Penetration and load test notification
If you, or a third party acting on your behalf, plan to perform a penetration test or significant load testing on your cloud.gov Platform applications, or cloud.gov Pages sites, please send the following information to cloud.gov support ahead of your planned test:
* Web applications or website under test: Examples would include:
_webapp_.agency.gov or _webapp_.app.cloud.gov
_site_.agency.gov or preview_url.pages.cloud.gov
* Testing organization and contact/liaison information:
* Source IPs or IP ranges (for testers and their tools):
* Expected start date, (or "starting immediately"):
* Expected end date:
* Acknowledgement that you are abiding by the terms at https://cloud.gov/docs/compliance/pentest/
This notification is only necessary for in-depth security testing or significant load-testing, which is a common step in agency ATO processes for customer systems and in the software development lifecycle. You don’t need an approval, and cloud.gov doesn’t provide approvals. Simply sending the notification is sufficient. You can always run routine automated vulnerability scans on your own applications without special notification.
When arranging a security assessment or penetration test, the system under test is one of:
- cloud.gov Platform: your application at application-name.app.cloud.gov, or your external domain (e.g. https://agency.gov)
- cloud.gov Pages: your website at your preview URL (at
sites.pages.cloud.gov
), or your external domain (e.g._site_.agency.gov
)
For cloud.gov Platform systems, you can also conduct testing of:
- Your application instance via
cf ssh
- Your brokered services either directly or via
cf ssh
orssh
proxy.
You are not permitted to attempt any scanning or reconnaissance from your instances or brokered services.
You are not permitted to test the cloud.gov infrastructure, which comprises the following sites and web applications:
https://pages.cloud.gov
https://pages-staging.cloud.gov
https://cloud.gov
https://*.fr.cloud.gov
(If you have a legacy application in the .fr.cloud.gov
subdomain, please contact support.)
Your assessment must not target other cloud.gov customers, nor perform or simulate denial of service attacks or otherwise violate the Amazon AWS testing policy.
If you suspect that you have uncovered a vulnerability in any of cloud.gov’s products, please reference our security.txt
All cloud.gov products are under regular testing by our team, and by third-party assessors, as part of our Continuous Monitoring plan. FedRAMP® makes the results available to authorized users.