CA PAM Security Posture and Penetration Testing Attestation Guidance
search cancel

CA PAM Security Posture and Penetration Testing Attestation Guidance

book

Article ID: 445373

calendar_today

Updated On:

Products

CA Privileged Access Manager (PAM)

Issue/Introduction

Customers require detailed information regarding the security/penetration testing scope and risk management practices for CA PAM to support internal cyber risk assessments and vendor due diligence, particularly concerning AI-enabled offensive threats.

Resolution

Broadcom adheres to a rigorous security framework for the CA PAM product. The following nine points outline our security posture, testing methodologies, and compliance documentation.

1. Third-Party Penetration Testing
Broadcom engages independent, accredited third-party security firms to perform comprehensive penetration testing on CA PAM. These tests are conducted at least annually or upon significant architectural changes to ensure unbiased validation of the product’s security controls.

2. Scope of Security Testing
The testing scope is exhaustive, covering:

  • Web Application Security: Evaluation against the OWASP Top 10 vulnerabilities (e.g., Injection, Broken Access Control, SSRF).
  • API Security: Testing of all RESTful and SOAP interfaces for unauthorized data exposure or manipulation.
  • System Hardening: Assessment of the underlying hardened Linux appliance and service configurations.
  • Cryptographic Controls: Validation of TLS configurations and encryption-at-rest implementations.

3. AI-Enabled Threat Mitigation
Our testing protocols are updated continuously to account for evolving AI-enabled offensive capabilities. This includes testing against automated vulnerability discovery tools and adversarial AI models that attempt to bypass traditional security heuristics.

4. Secure Software Development Lifecycle (SSDLC)
CA PAM is developed following the Broadcom SSDLC. This ensures security is integrated into every phase, from design (Threat Modeling) to deployment.

5. Continuous Vulnerability Management
Broadcom utilizes Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) throughout the development cycle. Vulnerabilities are prioritized using the CVSS (Common Vulnerability Scoring System) and addressed according to established SLAs.

6. Security Assurance Documentation
While full, raw penetration test reports are considered Broadcom Intellectual Property and are not shared, we provide a Security Attestation Letter or a Security Practice Summary. These documents attest that testing was performed, summarize the scope, and confirm that all high-risk findings have been remediated.

7. Supply Chain Security (Software Bill of Materials)
We perform regular analysis of third-party and open-source libraries used within CA PAM. This process mitigates supply chain risks by ensuring that components with known vulnerabilities (CVEs) are patched or replaced promptly.

8. Administrative and Logical Access Controls
CA PAM’s own security is enforced through strict logical separation, multi-factor authentication (MFA) support, and comprehensive audit logging, which are themselves subjects of our security testing.

9. Requesting Attestation Evidence
Customers requiring the latest "Security Assurance" document or the "Symantec PAM Security Practices" PDF should contact their Broadcom Account Director or open a support case to receive these restricted documents under a standard Non-Disclosure Agreement (NDA).