We are using SAS VA 7.4 on our intranet. Which obviously means this gives no access to anyone outside our domain. Anyone who has to access the dashboard has to connect to the domain through VPN. The server has firewall restriction enabled and Mcfxxx full security application is also installed. Because of settings mentioned in the local environment (non-internet), we installed and left at HTTP and not https. now my infrastructure & security is recommending us to move to https / SSL stating that "an Open HTTP is a risk for internal threats as well. Root Cause for many of the `Top 10 OWASP Threats’ like `Cross-site scripting’ is open HTTP access. I understand it can be org decision, but I want to know if this was necessary. If by decision, HTTPS is always recommended then, why have an option for HTTP. By Default, SAS can have their default installation settings to HTTPS. Sometimes people do because they are asked to do or they are told that it is better safe than sorry though it may not warrant one. Metaphorically, I don't want to buy an antivirus software when I don't have a computer or mobile phones for the virus can attack me. Regards, Arvind E
... View more