Application Security
The Sterling Portal, SCBConnect, utilizes a secure development framework, as well as a number of third party tools using techniques such as Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), that are peformed for every build and deployment, in addition to annual third party penetration testing.
Vulnerabilities in the software supply chain are identified and tracked to remediation via container scanning, source code scanning, and other techniques.
Our production environment is continually analyzed and scanned by a number of third party tools, such as AWS GuardDuty, AWS MACIE (for Data Loss Prevention), in addition to a number of in house and open source tools (such as Steampipe compliance monitoring).