department-of-veterans-affairs / va.gov-team

Public resources for building on and in support of VA.gov. Visit complete Knowledge Hub:
https://depo-platform-documentation.scrollhelp.site/index.html
283 stars 205 forks source link

Sync with Platform Security team on final Platform website PSIRR changes #58505

Open briandeconinck opened 1 year ago

briandeconinck commented 1 year ago

User Story

As a VFS team member, I want to know the current details of the Privacy, Security, Infrastructure Readiness Review so that I can be sure my team is prepared for it.

Assignee: Peer Reviewer:

Description

This issue consists of the remaining items from #56317 that required input from Platform Security --- specific guidance on requirements and procedures for changes to the Privacy, Security, and Infrastructure Readiness Review touchpoint.

Impacted Artifacts

Tasks

Peer Review

To be completed by peer reviewer

Acceptance Criteria

How to prepare this issue

Refinement

shiragoodman commented 1 year ago

@jhouse-solvd @little-oddball FYSA

jhouse-solvd commented 1 year ago

@shiragoodman and I had a sync on what's next. The Platform Security team will review and respond to feedback from @briandeconinck on this page and aim to help action this ticket in one or two upcoming sprints.

shiragoodman commented 1 year ago

Platform Security is tracking this work through this ticket: https://github.com/department-of-veterans-affairs/platform-security/issues/294

humancompanion-usds commented 1 year ago

Discussed with @raywangoctova - This work is deprioritized until we get to 90% ATO compliance. Target is ~4 weeks. Thus this will go on the backlog until then. We can revisit then.

shiragoodman commented 1 year ago

@jhouse-solvd @raywangoctova checking in on this as it's been 1 month. Please let me know where we stand.

cc @humancompanion-usds

kell-y commented 6 months ago

Draft page here: https://vfs.atlassian.net/wiki/spaces/PSEC/pages/3101949968/Privacy+security+infrastructure+readiness+review+-+For+Review

Proposed solution for PSIRRs:

shiragoodman commented 6 months ago

sounds good @kell-y - thank you for sharing! cc @humancompanion-usds

The only clarification I'd like to make (which I believe we agreed to when we met via Zoom last week) is that by "1st touchpoint" and "2nd touchpoint", you really only mean 1 touchpoint with 2 check-ins or sections. We would update the flow on this page to indicate 1 Privacy Security Infrastructure Readiness Review under the Define column, below Design Intent. The instance under Build would be removed. The reason for this is because we're cautious/concerned that adding an additional touchpoint to the Collaboration Cycle would be perceived as burdensome or overbearing, potentially causing VFS teams to lose trust and willingness to participate in the process.

In support of this effort, Governance team will make modifications to the Staging Review process to not only advocate and direct VFS teams to the PSIRR, but also block teams from scheduling Staging Review if teams have failed to complete either PSIRR check-in. We still need to define the specifics, but I will begin discussions with my team and share our ideas with you.

If you'd like to discuss in more detail, please let me know! Otherwise, the plan sounds great and Governance team is on board.

kell-y commented 6 months ago

Yes, I agree with the language about 1 touchpoint with 2 check-ins! Thanks for clarifying.