Implementing Burp Suite Enterprise Edition involves several key steps:
Planning and Preparation:
Define Objectives: Clearly outline your organization's security goals and how Burp Suite Enterprise Edition will help achieve them.
Select Deployment Method: Choose between a standard installer for on-premises or cloud-based services, a Kubernetes deployment, or CI-driven scans without a dashboard.
Determine Architecture: Decide on a single-machine setup or a multi-machine architecture with dedicated scanning machines and an external database, based on your scalability needs.
Review System Requirements: Ensure your infrastructure meets the necessary specifications for your chosen deployment method.
Installation and Configuration:
Install the Application: Download and run the installer appropriate for your deployment choice.
Configure Initial Settings: Set up an administrator account, connect to your database, and upload a TLS certificate if required.
Integration and Testing:
Integrate with Development Processes: Connect Burp Suite Enterprise Edition with your CI/CD pipelines and issue-tracking systems to automate scanning.
Conduct Test Scans: Perform initial scans to verify the setup and ensure that the system identifies vulnerabilities as expected.
Training and Documentation:
User Training: Provide training sessions for security teams and developers to effectively use the platform.
Documentation: Compile internal guides and best practices to assist users in navigating and utilizing the system.
Go-Live and Monitoring:
Launch: Begin full-scale operations with Burp Suite Enterprise Edition integrated into your security workflow.
Burp Suite Enterprise Edition offers extensive customization options to align with specific business needs. Key customization features include:
Custom Scan Configurations: Define detailed settings such as crawl depth, request throttling, and specific vulnerability checks to tailor scans to your application's requirements.
Extensions and BApps: Enhance functionality by adding extensions from the BApp Store or developing custom ones. Extensions can implement custom scan behaviors and capabilities, allowing for tailored vulnerability detection and reporting.
BChecks: Create and import custom scan checks (BChecks) to target specific vulnerabilities unique to your applications. This enables more precise and efficient testing workflows.
Integration with CI/CD Pipelines Seamlessly integrate with various CI/CD platforms to automate security scans within your development processes, ensuring timely identification and remediation of vulnerabilities.
Role-Based Access Control: Implement RBAC to manage user permissions effectively, ensuring that team members have appropriate access levels based on their roles.
Single Sign-On (SSO) Integration: Integrate with SSO solutions like SAML or LDAP to streamline user authentication and enhance security.
Issue Tracking Integration: Connect with platforms such as Jira, GitLab, and Trello for efficient tracking and management of identified vulnerabilities, facilitating seamless collaboration between security and development teams.
Customizable Reporting: Generate tailored reports with specific details, severity levels, and confidence ratings to meet organizational reporting standards and compliance requirements.
Pricing details are not publicly listed and require direct contact with PortSwigger for a tailored quote.
PortSwigger provides documentation and support to assist with installation, but no formal setup service fees are commonly reported.
No separate maintenance contracts or fees are typically required.
Higher-tier or premium support options may be available but are not commonly detailed publicly and may involve additional fees.
For cloud-hosted or managed deployment options (if offered), additional hosting fees may apply, but these are not standard Burp Suite charges.
Training can help teams accelerate adoption and improve security testing processes.
Burp Suite Enterprise Edition offers a range of training and support resources to assist new users in effectively utilizing the platform:
Training Resources:
Web Security Academy:
Provides high-quality learning materials, interactive vulnerability labs, and video tutorials.
Allows users to learn at their own pace with over 190 interactive labs covering various web security topics.
Regularly updated with new material and labs to keep up with the latest developments in web security research.
Video Tutorials:
A series of tutorials covering product essentials such as site configuration, setting up scanning machines, and integrating Burp Suite Enterprise Edition with CI/CD platforms.
Designed to help users get to grips with all the basics of the platform.
Specialist Training Partners:
PortSwigger collaborates with specialist training partners worldwide to offer hands-on courses for both novice and advanced users.
These courses provide practical training on using Burp Suite to find real-world vulnerabilities.
Users can contact these partners directly to discuss options for tailored on-site training.
Support Resources:
Support Center:
A comprehensive hub containing numerous articles, step-by-step guides, and video tutorials to assist users with various aspects of Burp Suite.
Users can access extensive product documentation and get help and advice from experts on all things Burp.
Technical Support:
Provided free of charge to all users via the Support Center.
The support team is available to answer technical queries Monday to Friday between 9 am and 5 pm UK time, typically providing an initial response within one working day.
Documentation:
Comprehensive guides are available to help users set up and effectively use Burp Suite Enterprise Edition.
