finos / compliant-financial-infrastructure

Compliant Financial Infrastructure accelerates the development, deployment and adoption of services provided for AWS, Azure and Google in a way that meets existing regulatory and internal security controls.
Apache License 2.0
127 stars 61 forks source link

Determine process for soliciting policy input #328

Closed eddie-knight closed 1 year ago

eddie-knight commented 1 year ago

Recent discussions have repeatedly highlighted the need for a strategic approach to soliciting input from end users.

As discussed on today's community call, we need to determine our goals before we can drill into the tactical approach.

Once we determine the information we're hoping to get at this time, @niamhoparker has offered to support the Policy WG in tactfully engaging the right people.

abdullahgarcia commented 1 year ago

Thanks for formalising the issue @eddie-knight.

@niamhoparker - when can we get together to address this? Also, looking forward to seeing you in the upcoming session this Wednesday!

jstclair2019 commented 1 year ago

Sorry if totally dumb question, but have we determined what policy areas we seek to collect? I know I've personally harped on ICT risks, but didn't think that's all. Maybe policies on loss reserve ratios? :) Too soon?

AdrianHammond commented 1 year ago

Hi @jstclair2019 We are looking to get an understanding from the FSI members of FINOS so that we can determine the common security / compliance requirements that we can address via CFI. In the session last Wednesday we discussed some of the tactics to get this information (interviews and surveys) but what we did not finalise, which we should do on Wednesday, what the ask is.

abdullahgarcia commented 1 year ago

Brief statement to address the FINOS members in order to gain the required information.

niamhoparker commented 1 year ago

Brief statement to address the FINOS members in order to gain the required information.

hi @abdullahgarcia @eddie-knight - hope you're well. following up on this. let me know timeline so i can dedicate time to this when ready. happy to join any meeting. just ping me on slack if easier too.

eddie-knight commented 1 year ago

Starting a slack thread to hammer out the process for this.