cncf / tag-security

🔐CNCF Security Technical Advisory Group -- secure access, policy control, privacy, auditing, explainability and more!
https://tag-security.cncf.io
Other
2.08k stars 518 forks source link

[Sec Assess WG] Getting more reviewers for Security Assessments #447

Closed lumjjb closed 1 year ago

lumjjb commented 4 years ago

This issue was created from results of the Security Assessment Improvement Working Group (https://github.com/cncf/sig-security/issues/167#issuecomment-714514142).

Getting more reviewers for Security Assessments

Premise

Ideas

Logistics

magnologan commented 4 years ago

I'm interested!

stale[bot] commented 3 years ago

This issue has been automatically marked as inactive because it has not had recent activity.

magnologan commented 3 years ago

Working on it! =)

magnologan commented 3 years ago

what are the reasons that people want to participate?

can we incentivize more?

Provide swag/recognition

For issues found they would get discount for courses and conference

Example:

Actively reach out to past reviewers (This is currently done by co-chairs and TLs informally)

Create a more concrete list of the expectations/requirements of a reviewer Find new ways to engage new reviewers including inexperienced ones

Reach out to researchers to review the projects

Recommend the CNCF provide training/skills to community members to be able to perform assessments and audits

aspanner commented 3 years ago

plus add a guide on how to sign up as a security auditor/participant and how to claim a work item as part of the short training video.

stale[bot] commented 3 years ago

This issue has been automatically marked as inactive because it has not had recent activity.

MVrachev commented 3 years ago

what are the reasons that people want to participate?

Plus learn new stuff during the assessment.

I think one question we want to answer do we consider the assessments as a learning opportunity too?

There is an old issue I created before https://github.com/cncf/sig-security/issues/256 about the need for a lower entry-level position in the assessments which will allow an inexperienced developer to learn during security assessments and eventually volunteer for security reviewers.

I added a new comment about why I think this would be useful here: https://github.com/cncf/sig-security/issues/256#issue-484537322

stale[bot] commented 3 years ago

This issue has been automatically marked as inactive because it has not had recent activity.

magnologan commented 3 years ago

I've talked to @lumjjb before, and I'll submit a PR this week with the suggestions I've mentioned previously on this issue. Then, once they are accepted, we can close this one. Thanks!

lumjjb commented 3 years ago

Hey @magnologan ! How is this going? Any way that we can help out with this?

magnologan commented 3 years ago

Hi @lumjjb sorry, I missed this, since the isn't assigned to me I forgot to follow up here. I'll submit a PR this week with the suggestions above. Do you mind assigning this to me just to make sure I don't forget? Thank you!

lumjjb commented 3 years ago

Ok - assigned now :). Looking forward to the PR!

lumjjb commented 3 years ago

Checking back on this @magnologan

apmarshall commented 3 years ago

Adding myself to the project of turning Magno’s contributions here into a PR for the repo

hyakuhei commented 3 years ago

This is definitely something I can help with, I've also been working on a few (scrappy) tools that make threat modelling and security reviews code driven, git friendly and a bit more accessible. Will share more if there's interest.

lumjjb commented 3 years ago

Hi @hyakuhei , @apmarshall !

Just checking back on this!

hyakuhei commented 3 years ago

Still happy to help but a bit unclear on what the engagement model is; how do we arrange and conduct a review?

stale[bot] commented 3 years ago

This issue has been automatically marked as inactive because it has not had recent activity.

ashutosh-narkar commented 3 years ago

The security facilitator role helps with the tasks outlined in this issue.

stale[bot] commented 2 years ago

This issue has been automatically marked as inactive because it has not had recent activity.

anvega commented 1 year ago

Closing this out -- the onus of convocating reviewers lies on the tag leadership and the assessments facilitator.