Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Subject: [Akraino The Security Sub-Committee] Akraino Security subgroup weekly meeting
When: Occurs weekly starting 6/1/2020 from 11:00 AM to 12:00 PM Pacific Time.
Where:

Akraino Edge Stack 1 is inviting you to a scheduled Zoom meeting.

Topic: Akraino Security Sub-Group Bi-Weekly Meeting
Time: Sep 28, 2020 11:00 AM Pacific Time (US and Canada)
Every week on Mon, until Sep 6, 2021, 50 occurrence(s)
Please download and import the following iCalendar (.ics) files to your calendar system.
Weekly: committee meeting schedule can be found on the Akraino calendar https://zoom.us/meeting/tJAsfuyhrzMtEteKpUJsom1BhGl3T69xo-wk/ics?icsToken=98tyKuCsrzIvE9WdtxGERowIBYr4Z_PzmFxaj7dYtw_QKTNcb1LUPsVOYYYpScDf

Join Zoom Meeting
https://zoom.us/j/94195918783?pwd=YXdKako3bTlUTGVxQlByZTNDWS9lQT09

Meeting ID: 941 9591 8783
Passcode: 600898
One tap mobile
+16699006833,,94195918783# US (San Jose)
+12532158782,,94195918783# US (Tacoma)

Dial by your location
+1 669 900 6833 US (San Jose)
+1 253 215 8782 US (Tacoma)
+1 346 248 7799 US (Houston)
+1 646 558 8656 US (New York)
+1 301 715 8592 US (Germantown)
+1 312 626 6799 US (Chicago)
877 369 0926 US Toll-free
855 880 1246 US Toll-free
Meeting ID: 941 9591 8783
Find your local number: https://zoom.us/u/aee0gyHkh8

   Due to an urgent conflict today's meeting, 7/13/2020, has been cancelled.  The following email was sent out with a request for input regarding Maturity level security review requirements.

The main agenda item for today was to discuss incubation and maturity security requirements for blueprints.  Please review the updates that I have made to the following link concerning Incubation and Maturity:  PASS/FAIL Criteria for Vuls, Lynis and Kube-Hunter:

https://wiki.akraino.org/display/AK/Steps+To+Implement+Security+Scan+Requirements

Currently the difference between Incubation and Maturity Security Requirements is that exceptions are more readily granted for incubation.  Exceptions for maturity should be granted only for cases where the issue does not apply to the blueprint (ie specific code/configuration is not being used) or a separate security measure is being taken to mitigate the issue.  Any exception granted for the Maturity phase should be very clearly documented.

For Maturity we must require a higher security level than Incubation, yet these requirements need to be testable by BluVal and easily quantified.  If there are additional security measures that you feel should be added to the Maturity requirements for Akraino please respond to the security team, security@lists.akraino.org, with those recommendations for discussion.  Please do this as soon as possible because we need to provide all of our Maturity requirements to the TSC in the next two weeks for their review/approvallists.akraino.org/g/security/calendar.

The schedule of the meeting is driven by the agenda.  Please send your discussion topics to the security@lists.akraino.org mailing list
a few days before the meeting.


 

Agenda:

ICN BP Security review (Bluval results): Kuralamudhan Ramakrishnan (Deactivated) & Igor D.C.: - 20 - 30 mins

...

  • Security tool integration status check
    • PTLs might be under the release pressure, need to talk to PTLs individually. (Ken will follow up)
    • Clarification: Just one sample repo location for each language, no need to list all repos
    • David will fill in the Network Cloud Blueprint Family  as an example
  • CII badging
    • Not all of them relating to security
    • Suggest to TSC to have CII as part of maturing process
    • Each blueprint project is not created for the same audience, can we mandate the same set of requirements?
    • Should process subcomittee to adopt CII badging to have a standard measurement. 

...

  • July 17, 2019 Meeting cancelled
  • May 22, 2019 minutes / recording / slides
  • May 8, 2019 Meeting cancelled
  • April 24, 2019 minutes / recording / slides
  • April 10, 2019 minutes / recording /slides
  • March 27, 2019 minutes / recording /slides
  • March 13, 2019 minutes / recording /slides (Meeting cancelled due to Zoom technical issues)
  • February 27, 2019 minutes / recording /slides
  • February 13, 2019 minutes / recording/ slides
  • January 30, 2019 minutes / recording / slides
  • January 16, 2019 minutes / recording / slides