OpenChain-Project / Security-Assurance-Specification

Other
21 stars 7 forks source link

[Improvement] Include "remediation" and "mitigation" in Section 3.1.5 - Standard Practice Implementation #25

Closed shanecoughlan closed 1 year ago

shanecoughlan commented 1 year ago

Action

Remediation and mitigation were added to Section 3.1.5 - Standard Practice Implementation.

Old Language

3.1.5 - Standard Practice Implementation

The Program demonstrates a sound and robust handling procedures of Known Vulnerabilities and Secure Software Development by defining and implementing following procedures:

A process shall exist for the Security Assurance methods listed above.

New Language

3.1.5 - Standard Practice Implementation

The Program demonstrates a sound and robust handling procedures of Known Vulnerabilities and Secure Software Development by defining and implementing following procedures:

A process shall exist for the Security Assurance methods listed above.

Rationale

We previously talked said "identified risks will have been addressed" but did not define how. Especially because of the citation of "remediation" in Section 3.3.2 - Security Assurance, it made sense to clarify more specifically what "been addressed" means.

shanecoughlan commented 1 year ago

This issue is being closed as complete (for now). You can reopen it at any time to add new comments, ideas or concerns.