ossf / SIRT

The OSS-SIRT SIG (Open Source Software Security Incident Response Team Special Interest Group) is a group working within the OSSF's Vulnerability Disclosure Working Group that is focused on creating secure vulnerability management capabilities within the open source ecosystem to ensure effective coordinated vulnerability disclosure practices (CVD)
Apache License 2.0
9 stars 9 forks source link

Tooling Requirements #30

Open ran-dall opened 1 year ago

ran-dall commented 1 year ago

At today's Section 3 meeting, the possibility of using VINCE (or possibly developing our vendor-agnostic tooling similar to VINCE) was discussed; however, the issue came up as to what we wanted to determine the requirements of said tooling solution.

I've opened this issue so the group may propose and document some of these requirements.

TheFoxAtWork commented 1 year ago

@SecurityCRob had some awesome suggestions on the call and he said he would capture many of them here.

TheFoxAtWork commented 1 year ago

Also recommend structuring/capturing this such that it could be a timeless blog post. Cover our use cases, threat concerns, collaboration and partnership needs.

SecurityCRob commented 1 year ago

My first round of SIRT IR tool requirements: