ossf / wg-vulnerability-disclosures

The OpenSSF Vulnerability Disclosures Working Group seeks to help improve the overall security of the open source software ecosystem by helping mature and advocate well-managed vulnerability reporting and communication.
https://openssf.org
Apache License 2.0
175 stars 40 forks source link

Security Emergency/Crisis Response resources (team, guide, etc) #100

Open jenniferfernick opened 2 years ago

jenniferfernick commented 2 years ago

In our October 18 2021 WG meeting, I raised the question of "where do open-source projects turn in the event of a security crisis or emergency?" Here, security emergency could include, for example:

This is especially important when the affected project/individual does not know where to turn or who to trust for initial advice. Often, peoples' network strongly determines the support they are able to access in the event of a security crisis, which is inequitable; much of the basic information about how to deal with these scenarios is not (to our knowledge) documented

Discussion resulted in us determining that:

Prior to starting a repo for documenting such a guide, we decided to discuss via GitHub issue the scope of the problem and what an effective guide etc could look like.

NicoleSchwartz commented 7 months ago

A similar issue came up in today's meeting about guidance on data reporting (data loss, data breach)