Quadrotech Nova Reporting cryptographic usage is based on Azure FIPS 140-2 compliant cryptographic functions. For more information, see: https://docs.microsoft.com/en-us/azure/storage/blobs/security-recommendations.
The Quadrotech Nova team follows a strict Quality Assurance cycle.
·Access to source control and build systems is protected by domain security, meaning that only employees on Quests corporate network have access to these systems. Therefore, should an On Demand developer leave the company, this individual will no longer be able to access Quadrotech Nova systems.
·All code is versioned in source control.
·All product code is reviewed by another developer before check in.
In addition, the Quadrotech Nova Development team follows a managed Security Development Lifecycle (SDL) which includes:
·MS-SDL best practices
·Threat modelling.
·OWASP guidelines.
·Regularly scheduled static code analysis is performed on regular basis.
·Regularly scheduled vulnerability scanning is performed on regular basis.
·Segregated Development, Pre-Production, and Production environments. Customer data is not used in Development and Pre-Production environments.
Quadrotech Nova developers go through the same set of hiring processes and background checks as other Quest employees.
Source control and build systems can only be accessed by Quest employees on Quests corporate network (domain security.) If a developer (or any other employee with access to Quadrotech Nova Reporting) leaves the company, the individual immediately loses access to the systems.
All code is versioned in source control.
Access to Quadrotech Nova Reporting data is restricted to:
·Quest Operations team members
·Particular Quest Support team members working closely with Quadrotech Nova Reporting product issues.
·The Quadrotech Nova Reporting development team to provide support for the product
Access to Quadrotech Nova Reporting data is restricted through the dedicated Quest Azure AD security groups. For different types of data (e.g., product logs, customer data, and sensitive data) different access levels and lists of allowed people are assigned.
© ALL RIGHTS RESERVED. Feedback 利用規約 プライバシー Cookie Preference Center