7 posts found
1 September 2026 · By P LarnerArticle
Goal five of the CISA pledge is the one with a hard deliverable, which is a published vulnerability disclosure policy. Ours is live, machine-readable and now carries the affirmative authorisation CISA asks for. Here is how to report, and what is still thin.
Secure by Design#security.txt#safe harbour#coordinated disclosure#Secure by Design#vulnerability disclosure
Read more →1 September 2026Article
Goal four of the CISA pledge asks manufacturers to make patching easier, and its first suggestion is automatic updates. RaptorGRC cannot auto-update by design, so this is what we built instead and what it still does not do.
Secure by Design#Secure by Design#air-gapped#supply chain#releases#patching
Read more →1 September 2026 · By P LarnerArticle
Goal one of the CISA pledge asks for measurably more multi-factor authentication. This is what RaptorGRC and the customer portal ship today, what an administrator controls, and the enforcement default we have not changed yet.
Secure by Design#MFA#TOTP#authentication#SSO#Secure by Design
Read more →1 September 2026 · By P LarnerArticle
Goal six of the CISA pledge is about CVE records with accurate CWE and CPE fields. RaptorGRC has never had a CVE and we have never issued one, so this article covers what we publish instead and what we would do the day that changes.
Secure by Design#CVE#SBOM#transparency#Trivy#CycloneDX#Secure by Design
Read more →1 September 2026 · By P LarnerArticle
Goal seven of the CISA pledge asks manufacturers to give customers the means to gather evidence of an intrusion. RaptorGRC has an audit log in every deployment. This is what it captures, why its queue refuses new entries rather than discarding old ones, and the four things it does not do yet.
Secure by Design#SIEM#audit log#incident response#Secure by Design#logging
Read more →1 September 2026 · By P LarnerArticle
Goal three of the CISA pledge asks manufacturers to remove whole classes of flaw rather than individual bugs. The three classes we picked, the analysers and pipeline jobs that enforce them, and three places where our own pledge page overstates the enforcement.
Secure by Design#memory safety#SQL injection#Secure by Design#XSS#static analysis
Read more →1 September 2026 · By P LarnerArticle
Goal two of the CISA pledge is about universally shared default credentials. RaptorGRC has never shipped one, and the container will not start unless you supply an administrator password. Here is the mechanism, and the gaps around it.
Secure by Design#containers#password policy#Secure by Design#default passwords#deployment
Read more →