Linux OS and app security

Status
Not open for further replies.

Puddin

Customer
Joined
Mar 18, 2019
Messages
18
Reaction score
0
Does the Linux OS and application go through some sort of third party or internal security testing validation to ensure that it is hardened and validated to prevent exploitation? This would be more than the published firewall and documented settings.

Thanks,
Ken
 
What do you mean by the Linux OS? Are you talking in general or are you asking specifically about the 3CX provided ISO. Either way the short answer to this question is if this is something that matters to you then you basically fall in one of three categories:

  • You've done this before and you know how to secure things to meet your requirements.
  • You can work around your requirements by putting your 3CX outside of whatever protected network has this requirement.
  • You move on to something that meets your needs that is likely appliance based.

If you can be more specific as to what you are trying to achieve compliance for (HIPPA, SOX, PCI, DFARS, etc) then you might get more specific answers.
 
Is the Debian OS hardened or is that the responsibility of the customer? Is the OS updated with patches from 3CX or is it up to the customer to update and maintain the Debian OS? Are there any known vulnerabilities of the 3CX PBX application itself?
 
It's hardened in the sense that it uses current packages upon installation (Debian) and firewall rules to allow traffic specifically on the 3CX required ports. Anything beyond that is up to you. And this is assuming you are using the 3CX ISO. If you do a manual install then everything is up to you.

If there are any known vulnerabilities in 3CX they keep that under wraps.
 
  • Like
Reactions: Nick W
It's hardened in the sense that it uses current packages upon installation (Debian) and firewall rules to allow traffic specifically on the 3CX required ports. Anything beyond that is up to you. And this is assuming you are using the 3CX ISO. If you do a manual install then everything is up to you.

If there are any known vulnerabilities in 3CX they keep that under wraps.

we have actually one more OS function which is controlled which is OS Security Patches. We test all security patches been issued by Debian and can apply them to be installed with the auto upgraded option. If this is enabled, not only the PBX udpates but we also apply security OS patched.
 
Thanks for all replies.
 
Status
Not open for further replies.

Members Online Now

Forum statistics

Threads
111,832
Messages
589,284
Members
164,662
Latest member
DejanMDS