openedx / wg-security

A repo to keep public issues related to Security Working Group Work
1 stars 0 forks source link

Create on-call runbook/playbook #23

Closed pshiu closed 6 months ago

pshiu commented 1 year ago

We need a runbook so it's clear to working group members how to respond to security disclosures.

Some open questions from: https://openedx.atlassian.net/wiki/spaces/COMM/pages/3624140816/Security+Working+Group+Private:

pshiu commented 1 year ago

Started to address "What are the expectations for on-call?" in new section On-Call Duties section on our "For working group members" Confluence page.

pshiu commented 1 year ago

Added runbook on finding a maintainer in our Security Playbooks.

pshiu commented 1 year ago

Started draft sections:

Added to Triage security@openedx.org emails.

pshiu commented 1 year ago

Added section Forward a report to an operator or Axim.

pshiu commented 10 months ago

Next steps:

pshiu commented 9 months ago

@alangsto & I met and compiled the current 2U practices. We now need to compare them.

pshiu commented 9 months ago

@alangsto & I met and added details to Security Playbooks – for Security WG members.

pshiu commented 8 months ago

@feanil & I met and we worked on Common Issues.