Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Review TagUI security features to either improve or document well - done #1028

Closed
kensoh opened this issue May 4, 2021 · 7 comments
Closed
Assignees
Labels

Comments

@kensoh
Copy link
Member

kensoh commented May 4, 2021

Some starting points from Nandan, a reputable RPA influencer - https://www.linkedin.com/in/nandanmullakara/

https://botnirvana.org/4-steps-to-ensure-robotic-process-automation-security/

https://botnirvana.org/gsa-helping-agencies-overcome-mental-barrier-fielding-unattended-bots/

https://www.blueprism.com/uploads/resources/white-papers/Blue-Prism-Security-Guide-2020.pdf

@kensoh kensoh added the feature label May 4, 2021
@kensoh kensoh self-assigned this May 4, 2021
@kensoh
Copy link
Member Author

kensoh commented May 27, 2021

Also linking to - #959 (comment)

@kensoh
Copy link
Member Author

kensoh commented Jun 4, 2021

@kensoh
Copy link
Member Author

kensoh commented Jun 8, 2021

@kensoh
Copy link
Member Author

kensoh commented Jun 8, 2021

This link below, first 2 topics are not relevant for bottom-up decentralised RPA, topic on audit and logging is done with report option and to be enhanced in #956, topic on version and change control users will be using MS Word documents as robots, version control is normally done by naming the file version.

https://botnirvana.org/4-steps-to-ensure-robotic-process-automation-security/

@kensoh
Copy link
Member Author

kensoh commented Jun 8, 2021

https://www.blueprism.com/uploads/resources/white-papers/Blue-Prism-Security-Guide-2020.pdf

For above link on security features of Blue Prism, many topics are irrelevant because -

  • TagUI's default implementation is an on-user-computer on-prem application that does not exist on any cloud
  • industry specific certifications like PCI-DSS, HIPAA, SOX aren't applicable because TagUI doesn't store data
  • TagUI isn't a SaaS or software on the cloud running on vendor's cloud, it runs on actual user's computers
  • in decentralised RPA, no need and not advisable to have bot credentials as users are held accountable

The topic on encryption is relevant, following are recommended best practices for TagUI -

  • For data at rest, storage encryption would be on user's computer OS-level as it is run on user's computer
  • For data in use, recommend user to manually enter sensitive info like passwords before letting robots take over
  • For data in motion, users enterprise apps websites are now https by default for secure data entry and retrieval

@kensoh kensoh changed the title Review TagUI security features to either improve or document well - to explore Review TagUI security features to either improve or document well - done Jun 8, 2021
@kensoh
Copy link
Member Author

kensoh commented Jun 8, 2021

@kensoh
Copy link
Member Author

kensoh commented Jun 18, 2021

Closing issue, change included in latest packaged release - https://github.com/kelaberetiv/TagUI/releases/tag/v6.46.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant