search for all text strings that conform to corporate security standards for valid passwords.
Has anyone implemented such a requirement before?
If so, how and with what tools ?
Cheers
Adrian
One answer
You can use "Full Text Search" to identify most occurrences. That is the text search box in the upper right hand corner of the web UI and it covers all of the primary artifacts.
For QM, this is going to be Plans, Cases, Scripts, Results, Suites, etc. I am not going to claim it's truly exhaustive (e.g. there may be some bits of text not indexed), but it's there already and will hit the majority of instances covering the most likely places where you'd hit SPI slip that you describe.
For QM, this is going to be Plans, Cases, Scripts, Results, Suites, etc. I am not going to claim it's truly exhaustive (e.g. there may be some bits of text not indexed), but it's there already and will hit the majority of instances covering the most likely places where you'd hit SPI slip that you describe.
Comments
sam detweiler
May 07 '14, 8:26 a.m.