/
2019-04-08 Meeting notes
2019-04-08 Meeting notes
Date
Attendees
Goals
- Review outstanding tasks and issues
- Look at tasks for week ahead
Discussion items
Item | Who | Notes |
---|---|---|
Outstanding tasks | Tim Whitlock (Deactivated) |
|
PenTest Internet | Tim Whitlock (Deactivated) | The Internet PenTest is now available in R:\0 Systems\Projects\Pen Tests\Internet Jan 2019\Renal March 19 this highlights a number os potential issues with patientview.org, one with internationalradar.org and a few with the wordpress configurations for the main websites. In addition it highlighted the lack of captchas on the form entry on thinkkidneys.nhs.uk and renalreg.org which could leave them open to an automated attack. Tim Whitlock (Deactivated) has started working through the website configuration issues, George Swinnerton will feedback the patientview issues to SSG and Rapolas will address the international radar issues. |
Action items
- Tim Whitlock (Deactivated) to look at Atlassian tools update solution for Bitbucket and Atlassian tools moving forward.
- George Swinnerton to get Kings to resend all patient data and verify it has happened.
- George Swinnerton to chase the expansion of the Kings feed so an extract can be produced. He will highlight that without this no audit file will be available for the annual report
- George Swinnerton to look at resolving the whole question of study groups and programmemberships
- George Swinnerton to follow up with Fiona about the peadiatric data fields that don't map readily.
- rapolas (Unlicensed) to look at the internet PenTest report and resolve internationalradar issues.
- Tim Whitlock (Deactivated) to look at website security issues related to headers, .htaccess and ciphers for all sites
- George Swinnerton to follow up with SSG about penTest issues on patientview