Compliance

ProRT-IP is designed to support compliance with industry standards and regulatory requirements for security scanning activities.

Industry Standards

OWASP Guidelines

ProRT-IP aligns with OWASP testing methodology:

OWASP CategoryProRT-IP Support
Information GatheringPort scanning, service detection
Configuration ManagementService version enumeration
Authentication TestingPort availability checks
Session ManagementTCP connection testing
Input ValidationProtocol-specific probes

OWASP Testing Guide Integration:

  • OTG-INFO-001: Conduct search engine discovery - Network enumeration
  • OTG-INFO-002: Fingerprint web server - Service detection
  • OTG-INFO-003: Review webserver metafiles - Port/service mapping
  • OTG-CONFIG-001: Test network infrastructure - Full network scanning

NIST Cybersecurity Framework

ProRT-IP supports NIST CSF functions:

FunctionActivityProRT-IP Feature
IdentifyAsset ManagementNetwork discovery, port scanning
IdentifyRisk AssessmentVulnerability identification
ProtectProtective TechnologyFirewall rule validation
DetectSecurity MonitoringNetwork change detection
RespondAnalysisIncident investigation support

NIST SP 800-115 Alignment:

  • Section 4: Planning - Scan scope definition
  • Section 5: Discovery - Network enumeration
  • Section 6: Vulnerability Analysis - Service detection
  • Section 7: Reporting - Multiple output formats

CIS Benchmarks

ProRT-IP can verify CIS benchmark controls:

# Check for unnecessary services (CIS 2.1.x)
prtip -sS -p 1-65535 target --top-ports 1000

# Verify firewall configuration (CIS 3.x)
prtip -sA -p 1-1000 target  # ACK scan for firewall rules

# Check network services (CIS 5.x)
prtip -sV -p 22,80,443,3389 target

Regulatory Requirements

GDPR (General Data Protection Regulation)

When scanning EU systems:

ArticleRequirementImplementation
Art. 6Lawful basisDocument authorization
Art. 5Data minimizationScan only necessary targets
Art. 32Security measuresEncrypt scan results
Art. 33Breach notificationReport within 72 hours

CCPA (California Consumer Privacy Act)

For California-related scanning:

  • Document business purpose for scanning
  • Implement reasonable security measures
  • Maintain records of processing activities
  • Honor data subject requests

PCI DSS

For cardholder data environments:

RequirementProRT-IP Support
11.2Quarterly network scans
11.3Penetration testing support
11.4IDS/IPS testing
# PCI DSS quarterly scan
prtip -sS -sV -p 1-65535 --top-ports 1000 pci-scope.txt \
    -oX pci-scan-$(date +%Y%m%d).xml

HIPAA

For healthcare environments:

SafeguardVerification Method
Access ControlPort/service inventory
Audit ControlsScan logging
IntegrityNetwork change detection
Transmission SecurityTLS certificate analysis

SOX (Sarbanes-Oxley)

For financial systems:

  • Document all scanning activities
  • Maintain audit trails
  • Verify access controls
  • Support change management

Security Certifications

ProRT-IP Security Status

AspectStatusDetails
Code AuditsRegularcargo audit, clippy
Memory SafetyRustNo buffer overflows
Dependency ScanningAutomatedGitHub Dependabot
Fuzz Testing230M+ executions0 crashes
Test Coverage54.92%2,151+ tests

Compliance Documentation

Audit Support

ProRT-IP provides audit-friendly features:

# XML output for compliance tools
prtip -sS -sV target -oX audit-scan.xml

# JSON for automated processing
prtip -sS -sV target -oJ audit-scan.json

# Greppable for quick analysis
prtip -sS target -oG audit-scan.gnmap

Documentation Requirements

DocumentRetentionPurpose
AuthorizationDuration of engagementLegal protection
Scan resultsPer retention policyAudit evidence
MethodologyIndefiniteProcess documentation
FindingsPer retention policyRemediation tracking

See Also