Burp Suite Enterprise Edition implements several security measures to protect user data:
Data Security Measures: PortSwigger, the developer of Burp Suite Enterprise Edition, has implemented appropriate security measures to prevent personal data from being accidentally lost, used, or accessed in an unauthorized way.
Compliance Reporting: The platform offers reporting aligned with the OWASP Top 10 2021 list and the PCI DSS v4.0.1 security compliance standard, assisting organizations in maintaining compliance with industry standards.
Burp Suite Enterprise Edition has the following policies regarding data ownership and portability:
Data Ownership:
The customer (licensee) retains ownership of all data processed by Burp Suite Enterprise Edition.
PortSwigger acts as a data processor on behalf of the customer for any personal data incidentally collected as part of their service.
Data Portability:
PortSwigger has processes in place to handle data portability requests.
Customers can contact [email protected] to make data portability requests.
Data Minimization and Retention:
PortSwigger has data protection policies that build in data minimization.
These policies cover how personal data may be used, transferred, stored, and deleted.
Data retention policies are in place which comply with applicable laws and are reviewed regularly.
Data Processing Agreement:
PortSwigger offers a Data Processing Agreement (DPA) for customers using Burp Suite Enterprise Edition in a software-as-a-service capacity.
The DPA outlines the terms under which PortSwigger processes personal data on behalf of the customer.
Data Protection:
PortSwigger implements technical and organizational measures to ensure appropriate security of processed data.
This includes measures for data protection during transmission and storage, such as encryption.
Data Subject Rights:
Burp Suite Enterprise Edition provides flexible scaling options designed to accommodate the evolving needs of organizations, enabling them to scale their security testing capacity up or down smoothly.
Kubernetes Deployment: For organizations using Kubernetes, this deployment supports automatic scaling. Scanning machines are dynamically created when demand increases and shut down when idle, optimizing resource use and controlling costs.
Auto-Scaling Benefits
Auto-scaling is particularly useful for handling variable workloads, such as scanning many applications within tight timeframes. It ensures resources are only used when necessary, reducing unnecessary expenses during low-demand periods.
Adjusting Scan Concurrency
Organizations can increase or decrease the number of concurrent scans their license permits. The system automatically adjusts to these changes, ensuring smooth performance without bottlenecks or downtime.
Integration with Development Workflows
Burp Suite Enterprise integrates with continuous integration and continuous deployment (CI/CD) pipelines and offers a GraphQL API. This allows automated and scalable management of scans that can grow alongside development processes.
Burp Suite Enterprise Edition's terms and conditions for contract renewal and cancellation are outlined in its Terms & Conditions of Supply. Key points include:
Contract Renewal:
Auto-Renewal Process: If your license is set to auto-renew and a valid recurring payment method is provided, payment for the upcoming license period will be processed 14 days before the current period ends. Auto-renewal can be disabled for specific licenses through your account page.
Contract Cancellation:
Order Cancellation: To cancel an order, you must email PortSwigger within 7 days of making the payment or within 7 days of an auto-renewal payment being processed. This must be done before accessing the hosted software or downloading the self-hosted software or license key. If the software has already been accessed or downloaded, a refund is not possible.
Termination by Licensor: PortSwigger reserves the right to terminate the license at any time with 30 days' written notice. In such cases, a pro-rata refund of the upfront license fee will be provided, reflecting the remaining term of the license.
Additional Considerations:
Amendments to Fees: PortSwigger may amend usage-based fees or the Unlimited Usage Model, with changes taking effect either at the start of the next license period or during the current period after at least 30 days' notice. If changes occur during the current period, you have the right to terminate the license within the notice period and receive a pro-rata refund for the unused term.
Burp Suite Enterprise Edition supports organizations in achieving compliance with various security standards by offering specialized compliance reporting and automated scanning capabilities. Notably, it provides compliance reports aligned with:
OWASP Top 10 2021: This report highlights any issues found by the scan that correspond to issue categories in the OWASP Top 10 2021.
PCI DSS v4.0.1: This report highlights any issues found by the scan that break the requirements set out in the PCI DSS v4.0.1 standard.
Burp Suite Enterprise Edition's automated scanning and reporting features assist organizations in working towards compliance with other standards, such as:
HIPAA: By identifying vulnerabilities that could lead to unauthorized access to protected health information, supporting HIPAA compliance efforts.
NIST 800-53: Through comprehensive security assessments, it aids in meeting the security and privacy controls outlined in NIST 800-53.
Burp Suite Enterprise
By PortSwigger Ltd