Web Application Vulnerability Scanning
MedIT performs proactive online vulnerability scanning on websites and web applications that contain confidential and (in particular) protected data (such as personal information, or PI), to ensure that all known vulnerabilities have been addressed, and that all reasonable security controls are in place. For new websites and web applications, the need for vulnerability scanning is usually identified during the assessment phase of the Faculty’s Information Risk Management Program, in which the sponsor of the system describes the types of data the system will contain, and outlines the security controls that will be in place to protect it. For existing systems, vulnerability scanning will be performed based on an inventory of high-risk systems maintained by MedIT.