Here in the company that I work, we have an integr...
# general
l
Here in the company that I work, we have an integration with a thirdparty company to perform bank payments. We want to perform a penetration test regarding NetSuite and this thirdparty company security. I tried to reach Oracle but they couldn't care less about my request. Does anyone knows if this is a problem?
j
Check the contract, I think NetSuite does not allow any penetration testing or load testing. Different things but I know a company I worked at and they were close to trouble because of it
n
Hi Luis, I 2nd JC's response. The terms of service / usage prohibit penetration testing https://www.netsuite.com/portal/assets/pdf/terms-of-service-v010118.pdf
That being said, you can go to the security page and/or your TAM (if you have one) and print out or request the security certifications that NetSuite maintains. With being a PCI level 1 they are required to perform quarterly penetration tests by an approved 3rd party