cncf / tag-security

🔐CNCF Security Technical Advisory Group -- secure access, policy control, privacy, auditing, explainability and more!
https://cncf.io/projects
Other
1.99k stars 496 forks source link

[Proposal] Implementation Initiatives WG #1226

Closed eddie-knight closed 2 months ago

eddie-knight commented 5 months ago

Description

Problem

Currently there is little in the way of cross-initiative coordination & visibility for efforts such as Security Pals and Security Slam. This results in a loss of potential for several reasons. There is an inability to fully utilize interested parties and influencers from across the CNCF community, a low level of sharing lessons learned, and a lack of integration with other parts of CNCF.

Proposed Solution

Create the Implementation Initiatives Working Group, designed to support and coordinate any tangible efforts that interface directly with CNCF projects.

Impact

Potential positive impacts:

Potential negative impacts:

Scope

In Scope:

Out of Scope:

Proposal Progress

Intent to lead:

Proposal to Project:

TO DO

eddie-knight commented 5 months ago

Presented this on today's call, and heard concerns from @JustinCappos related to bureaucracy. Proposal support was expressed by @ragashreeshekar and @mlieberman85 for different reasons.

After chatting offline with @PushkarJ, I threw together this list of different initiatives that could benefit from increased visibility, coordination, and maintenance of best practices documentation:

ArangoGutierrez commented 5 months ago

/cc

ragashreeshekar commented 5 months ago

Thanks for bringing this up @eddie-knight. This is a good idea, and I think it can help in following ways:

If the STAG community has enough interest and we choose to proceed with this working group, I'm happy to help/be the STAG rep.

eddie-knight commented 4 months ago

Interest has been communicated by @k8tgreenley from an events collaboration perspective, and @mlieberman85 regarding ad hoc project engagement for the implementation of security recommendations.

mnm678 commented 2 months ago

Thanks for this proposal, and for bringing up these issues. I think we can address this with a combination of improving existing process, and short-term WGs.

Some ideas for process improvements:

We could then have a light-weight, short-term WG for each initiative, which can check in at the general meeting for increased visibility.