18F / open-source-policy

This repository contains the official Open Source Policy of 18F
https://18f.gsa.gov
Other
298 stars 94 forks source link

GitHub ATO and Open Source Development in a Federal Development Environment #100

Open jlaura opened 2 years ago

jlaura commented 2 years ago

Not sure if this is the best place to ask, and please feel free to reply directly (jlaura@usgs.gov) if preferred.

I am working on team getting an ATO in place for using GitHub and am wondering how you all have structured your security guidelines to support open development on GitHub. For example, what, if any controls are in place to handle the need to maintain security and administrative reviews on repositories that are public or going to be made public? Do you maintain a prescriptive development workflow to enforce any policy requirements? Do you use some combination of policy and technical solution to ensure that repositories remain free from PII?

Thanks for any information you might be able to provide!

brittag commented 1 year ago

@jlaura Hello from a year in the future! I figure this info is probably no longer helpful to you, but maybe it'll be helpful to somebody else stumbling on this issue.

I no longer work for 18F/TTS, but I previously worked on a project there. Robust, specific, well-maintained documentation was a big part of our argument for why our Authorizing Officials should allow us to do public open source development. Here are some components: