# ncc

Published articles for ncc.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Announcing the results of Istio's first security assessment

DevFeed: [Announcing the results of Istio's first security assessment](<https://devfeed.tech/articles/announcing-the-results-of-istio-s-first-security-assessment-48735.md>)

Original publisher: [Read original article](<https://istio.io/latest/blog/2021/ncc-security-assessment/>)

Author: Neeraj Poddar (Aspen Mesh), on behalf of Istio Product Security Working Group

Published: 2021-07-13T00:00:00Z

Content type: release

Language: en

Sources: [Istio Blog](<https://devfeed.tech/sources/istio-blog.md>)

Topics: [istio](<https://devfeed.tech/topics/istio.md>), [Security](<https://devfeed.tech/topics/security.md>), [service-mesh](<https://devfeed.tech/topics/service-mesh.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>)

Tags: [assessment](<https://devfeed.tech/tags/assessment.md>), [audit](<https://devfeed.tech/tags/audit.md>), [documentation](<https://devfeed.tech/tags/documentation.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [istio](<https://devfeed.tech/tags/istio.md>), [mesh](<https://devfeed.tech/tags/mesh.md>), [microservices](<https://devfeed.tech/tags/microservices.md>), [ncc](<https://devfeed.tech/tags/ncc.md>), [releases](<https://devfeed.tech/tags/releases.md>), [security](<https://devfeed.tech/tags/security.md>), [services](<https://devfeed.tech/tags/services.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

Istio announces the results of a five-week third-party security assessment by NCC Group. The review examined the Istio codebase, architecture, security configurations, documentation, and components including istiod, ingress and egress gateways, and Envoy. Auditors found no critical issues; subsequent releases resolved all high-severity issues and several medium- and low-severity issues, while the project added a hardening guide and continued security evaluation.

### Source excerpt

The Istio service mesh has gained wide production adoption across a wide variety of industries. The success of the project, and its critical usage for enforcing key security policies in infrastructure warranted an open and neutral assessment of the security risks associated with the project. To achieve this goal, the Istio community contracted the NCC Group last year to conduct a third-party security assessment of the project. The goal of the review was "to identify security issues related to the Istio code base, highlight high-risk configurations commonly used by administrators, and provide perspective on whether security features sufficiently address the concerns they are designed to provide". NCC Group carried out the review over a period of five weeks with collaboration from subject matter experts across the Istio community. In this blog, we will examine the key findings of the report, actions taken to implement various fixes and recommendations, and our plan of action for continuous security evaluation and improvement of the Istio project. You can download and read the unabridged version of the security assessment report. Scope and Key Findings The assessment evaluated Istio's architecture as a whole for security related issues with focus on key components like istiod (Pilot), Ingress/Egress gateways, and Istio's overall Envoy usage as its data plane proxy. Additionally, Istio documentation, including security guides, were audited for correctness and clarity. The report was compiled against Istio version 1.6.5, and since then the Product Security Working Group has issued several security releases as new vulnerabilities were disclosed, along with fixes to address concerns raised in the new report. An important conclusion from the report is that the auditors found no "Critical" issues within the Istio project. This finding validates the continuous and proactive security review and vulnerability management process implemented by Istio's Product Security Working Gr