GSA-TTS / tts-tech-operations

Home of the TTS Technology Portfolio team
https://handbook.tts.gsa.gov/tech-operations/
Other
4 stars 0 forks source link

consensus around what security/compliance documentation is sensitive #1106

Open afeld opened 3 years ago

afeld commented 3 years ago

Background Information

We have questions come up regularly about whether or not it's ok for various security/compliance documentation to be public. Most recent conversation.

Implementation Steps

Acceptance Criteria

its-a-lisa-at-work commented 3 years ago

"TTS should be more judicious related to the information that it puts out publicly. The information related to systems can be used against TTS from an adversary to have an impact on the security of the systems. Before publishing security data, I recommend that TTS does the following:

JJediny commented 1 month ago

https://docs.google.com/document/d/1P-_ow-6CFu_uEJ62wLHTUhix-d5zWVls-hdTPD16bho/edit#heading=h.mety7wpfbz9l