Fortra® Security & Trust Center

Secure by Design at Fortra

Text

Fortra has signed CISA’s Secure by Design Pledge because we believe that software should be safe to use from day one. That is why we are committed to developing software that is built securely, with secure components, and comes with secure defaults. This approach is both forward-looking for new development and backward-looking improving code and default configurations in the software our customers have used and trusted for years. 

The Secure by Design Pledge has seven focus areas and target goals: 

Focus Areas and Goals

The Secure by Design Pledge has seven focus areas and target goals: 

Multi-Factor Authentication (MFA)

To protect against password-based attacks, implementing phishing-resistant controls is one of the most effective defenses. MFA is the most common approach to this problem, and applications should allow for or enforce this control, especially when handling sensitive data or elevated privileges. 

Fortra offers or requires MFA in several of our products, including all our SaaS-based offerings, such as Fortra’s Platform, Fortra’s GoAnywhere MFT, Fortra’s Data Security, and Fortra’s Secure Collaboration, as well as many of our on-premises products. Our goal is to implement phishing-resistant access in every product where it provides the most protection. 

Secure by Design Report

Text

Fortra’s commitment to Secure by Design development includes being transparent about what we are doing to enhance the security of our products. As part of our pledge, we will publish an annual report coinciding with Fortra Release Days and documenting our progress against the seven focus areas outlined above. This report will communicate our efforts along with metrics based on the pledge goals. For example, a survey of our products and our progress toward eliminating default passwords, the number of CVEs released in the previous quarter, and our efforts to eliminate entire classes of vulnerabilities.  

Text

At a Glance

Category

Goal

How Fortra Is Addressing This

Multi-Factor Authentication (MFA) 

Within one year of signing the pledge, demonstrate actions taken to measurably increase the use of multi-factor authentication across the manufacturer’s products.

We have made good progress towards implementing MFA in all our products, several products that didn’t previously support MFA now do in their latest releases. This control remains in the maintenance status.
Default Passwords 

Within one year of signing the pledge, demonstrate measurable progress towards reducing default passwords across the manufacturer's products.

Our development teams have made significant progress towards eliminating default passwords; the majority of Fortra products do not contain default passwords at all, and several products that previously included them have since eliminated them. This control is in the maintenance status.
Reducing Entire Class of Vulnerability 

Within one year of signing the pledge, demonstrate actions taken towards enabling a significant measurable reduction in the prevalence of one or more vulnerability classes across the manufacturer’s.

Given the breadth of products offered by Fortra, it is difficult to implement changes that positively affect all our products. While we are working tirelessly to improve our legacy products, we are also implementing this control on our new offerings. We are committed to utilizing the best of breed tools and languages, and we are careful about which we choose to develop new products. We are giving special attention to using memory safe languages and to making other sweeping decisions that automatically block whole classes of vulnerabilities.
Security Patches 

Within one year of signing the pledge, demonstrate actions taken to measurably increase the installation of security patches by customers. 

This control is in the maintenance status as we continue to regularly publish security patches, for our on-prem solutions we automatically deploy those patches as well, we also work with self-hosted customers to ensure they apply these patches in a timely fashion.
Vulnerability Disclosure Policy 

Within one year of signing the pledge, publish a vulnerability disclosure policy (VDP). 

Complete
Common Vulnerabilities and Exposures (CVE) 

Within one year of signing the pledge, demonstrate transparency in vulnerability reporting. 

See complete list here.
Evidence of IntrusionsWithin one year of signing the pledge, demonstrate a measurable increase in the ability for customers to gather evidence of cybersecurity intrusions affecting the manufacturer’s products. We have been working diligently to achieve this control. Previously, an internal survey found that only 12% of solutions lacked evidence of intrusion and since then several of those products have implemented logging to meet this goal. 

When we reviewed our survey answers with teams, we found a slight increase in products that used it (+2%), a modest decrease in those that don’t (-10%) and a modest increase where MFA was “N/A” (+10%), meaning we had respondents conservatively answering “False” when MFA was not applicable for their products (e.g., no interactive logins). For the remaining 22% of products that are not using MFA, there is not a strong use case for this control based on the context of the access. For instance, products running on IBM i may defer this control to the OS or integrate with Powertech Multi-Factor Authentication. We are considering this control in Maintenance status now. 

 

Default Passwords

The use of default passwords in Fortra products is rare base on our survey, however, we did find instances where the practice was used (18% use default passwords). Several of those products now have backlog items to mitigate or remediate the weakness which will find their way into a future release. Throughout Q2 we will track the teams’ progress in replacing default passwords with safer options and ensure this pattern is not used in new development.

 

Evidence of Intrusions

Like default passwords, most of Fortra’s products provide logging to help defenders detect evidence of intrusion affecting the software. 70% of products provided evidence of intrusion while only 12% did not. We will assess the logging gaps in those products and determine how we can provide customers with the information they need to respond quickly to incidents in their environments. Logging strategies and configurations are being evaluated and updates are planned to close the gap.

 

Reducing Entire Class of Vulnerability

The current approach to this goal is to leverage existing patterns and frameworks that have built in mitigations against attacks such as XSS, and SQLi. Fortra also has an inner-source project underway to standard approaches to common problems and centralize good security hygiene. Benchmarking this goal is a challenge and we are testing ways we can scan or discover vulnerability hot-spots that could benefit from targeted approaches. 

 

Security Patches

For customers in our cloud-hosted and SaaS environments such as Fortra Platform, Fortra VM, and Tripwire ExpertOps customers never have to worry about being on the latest version. Fortra deploys updates as soon as we are able to deploy them. The Platform even allows for real-time updates of the Fortra Agent.

With customers in air-gapped and isolated on-premises environments, ensuring they have the latest software can be a challenge. Fortra is committed to providing timely communication to our on-premises customers when updates are available and we are working to determine which products have the highest barriers to upgrades. 

 

Vulnerability Disclosure Policy

In December of 2023, Fortra became a CVE Numbering Authority (CNA) and as part of that effort published its vulnerability disclosure policy on Fortra.com. Fortra welcomes external researchers to contact us with any security issues they find in our products and our research teams are committed to responsible disclosure to better safeguard our digital world.

 

CVEs

As a CNA, Fortra now publishes their own CVEs when discovered. In 2024 Fortra published 14 CVEs for its own products and two for an external vendor. Fortra-published CVEs can be found in the Security Advisories area on Fortra.com. We will continue to provide transparency and fixes so our customers can effectively manage their risk posture.

Learn More About Fortra Products and Public Trust Center

Our Soutions