选择默认的网站语言
en English
Zabbix
  • 产品技术
    观看Zabbix demo 视频
    观看Zabbix demo 视频
    Zabbix Cloud Free trial

    Deploy a Zabbix instance with only a few clicks

    特征

    了解Zabbix如何收集、处理和可视化数据

    集成方案

    请查看监控模板和集成列表

    产品手册

    关于如何安装、配置和运行Zabbix的官方指导手册

    Zabbix能监控什么?

    • 网络监控
    • Server监控
    • 云监控
    • 容器监控
    • VMware监控
    • Windows监控
    • IoT物联网
    • 日志监控
    • 应用
    • Services
    • 数据库
    关于产品

    • Zabbix 7.2新特征
    • 产品发布日志
    • 产品截图
    • 系统要求
    • 生命周期和发布政策
    • 安全原则
    • Zabbix安全及漏洞修复查询
    • 产品路线图
    • 客户评价
    • Licence许可证说明
    • 下载Zabbix
    • 体验一下
  • 解决方案
    案例分析

    从其他公司使用Zabbix的真实案例中获得启发

    企业解决方案

    Zabbix是企业级监控解决方案,针对高性能和安全性进行了优化

    根据行业

    • 银行金融
    • 化工能源
    • 医疗健康
    • IT电信
    • 零售业
    • 航空航天
    • 教育机构
    • 政府机构
    • 市场营销
    • 下载Zabbix
    • 体验一下
  • 服务与支持
    Get Zabbix Cloud today
    Get Zabbix Cloud today
    订阅支持

    获得Zabbix技术团队提供的实时技术支持和故障排除

    Technical Support for MSPs

    Technical support for managed service providers

    所有专业服务

    可选择Zabbix提供的多样专业服务—从咨询到交钥匙解决方案

    • 技术咨询
    • Turkey标准实施
    • 模板定制
    • 版本升级
    • 二次开发
    • 集成服务
    • 迁移服务
    客户登录
    • 下载Zabbix
    • 体验一下
  • 认证培训
    培训一览

    在认证培训师指导下迅速系统掌握Zabbix

    • 培训日程
    • 培训讲师
    • 学员反馈
    • 常见问题
    • 认证证书查验
    • 培训申请表
    培训课程

    多个培训等级,逐个击破,逐步掌握

    • Zabbix用户级认证(ZCU)
    • Zabbix中级认证(ZCS)
    • Zabbix高级认证(ZCP)
    • Zabbix专家级认证(ZCE)
    • 升级课程 New
    专题培训(线上)

    1天的课程内容,深入学习特定监控主题

    • Zabbix数据预处理高级课程
    • Zabbix API高级课程
    • Zabbix安全管理高级课程
    • Zabbix问题与异常检测高级课程
    认证考试

    通过考试即可获得对应级别认证证书!

    • Zabbix用户级认证(ZCU)
    • Zabbix中级认证(ZCS)
    • Zabbix高级认证(ZCP)
    • 考试报名
    • 下载Zabbix
    • 体验一下
  • 合作伙伴
    Get Zabbix Cloud today
    Get Zabbix Cloud today
    合作伙伴项目

    合作伙伴网络:可为全球客户提供本地化技术支持和培训

    成为我们的合作伙伴

    加入合作伙伴网络,借助Zabbix获得全球认可的地位和支持

    Zabbix合作伙伴地图

    客户选择距离您最近的Zabbix合作伙伴

    大中华区总代理

    强强合作,加强Zabbix在新市场的地位

    • 下载Zabbix
    • 体验一下
  • Zabbix社区
    Get Zabbix Cloud today
    Get Zabbix Cloud today
    社区

    加入社区,提高你的Zabbix知识水平

    社区活动

    参加各种语言和地区的Zabbix线上/线下活动

    订阅新闻邮件

    订阅Zabbix时事通讯邮件,了解最新消息

    论坛

    与成千上万的活跃用户互帮互助

    博客

    了解技术操作指南、案例研究和新功能概述

    开发者

    欢迎贡献或与Zabbix合作

    在线公开课

    关于Zabbix不同方面的多种语言的公开课

    Bugs和功能请求

    报告错误并发送功能请求

    Contribute to Zabbix

    Help us make an outstanding monitoring solution even better

    • 下载Zabbix
    • 体验一下
  • 关于我们
    Get Zabbix Cloud today
    Get Zabbix Cloud today
    公司介绍

