ai-cfia / howard

The Howard project, named after "The Godfather of Clouds" Luke Howard, orchestrates the Kubernetes-based cloud infrastructure for the Canadian Food Inspection Agency's AI lab, managing applications like Nachet, Finesse, and Louis. It prioritizes robustness, security and efficiency
https://ai-cfia.github.io/howard/
MIT License
3 stars 0 forks source link

As a DevOps, I want to enhance security practices with systematic audits and proactive alerting #197

Open SonOfLope opened 7 months ago

SonOfLope commented 7 months ago

As a DevOps team, we aim to enhance our security posture through systematic audits and swift response mechanisms to maintain secure software repositories. Our goal is to establish robust processes not only for monitoring and assessing security vulnerabilities but also for effective incident management using modern alerting systems. This comprehensive approach will ensure Authorization to Operate (ATO) and Security Assessment & Authorization (SA&A) readiness for our software products.

Goals

Desired Outcomes

By achieving these goals, we strengthen our software's defense against security threats and ensure a proactive stance in incident management and security assessments.

rngadam commented 7 months ago

this is already covered by Github Security applied to our sources:

image

I'd be more interested in seeing how we monitor these are turned on for all our repos and how we ensure that security alerts are followed up on systematically by developers.

SonOfLope commented 7 months ago

this is already covered by Github Security applied to our sources:

image

I'd be more interested in seeing how we monitor these are turned on for all our repos and how we ensure that security alerts are followed up on systematically by developers.

Updated the issue to address this. Converted to an 'Epic' issue