Before I go into my views surrounding this topic, I hope that anyone reading it to assume it as constructive instead of a dig at the product (AwareIM).
AwareIM is an amazing piece of software, like all software it does contain bugs that are unforeseen and as IT aware individuals providing solutions to individuals/organisations we need to have a level of awareness (pun not intended) regarding basic security and architecture to protect our solutions created with AwareIM.
General Data Protection Regulation (GDPR), Office of the Australian Information Commissioner (OAIC), Local data privacy laws and internal business policies are not going to make life any easier; especially to the IT developer who provides solutions designed with AwareIM.
Most external security audits and local IT departments will look at both external/internal security (firewalls , networks isolation , security certificates, ACL , auditing) and component level software versions as a starting point.
I would like to suggest the following as it might help.
Releases:
Emergency release [Anytime – Out of band]– Critical product update to address potential/imminent vulnerability (any component, script, feature that makes up AwareIM).
Major release [Once a year]– New features and updates that can be rolled together.
Minor release [Twice a year] – Component level updates (DB connectors, Tomcat, ActiveMQ, Kendo, Eclipse et al).
Bug fixes [Anytime] – Updates to existing functions that are broken, scripts and engine related issues.
Secretly a forth class of update…
Special dooper, some CEO paid for this at an exorbitant rate over $25k and we get free beers at conference and free stuff! - [Anytime]
Obviously this will not keep everyone happy, however I think its a good balance between ensuring problems get addressed and security moves in the right direction.
Now, its all good being a stealthy poster and leaving AwareIM team to do all the leg work. 8-)
I’d like to donate some time to help move AwareIM if they wish to consider moving towards this model, maybe we should make it a community effort to keep licensing overheads low? 😮 :oops: :mrgreen: