Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Subject: [Akraino The Security Sub-Committee] Akraino Security subgroup weekly meeting
When: Occurs weekly starting 6/1/2020 from 11:00 AM to 12:00 PM Pacific Time.
Where:

Join Zoom Meeting

https://zoom.us/j/94195918783

Meeting ID: 941 9591 8783

One tap mobile

+16699006833,,94195918783# US (San Jose) 12532158782,,94195918783# US

+(Tacoma)

Dial by your location

+1 669 900 6833 US (San Jose)

+1 253 215 8782 US (Tacoma)

+1 346 248 7799 US (Houston)

+1 646 558 8656 US (New York)

+1 301 715 8592 US (Germantown)

+1 312 626 6799 US (Chicago)

877 369 0926 US Toll-free

855 880 1246 US Toll-free

Meeting ID: 941 9591 8783

Find your local number: https://zoom.us/u/aee0gyHkh8

   Due to an urgent conflict today's meeting, 7/13/2020, has been cancelled.  The following email was sent out with a request for input regarding Maturity level security review requirements.

The main agenda item for today was to discuss incubation and maturity security requirements for blueprints.  Please review the updates that I have made to the following link concerning Incubation and Maturity:  PASS/FAIL Criteria for Vuls, Lynis and Kube-Hunter:

https://wikicommittee meeting schedule can be found on the Akraino calendar https://lists.akraino.org/displayg/AK/Steps+To+Implement+Security+Scan+Requirements

Currently the difference between Incubation and Maturity Security Requirements is that exceptions are more readily granted for incubation.  Exceptions for maturity should be granted only for cases where the issue does not apply to the blueprint (ie specific code/configuration is not being used) or a separate security measure is being taken to mitigate the issue.  Any exception granted for the Maturity phase should be very clearly documented.

For Maturity we must require a higher security level than Incubation, yet these requirements need to be testable by BluVal and easily quantified.  If there are additional security measures that you feel should be added to the Maturity requirements for Akraino please respond to the security team, security@lists.akraino.org, with those recommendations for discussion.  Please do this as soon as possible because we need to provide all of our Maturity requirements to the TSC in the next two weeks for their review/approvalsecurity/calendar.

The schedule of the meeting is driven by the agenda.  Please send your discussion topics to the security@lists.akraino.org mailing list
a few days before the meeting.


 

Agenda:

ICN BP Security review (Bluval results): Kuralamudhan Ramakrishnan (Deactivated) & Igor D.C.: - 20 - 30 mins

...

  • Security tool integration status check
    • PTLs might be under the release pressure, need to talk to PTLs individually. (Ken will follow up)
    • Clarification: Just one sample repo location for each language, no need to list all repos
    • David will fill in the Network Cloud Blueprint Family  as an example
  • CII badging
    • Not all of them relating to security
    • Suggest to TSC to have CII as part of maturing process
    • Each blueprint project is not created for the same audience, can we mandate the same set of requirements?
    • Should process subcomittee to adopt CII badging to have a standard measurement. 

...

  • July 17, 2019 Meeting cancelled
  • May 22, 2019 minutes / recording / slides
  • May 8, 2019 Meeting cancelled
  • April 24, 2019 minutes / recording / slides
  • April 10, 2019 minutes / recording /slides
  • March 27, 2019 minutes / recording /slides
  • March 13, 2019 minutes / recording /slides (Meeting cancelled due to Zoom technical issues)
  • February 27, 2019 minutes / recording /slides
  • February 13, 2019 minutes / recording/ slides
  • January 30, 2019 minutes / recording / slides
  • January 16, 2019 minutes / recording / slides