ossf / wg-endusers

OpenSSF Endusers Working Group
https://openssf.org/
Apache License 2.0
28 stars 15 forks source link

Review OpenSSF Threat models #19

Open APM05 opened 1 year ago

APM05 commented 1 year ago

https://docs.google.com/document/d/1lLCsT0a5vp6FcvquWPzx8AzhFMORyw-4rd9WSyUO9zI/edit?usp=sharing

henrikplate commented 1 year ago

I made several changes and additions to the threat modelling document. It is still a draft, incomplete, etc. but better than the previous version (which, frankly, did not receive a lot of love beyond the changes made during the actual workshop sessions).

Maybe you have some time to review/comment/approve those changes, esp. concerning

It would be great to discuss any questions during tomorrow's WG meeting or next week Monday during the TM workshop.

APM05 commented 11 months ago

A suggestion is to have content separated for volunteers to take up and review instead of the whole doc. Can we have a few volunteers to help do the review, so we can get this moving with it?

APM05 commented 11 months ago

Suggestion -We should think in terms of generating the OSCAL as output to the threat modelling.