    Zabbix公司和管理团队简介

    公司新闻

    新的合作伙伴关系、版本和里程碑等

    我们的用户

    哪些客户在用Zabbix

    隐私政策

    用户需要了解的相关法律

    商标政策

    下载Zabbix logo及使用规范

    战略合作关系

    与哪些领先的IT公司密切合作

    联系我们

    可在全球范围与我们取得联系

    招贤纳士

    可在Zabbix全球任一分公司开启职业生涯

    • 下载Zabbix
    • 体验一下
下载Zabbix
  • Join the Zabbix Meeting in Malmo – January 30
  • Zabbix 7.2已发布! 查看及下载
  • 博客
  • 产品手册
中文
  • English (US)
  • 日本語
  • Русский
  • Español (LA)
  • Português (BR)
  • Deutsch
  • Français
  • Czech
  • 客户登录
BANNER_ZABBIX_SECURITY_POLICY_SUPERTITLE

Zabbix Security Policy

Total security demands constant awareness

Our security policy is a structured, systematic, and holistic approach to data security that guards the confidentiality, integrity, and availability of information. It also ensures that our employees and affiliates are aware of their responsibilities, understand security policy procedures, and know how to safeguard information.

  • Process
  • Certifications
  • Cloud security
  • Disclosure policy
  • Reporting issue
  • Dealing with issues
  • Zabbix x HackerOne
  • 主页
  • 产品

The Zabbix security process

Zabbix follows a strict process when developing new versions of our software, according to the  Zabbix life cycle and release policy. All tasks are subject to strict standards imposed by Zabbix: 

  • All Zabbix developers adhere to project  coding guidelines
  • All code is reviewed by a senior developer before being merged into the Zabbix code base
  • All tasks are tested by Quality Assurance engineers
  • Root Cause Analysis is performed for found vulnerabilities and results are added to secure code trainings performed for developers to avoid similar vulnerabilities in the future.
  • Zabbix Cloud development and testing environments maintain a separate access control, completely isolated from the production environment.
  • No testing is ever done in Zabbix Cloud customer production environments, and account data/contact information as well as customer content (in Zabbix nodes) is never copied and used for testing/troubleshooting.
  • A Zabbix node in the cloud is almost the same as a standalone version, and we provide you the latest version with fixed security vulnerabilities and findings from HackerOne and other sources.
  • Zabbix Cloud is continuously scanned and assessed by internal tools and teams, and security issues are passed down to the infrastructure or development team to increase our security posture.
  • Although the development process is designed to reduce security issues, it is still possible that new vulnerabilities might be discovered. Zabbix treats security issues in maintained versions as a high priority. Please note that Zabbix does not fix security issues in versions that are no longer supported. If this is required, it is custom development charged by an hourly rate.

Certifications

To assure our customers that Zabbix is a well-managed and professional organization, that appropriate information security measures are applied as necessary, and that customers can trust the source code, our professional services, and our Zabbix Cloud service, Zabbix has: 

  • Implemented a security program consistent with and conforming to the ISO/IEC 27001:2022 standard for Information Security Management
  • Implemented the ISO/IEC 27017:2015 extension for cloud security controls
  • Used other cybersecurity best practices to compliment the standard
Certifications

View certificate in full size

Zabbix Cloud security

Every customer's Zabbix instance is isolated from one another. 

Every customer's Zabbix instance data is on EBS volumes and encrypted at-rest with AES-256.

Every customer node uses Amazon Time Sync Service NTP pools (time.aws.com) as a time source.

AWS Snapshot technology and EBS encryption with AES-256 at-rest data encryption is used for customer backups.

All in-transit communications both internally and externally use at least TLS 1.2 and (where possible) TLS 1.3 certificates.

Users can sign up with a valid email address and set their password in the Zabbix cloud platform. OTP codes are used for security purposes.

Customer passwords for local accounts are protected with a BCRYPT hashing algorithm, so Zabbix employees do not have access to your password and cannot retrieve it for you. The only option if you lose your password is to reset it.

In cases where Zabbix employees need to connect to a customer's backend or frontend components, review log files, solve any issue with Services, at a customer’s explicit request for technical support reasons, or as required by law, we use combination of enterprise grade key management services and secret management technologies. There are no standing privileges for engineers or support team. We practice Just-in-Time access for as brief a period as possible.  

Every employee working within Zabbix and accessing Zabbix Cloud in any way is using company owned and managed devices with XDR and at-rest encryption.

Multiple sets of best practices are used – systems are hardened using CIS, AWS VPC best practices, AWS IAM best practices, etc.

We have several internal solutions in place that are used for monitoring our systems, availability, performance, and other critical parameters.

