Hi,

As per our procedures, this is the report from the security team.

* Vulnerability procedures *
There is a draft of the vulnerability procedures created (thanks Don, Amy).  
https://wiki.onap.org/display/DW/Draft+ONAP+Vulnerability+Management

  *   The team will review this over the next week and plan to submit it to the 
TSC at the developers event for TSC approval.
  *   There was an organizational question that we discussed, which is how to 
formally handle the vulnerability management team.  Note: the vulnerability 
management team is *separate* from the security team, even if there may be 
overlap in membership.  The reason is to keep it the personal involved in the 
vulnerability management small.
We would like to propose that the vulnerability management team is its own 
subcommittee.  If this viewed favorably by the TSC, then we will go ahead an 
submit a request for a vulnerability sub-committee.
Request for Input from the TSC: Is it agreeable to go ahead and request a 
vulnerability management subcommittee (Note, this is not the approval, but a 
request for guidance on the way foreward).

Proactive aspects:

  *   Early discussions only so far, gathering input (and thanks Catherin for 
your input via confluence as well).

Other:

  *   Last meeting we had discussion about the security team:
     *   Sub-committee only?
     *   Sub-committee and security coordinator?
  *   The drafts are repeated at the end of this for information.
  *   Request for guidance from TSC.  Coordinator and sub-committee, or 
sub-committee only.
     *   Recommendation from me: Both.  Motivation: if we have both a 
vulnerability management sub-committee and a security sub-committee, the task 
of the security coordinator is keep abreast of both, and other security 
initiatives if they are spun up.

Best Regards,

Steve.

***Security: Sub-committee, coordinator.***
We have discussed the idea of a security subcommittee.  The motivation is that 
it provides transparency about who is involved, and is a mechanism for ensuring 
that there is dedicated security support.
Note: The security subcommittee is not the vulnerability response team.

Here is a the draft proposal for the subcommittee:

  *   TSC subcommittee name: Security Subcommittee (SEC)
  *   TSC subcommittee purpose:
  *   The security subcommittee is responsible for defining and proposing 
activities, process and guidelines that aim to increase the security of ONAP.  
This includes, but is not limited to:
     *   Creating and maintaining vulnerability procedures.
     *   Defining ,promoting and proposing proactive security activities (to be 
executed by  and with the agreement of active projects).
     *   Providing best practices, security guidelines.

The security subcommittee is advisory by nature, and not authoritative. It may 
make proposals and provide advice to projects and to the TSC.

The security subcommittee operates on a rough consensus basis.  If the 
subcommittee is unable to reach consensus on what advice to offer, the 
subcommittee will refer the matter to the TSC.

TSC security subcommittee expected deliverables:

Security procedures, guidelines, proposed activities and best practices aimed 
at supporting a secure ONAP platform.
TSC security subcommittee participants:  Contained on the security committee 
web-page.
The participants self nominate to the sub-committee chair, who confirms the 
participants with the TSC.
TSC security sub-committee chair is the same as the security coordinator.
Meeting Frequency: Weekly.



*****************************
Draft security coordinator definition.

  *   Coordination Area: TSC Security
  *   Coordination area responsibility description:
     *   Ensure required security approaches, practices and procedures are in 
place for the ONAP platform.
     *   Ensure that there is a functioning ONAP security community.
     *   May do so with the support of a Security sub-committee.
  *   Reporting cadence: Weekly
  *   Area Coordinator:



[Ericsson]<http://www.ericsson.com/>

STEPHEN TERRILL
Technology Specialist
DUIC, Systems and Technology
Development Unit IP & Cloud
Business Unit, IT & Cloud Products

Ericsson
Ericsson R&D Center, via de los Poblados 13
28033, Madrid, Spain
Phone +34 339 3005
Mobile +34 609 168 515
[email protected]
www.ericsson.com


[http://www.ericsson.com/current_campaign]<http://www.ericsson.com/current_campaign>

Legal entity: Ericsson EspaƱa S.A, compay registration number ESA288568603. 
This Communication is Confidential. We only send and receive email on the basis 
of the terms set out at 
www.ericsson.com/email_disclaimer<http://www.ericsson.com/email_disclaimer>

_______________________________________________
ONAP-TSC mailing list
[email protected]
https://lists.onap.org/mailman/listinfo/onap-tsc

Reply via email to