Please describe your proposed solution
Iagon will leverage the services of the chosen auditors to engage in a full scale audit of the Iagon architecture as it is an important step to verifying the network in preparation for the Fortune 500 pilot.
This audit will evaluate the Iagon system, identify any possible vulnerabilities in the network and ensure its safety and security. Doing so will give Iagon the validation it needs from a well established auditing firm and will support a smooth continuation of enterprise adoption.
We are currently in talks with well-established firms like SecureWorks and Tweag for their expertise in security and architectural auditing. However, we are also exploring other options to ensure we choose the best fit for our needs.
The assessment will cover a variety of industry standard audits and security tests, including but not limited to:
- A high level architectural audit of all core web and blockchain components involved in running the network
- A penetration test of external facing services
- A web application security assessment for each of the web apps used to provide our core product offering
Iagon will also add Static Application Security Testing (SAST) and dependency analysis, as well as container scanning to our Software Development Lifecycle (SDLC) where applicable and not already present. These are common practices to prevent unsafe software by avoiding insecure code changes or using libraries that have security vulnerabilities.
What the audit will not cover:
- The Iagon smart contracts are already in the process of being audited and currently in the remediation phase, and as such will not require another audit phase.