Hi, As per our procedures, this is the report from the security team.
* Vulnerability procedures * There is a draft of the vulnerability procedures created (thanks Don, Amy). https://wiki.onap.org/display/DW/Draft+ONAP+Vulnerability+Management * The team will review this over the next week and plan to submit it to the TSC at the developers event for TSC approval. * There was an organizational question that we discussed, which is how to formally handle the vulnerability management team. Note: the vulnerability management team is *separate* from the security team, even if there may be overlap in membership. The reason is to keep it the personal involved in the vulnerability management small. We would like to propose that the vulnerability management team is its own subcommittee. If this viewed favorably by the TSC, then we will go ahead an submit a request for a vulnerability sub-committee. Request for Input from the TSC: Is it agreeable to go ahead and request a vulnerability management subcommittee (Note, this is not the approval, but a request for guidance on the way foreward). Proactive aspects: * Early discussions only so far, gathering input (and thanks Catherin for your input via confluence as well). Other: * Last meeting we had discussion about the security team: * Sub-committee only? * Sub-committee and security coordinator? * The drafts are repeated at the end of this for information. * Request for guidance from TSC. Coordinator and sub-committee, or sub-committee only. * Recommendation from me: Both. Motivation: if we have both a vulnerability management sub-committee and a security sub-committee, the task of the security coordinator is keep abreast of both, and other security initiatives if they are spun up. Best Regards, Steve. ***Security: Sub-committee, coordinator.*** We have discussed the idea of a security subcommittee. The motivation is that it provides transparency about who is involved, and is a mechanism for ensuring that there is dedicated security support. Note: The security subcommittee is not the vulnerability response team. Here is a the draft proposal for the subcommittee: * TSC subcommittee name: Security Subcommittee (SEC) * TSC subcommittee purpose: * The security subcommittee is responsible for defining and proposing activities, process and guidelines that aim to increase the security of ONAP. This includes, but is not limited to: * Creating and maintaining vulnerability procedures. * Defining ,promoting and proposing proactive security activities (to be executed by and with the agreement of active projects). * Providing best practices, security guidelines. The security subcommittee is advisory by nature, and not authoritative. It may make proposals and provide advice to projects and to the TSC. The security subcommittee operates on a rough consensus basis. If the subcommittee is unable to reach consensus on what advice to offer, the subcommittee will refer the matter to the TSC. TSC security subcommittee expected deliverables: Security procedures, guidelines, proposed activities and best practices aimed at supporting a secure ONAP platform. TSC security subcommittee participants: Contained on the security committee web-page. The participants self nominate to the sub-committee chair, who confirms the participants with the TSC. TSC security sub-committee chair is the same as the security coordinator. Meeting Frequency: Weekly. ***************************** Draft security coordinator definition. * Coordination Area: TSC Security * Coordination area responsibility description: * Ensure required security approaches, practices and procedures are in place for the ONAP platform. * Ensure that there is a functioning ONAP security community. * May do so with the support of a Security sub-committee. * Reporting cadence: Weekly * Area Coordinator: [Ericsson]<http://www.ericsson.com/> STEPHEN TERRILL Technology Specialist DUIC, Systems and Technology Development Unit IP & Cloud Business Unit, IT & Cloud Products Ericsson Ericsson R&D Center, via de los Poblados 13 28033, Madrid, Spain Phone +34 339 3005 Mobile +34 609 168 515 [email protected] www.ericsson.com [http://www.ericsson.com/current_campaign]<http://www.ericsson.com/current_campaign> Legal entity: Ericsson EspaƱa S.A, compay registration number ESA288568603. This Communication is Confidential. We only send and receive email on the basis of the terms set out at www.ericsson.com/email_disclaimer<http://www.ericsson.com/email_disclaimer>
_______________________________________________ ONAP-TSC mailing list [email protected] https://lists.onap.org/mailman/listinfo/onap-tsc
