Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Sec Assess WG] Naming and Scope of assessments #444

Closed
2 tasks
lumjjb opened this issue Oct 30, 2020 · 4 comments
Closed
2 tasks

[Sec Assess WG] Naming and Scope of assessments #444

lumjjb opened this issue Oct 30, 2020 · 4 comments
Labels
assessment-process proposed improvements to security assessment process help wanted Extra attention is needed inactive No activity on issue/PR suggestion New suggestion for the CNCF sig-security group that don't fall into an existing category

Comments

@lumjjb
Copy link
Contributor

lumjjb commented Oct 30, 2020

This issue was created from results of the Security Assessment Improvement Working Group (#167 (comment)).

Naming and Scope of assessments

Premise

  • Assessment is an overloaded term, and can lead to confusion

Ideas

  • Have a better articulation of what is a sec assess.
  • Include scope to include additional aspect of code audit related checks/certification
  • Add mapping aspects of assessments to compliance frameworks
  • Additional suggestion of scope to include related to security testing

Logistics

  • Contributors (For multiple contributors, 1 lead to coordinate)
  • Placeholder_1
  • Placeholder_2
  • SIG-Representative
@lumjjb lumjjb added help wanted Extra attention is needed assessment-process proposed improvements to security assessment process suggestion New suggestion for the CNCF sig-security group that don't fall into an existing category labels Oct 30, 2020
@stale
Copy link

stale bot commented Dec 29, 2020

This issue has been automatically marked as inactive because it has not had recent activity.

@TheFoxAtWork
Copy link
Contributor

@lumjjb is this considered complete?

@stale stale bot removed the inactive No activity on issue/PR label Mar 15, 2021
@stale
Copy link

stale bot commented May 15, 2021

This issue has been automatically marked as inactive because it has not had recent activity.

@stale stale bot added the inactive No activity on issue/PR label May 15, 2021
@anvega
Copy link
Contributor

anvega commented Jun 20, 2023

With the publication of the assessments book, we've ratified the use of assessment.

@anvega anvega closed this as completed Jun 20, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
assessment-process proposed improvements to security assessment process help wanted Extra attention is needed inactive No activity on issue/PR suggestion New suggestion for the CNCF sig-security group that don't fall into an existing category
Projects
None yet
Development

No branches or pull requests

3 participants