cncf / tag-security

🔐CNCF Security Technical Advisory Group -- secure access, policy control, privacy, auditing, explainability and more!
https://tag-security.cncf.io
Other
2.09k stars 521 forks source link

[Sec Assess WG] Time and Effort of Security Assessments #446

Closed lumjjb closed 1 year ago

lumjjb commented 4 years ago

This issue was created from results of the Security Assessment Improvement Working Group (https://github.com/cncf/sig-security/issues/167#issuecomment-714514142).

Time and Effort of Security Assessments

Premise

Ideas

Additional Context:

Logistics

magnologan commented 4 years ago

I'm interested!

JustinCappos commented 4 years ago

This is hard because it isn't clear when a security assessment is really "done". It's not like being asked to write a 3 page essay, it's like a mathematical proof where a bug or problem may end up going down a long rabbit hole of explanations / fixes. Possibly a more rigorous threat modeling step up front would help, but this would be unevenly applied (unless done by a central group) and difficult to do well.

stale[bot] commented 3 years ago

This issue has been automatically marked as inactive because it has not had recent activity.

anvega commented 1 year ago

Closing this out based on Justin's comment above. While aspirational, it is practically unfeasible.