Cyber Security Measures
At WhooshPro, we practise holistic security by design at every aspect of our business. From day-to-day operations to project deliveries for our clients. As a modern digital agency, we understand the need of strong cyber security measures to protect and safeguard our clients’ and our own digital wellbeing.
Today, agile methodology is the core of our project management style to deliver solutions for our clients timely, with quality, and securely. We adopt various agile concepts such as DevSecOps with security protection integrated into our development and operations processes right from the start.
Hence, agile security is a natural extension to our agile methodology.
Our Security Foundation Blueprint
Cyber Security at DevOps
Planning: continuous security review and risk analysis at the start of every sprint cycle, constantly educating and reminding teams of security guidelines and importance.
Development: static application security testing (SAST) built into development tools, as well as continuous team education on security, where developers are keenly aware of OWASP documented and evolving threats. White box security review coverage.
CI / CD: built-in automated security scans and tests where appropriate. Choice of hosting and provider platforms that are certified (e.g. ISO 27001), durable and highly available.
Testing: dynamic application security testing (DAST) and fixtures prior to deployment. Black box or grey box security review coverage.
Deployment: identity access management and restriction to different environments and resources to ensure restricted and limited access.
Monitoring: regular detection, patches, upgrades, and remediation to threats and vulnerabilities.
With the various security aspects well documented, understood, reviewed, practiced, and progressively improved in our security by design policy, and a culture of intentional constant reminding of people to follow good security hygiene practices, we inherently contribute to a more secure solution delivery pipeline to our customers. Ensuring robust secure systems outcome.
Apart from the deeply rooted internal security best practices that is continuously iterated and improved, we also work with external qualified security experts (such as CREST accredited entities) to perform vulnerabilities assessment and penetration testing (VAPT) where needed. All in all, protecting and ensuring security from the inside out.
Moreover, we are a Singapore CSRO licensed cyber security service provider. We fully understand the needs for total cyber security defence.
Our Strengths
Hear what our clients say.
See what we have done.