Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

How does Cloud Service Certification maintain the security of the environment and the protection of the environment for open source consumers #18

Closed
mcleo-d opened this issue Jan 30, 2020 · 4 comments · Fixed by #52
Assignees
Labels
question Further information is requested

Comments

@mcleo-d
Copy link
Member

mcleo-d commented Jan 30, 2020

As raised on the Cloud Service Certification call on 30th January 2020 Ken D'Aura from The Hartford - Insurance Firm

Roadmap item : How does Cloud Service Certification maintain the security of the environment and the protection of the environment for open source consumers?

@mcleo-d mcleo-d added the question Further information is requested label Jan 30, 2020
@mcleo-d mcleo-d added this to To do in Compliant Financial Infrastructure via automation Jan 30, 2020
@mcleo-d mcleo-d moved this from To do to Prioritised in Compliant Financial Infrastructure Jan 30, 2020
@git-hub-forwork1
Copy link
Contributor

Since I was not in attendance for the meeting this question was posed I will have to assume the purpose. I assume the question is a supply chain question since this project would be the OSS portion of the equation. This project will have a peer review process to ensure the content created is functional (works as intended) and at least 2 members feel the content meets the control objective it was created for.
This is OSS and it should not be trusted completely. This is the purpose of the design of the artifacts as well. The intention to turn control implementations into code and provide the bdd test cases and the user stories is so consumers can rebuild this content themselves using the stories. The can verify the actions of the code actually do the tasks intended.
If I took this question the wrong way please do update me so I can respond more accurately.

@mcleo-d
Copy link
Member Author

mcleo-d commented May 7, 2020

@peterrhysthomas - As a result of your contribution during the CSC call on 7th May, can you note the next steps for this item?

@peterrhysthomas
Copy link
Contributor

I think we should add this to the documentation, this is a nice summary of the contribution process and also the guarantee/warrantee provisions of the software (effectively we are saying this is distributed without any guarantee and any users should perform their own due diligence).

@mcleo-d
Copy link
Member Author

mcleo-d commented Jul 24, 2020

#52 raised to add the question and answer to the CSC wiki.

mcleo-d pushed a commit to mcleo-d/cloud-service-certification that referenced this issue Aug 6, 2020
Compliant Financial Infrastructure automation moved this from In progress to Done Aug 6, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
question Further information is requested
Projects
Archived in project
Development

Successfully merging a pull request may close this issue.

3 participants