Re: [asterisk-users] Security Architecture or Security Evaluations Docs?

2014-07-28 Thread Jeffrey Walton
Thanks Patrick, Assuming security+evaluation refers to Common Criteria, Common Criteria is one, but not necessarily the only type of security evaluation. Often times organizations with resources will perform an evaluation against its own standards before adopting or accepting a system. I was

Re: [asterisk-users] Security Architecture or Security Evaluations Docs?

2014-07-28 Thread Patrick Laimbock
On 28-07-14 12:28, Jeffrey Walton wrote: [snip] Is there anything that includes the development process? I'm interested in the secure development items and testing. Info about the development of Asterisk can be found here: http://asterisk.org/community/developers

[asterisk-users] Security Architecture or Security Evaluations Docs?

2014-07-26 Thread Jeffrey Walton
Does anyone know of Security Architecture or Security Evaluations documents that I could read? Searching is turning up no hits. For example, http://www.google.com/#q=security+evaluation+site:asterisk.org and http://www.google.com/#q=security+architecture+site:asterisk.org. --

Re: [asterisk-users] Security Architecture or Security Evaluations Docs?

2014-07-26 Thread Patrick Laimbock
On 26-07-14 14:23, Jeffrey Walton wrote: Does anyone know of Security Architecture or Security Evaluations documents that I could read? Searching is turning up no hits. For example, http://www.google.com/#q=security+evaluation+site:asterisk.org and