Customers require detailed information regarding the security/penetration testing scope and risk management practices for CA PAM to support internal cyber risk assessments and vendor due diligence, particularly concerning AI-enabled offensive threats.
Broadcom adheres to a rigorous security framework for the CA PAM product. The following nine points outline our security posture, testing methodologies, and compliance documentation.
1. Third-Party Penetration Testing
Broadcom engages independent, accredited third-party security firms to perform comprehensive penetration testing on CA PAM. These tests are conducted at least annually or upon significant architectural changes to ensure unbiased validation of the product’s security controls.
2. Scope of Security Testing
The testing scope is exhaustive, covering:
3. AI-Enabled Threat Mitigation
Our testing protocols are updated continuously to account for evolving AI-enabled offensive capabilities. This includes testing against automated vulnerability discovery tools and adversarial AI models that attempt to bypass traditional security heuristics.
4. Secure Software Development Lifecycle (SSDLC)
CA PAM is developed following the . This ensures security is integrated into every phase, from design (Threat Modeling) to deployment.
5. Continuous Vulnerability Management
Broadcom utilizes Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) throughout the development cycle. Vulnerabilities are prioritized using the CVSS (Common Vulnerability Scoring System) and addressed according to established SLAs.
6. Security Assurance Documentation
While full, raw penetration test reports are considered Broadcom Intellectual Property and are not shared, we provide a Security Attestation Letter or a Security Practice Summary. These documents attest that testing was performed, summarize the scope, and confirm that all high-risk findings have been remediated.
7. Supply Chain Security (Software Bill of Materials)
We perform regular analysis of third-party and open-source libraries used within CA PAM. This process mitigates supply chain risks by ensuring that components with known vulnerabilities (CVEs) are patched or replaced promptly.
8. Administrative and Logical Access Controls
CA PAM’s own security is enforced through strict logical separation, multi-factor authentication (MFA) support, and comprehensive audit logging, which are themselves subjects of our security testing.
9. Requesting Attestation Evidence
Customers requiring the latest "Security Assurance" document or the "Symantec PAM Security Practices" PDF should contact their Broadcom Account Director or open a support case to receive these restricted documents under a standard Non-Disclosure Agreement (NDA).