System availability can be checked at https://cloud-status.zabbix.com/

Disclosure policy

In Zabbix we use the term "responsible disclosure", which means we have a policy on how we disclose all security issues that come to our attention, but only after the issues have been resolved and all customers with support contracts are given time to upgrade or patch their installations.
We kindly ask that when you are reporting a security issue, you follow the same guidelines and share the details only with the Zabbix Security team.

Security issue reporting

Before reporting the issue:
Make sure that the issue you are submitting is not related to server configuration, 3rd party scripts and utilities. In order to avoid any possible issues with server configuration we advise Zabbix users to read Best practices for secure Zabbix setup.

To report a security issue, create a new issue in the Zabbix Security Reports (ZBXSEC) section of the public bug tracker describing the problem (and a proposed solution if possible) in detail. This way, we can ensure that only the Zabbix security team and the reporter have access to the case.

The following information will be helpful for the Zabbix Security team:

  • Date and time when you identified the security defect.
  • Affected Zabbix version range.
  • Type of security issue you are reporting, e.g.: XSS, CSRF, SQLi, RCE.
  • Affected components, e.g.: Frontend, Server, Agent, API.
  • Any details you can provide, e.g. screenshots, screen recordings, http(s) transaction logs, POC exploits (please do not share any evidence via unauthenticated file sharing services and avoid sharing sensitive information, as if the Zabbix Security team decides that this issue does not fit the security defect description it might be moved to the ZBX project and the issue will be visible to all users).
  • Step-by-step instructions on how to reproduce the issue, as the problem might not be easily identifiable.
Security issue reporting

Dealing with security issues

  1. The Zabbix Security team reviews the issue and evaluates its potential impact.
  2. If the security issue is found not to be related to security, then the issue will be moved to an internal development project.
  3. The Zabbix security team works on the issue to provide a solution and keeps all details on the problem until the next version of impacted Zabbix product is out. If Zabbix source code and Zabbix Cloud node is impacted by the same vulnerability, details will be kept internal until both products are updated.
  1. New packages are created and made available for download on  https://zabbix.com/download section and Zabbix Cloud node version is updated as well.
  2. Zabbix requests CVE identifiers for the security issue for Zabbix source code.
  3. Clients with valid support agreements are emailed giving a period of time when it is possible to upgrade before the issue becomes known to the public.
  4. Fixed vulnerabilities or any other security advisories are published to our Security advisory page https://www.zabbix.com/security_advisories

The Zabbix bug bounty program

Developed in partnership with HackerOne, the world's leading platform for ethical hackers, the Zabbix bug bounty program contributes to the security of the product by allowing hackers to discover potential security vulnerabilities in different Zabbix components. The program offers up to $3,000 as a reward for discovering and reporting a bug. More information can be found in the Zabbix bug bounty page.

The Zabbix bug bounty program
  • 中国
  • 日本
  • 欧洲
  • 美国
  • 阿根廷
  • 巴西
  • 智利
  • 哥伦比亚
  • 墨西哥
中国
+86 021-6978-6188
日本
+81 3-4405-7338
欧洲
+371 6778-4742
美国
+1 877-4-ZABBIX
阿根廷
+54 11 3989-4060
巴西
+55 11 4210-5104
智利
+56 44 890 9410
哥伦比亚
+57 1 3819310
墨西哥
+52 55 8526 2606
联系Zabbix合作伙伴
联系我们
产品技术
  • 产品概览
  • Zabbix 7.2新特征
  • 集成方案
  • 系统要求
  • 生命周期和发布政策
  • License
  • 产品手册
  • 产品路线图
解决方案
  • 根据监控对象
  • 根据行业
  • 企业解决方案
  • 案例分析
  • 我们的用户
服务
  • 年度订阅服务
  • 技术咨询
  • Turkey标准实施
  • 模板定制
  • 版本升级
  • 二次开发
  • 集成服务
  • 迁移服务
认证培训
  • Zabbix用户级认证(ZCU)
  • Zabbix中级认证(ZCS)
  • Zabbix高级认证(ZCP)
  • Zabbix专家级认证(ZCE)
  • 学员反馈
  • 常见问题
  • 合作伙伴申请表
  • 在线公开课
合作伙伴
  • 合作伙伴项目
  • 成为我们的合作伙伴
  • 战略合作伙伴
  • 大中华区总代理
  • 合作伙伴地图
Zabbix社区
  • 社区活动
  • 论坛
  • 微信公众号
  • Bugs和功能请求
  • 开发者
  • Community templates
  • 邮件订阅
公司介绍
  • 关于我们
  • 招贤纳士
  • 联系我们
  • 公司新闻
  • 商标政策
加入我们 We are hiring!
  • 安全原则
  • 隐私政策
  • 商标政策

© 2001-2025 by Zabbix LLC. All rights reserved.