16. Vulnerability Management
Thru maintains a strong vulnerability management program to proactively identify, assess, and mitigate security weaknesses.
16.1 Vulnerability Scanning
Conducts regular automated scans using industry-leading tools.
Covers network devices, servers, and web applications.
Prioritizes vulnerabilities by severity and potential impact.
Integrates scanning results into the overall risk management process.
16.2 Patch Management
Applies security updates and patches through a structured approach.
Schedules regular updates and expedites critical patches.
Tests patches in a staging environment before deployment.
Uses automated tools for consistent and error-free patch deployment.
16.3 Penetration Testing
Conducts annual third-party penetration tests by certified professionals.
Includes network, applications, and APIs in the testing scope.
Simulates attacks to identify vulnerabilities and assess defenses.
Provides detailed reports and conducts follow-up testing for remediation.
This comprehensive program enhances our security posture by continuously addressing potential weaknesses, ensuring the reliability and security of our Managed File Transfer services.