May 2018 Summaries
4 posts from Bugcrowd
Filter
Month:
Year:
Post Summaries
Back to Blog
Bugcrowd has achieved SOC 2 Type I compliance, a framework for documenting and publishing information security policies and procedures. This achievement demonstrates the company's commitment to security, following rigorous testing of its infrastructure and data control policies against industry standards. Building on its existing ISO 270001 certification, Bugcrowd is now the first in the crowdsourced security industry with multiple audited controls, showcasing its dedication to holding high standards for security processes, people, researchers, and technology. The company's ongoing commitment to security is reflected in its goal to demonstrate compliance for SOC 2 Type II, further validating its control strength.
May 30, 2018
261 words in the original blog post.
The bug bounty model brings together security researchers from around the world, including tens of thousands from over 100 countries, to help organizations identify vulnerabilities in their code. These researchers are not all professional hackers, but rather white hat hackers who approach breaking into code like an adversary to help combat cyber attacks. Many of these researchers work full time in security and use bug bounty programs as a way to stay up-to-date on their skills or earn extra income. The motivations of bug hunters vary widely, with many reinvesting earnings back into their craft and others seeking to expand their knowledge and build their skill set through the challenge of the hunt. Bugcrowd's crowd is vetted through an identity verification process, which may be useful for organizations that require specific skill-sets or compliance reasons.
May 25, 2018
533 words in the original blog post.
Bug bounty programs are often misunderstood as being too risky, but the risks can be mitigated with the right processes and controls in place. By understanding that traditional testing methods have limitations, organizations can reduce their vulnerability to known threats by engaging with external security researchers. With a clear scope and budgeting, companies can minimize unknown variables and manage their risk. Working with a trusted partner or running a private program also lowers potential risks and ensures accountability among community members.
May 18, 2018
641 words in the original blog post.
In our recently released guide, 7 Bug Bounty Myths, Busted, we addressed some common misconceptions about the bug bounty model and bug bounty programs. Many companies, including those in finance, automotive, retail, IT security, education, and healthcare, are now engaging with the bug bounty model to improve their cybersecurity defenses. While tech companies were among the first to adopt this approach, it is no longer exclusive to them. The widespread adoption of bug bounty programs by enterprise organizations has just begun to take off, providing an opportunity for complex organizations to level the cybersecurity playing field and combat external threats.
May 11, 2018
639 words in the original blog post.