Skip to main content
June 10, 2021
Question

Risk review information

  • June 10, 2021
  • 3 replies
  • 0 views

Hi ,

Can you help with below information for Appian?

  • Does Appian set HTTP response header for web content cache. (for data should not be cached on user's local disk.)
    • Cache-Control: no-cache, no-store
      Pragma: no-cache
      Expires: -1

 

  • Are XFS mitigation headers “Xframe-option”; “frame-src” are set for Appian?

 

  • Appian contain upload functionality but does it have Antivirus scan in place for the uploaded files.?

Thanks,

Pooja

    3 replies

    stefanhelzle0001
    Brainy
    June 10, 2021

    Uploaded files are virus scanned.

    For the other topics, AFAIK yes.

    June 11, 2021

    Hello Stefan/All,

    Thanks for Responding on Pooja's query. 

    For File Upload 's AV scanning functionality, how could we check those settings in Appian  (Do we have any UI interface or source code that confirms that AV scans are enabled for all  type of file uploads) - We need kind of evidence to justify Appian's feasibility on AV scanning for File Upload cases. - Kindly Advise 

    Please  Note we read below artical published as Appian Documentation in community portal:

    https://docs.appian.com/suite/help/21.2/Anti-Virus_on_Cloud.html#:~:text=By%20default%2C%20all%20Appian%20Cloud,Console%2C%20and%20the%20Appian%20Designer.

    However it tells about  AV scanning abilities of Appian in  Appian Cloud environment and not the standard Appian installation on Any Cloud host

    We also need similar evidences of other asked functionalities  when it comes to 

    1) web content cache

    2) XFS mitigation headers “Xframe-option”; “frame-src” are set for Appian

    Please advise. 

    stefanhelzle0001
    Brainy
    June 11, 2021

    OK. Feels like this is a compliance check. I suggest to get in contact with Appian. They will be happy to help.

    If you do a on-premise setup, then it is your job to set up things correctly. Including virus scanning, caching, headers etc.