-
Notifications
You must be signed in to change notification settings - Fork 11
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update baseline.yaml - NEW - OSPS-DO-16 #119
base: main
Are you sure you want to change the base?
Conversation
added suggestion for criteria OSPS-DO-16 which covers project roles & responsibilities Signed-off-by: CRob <69357996+SecurityCRob@users.noreply.github.com>
Not 100% convinced this is a "docs", but open to alternate landing suggestions |
baseline.yaml
Outdated
Projects need to document the Roles and | ||
Responsibilities of the project to provide for | ||
Seperation of Duties, Dual Control, and other | ||
requirements. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
How does this differ from OSPS-DO-11
?
The project documentation MUST have a policy that code contributors are reviewed prior to granting escalated permissions to sensitive resources.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
do-11 is about access review of those that get the commit-bit, this is broader, "document whom can do what" within the project
It feels like there is probably a "governance" section waiting to happen. I'd nominate OSPS-DO-01, OSPS-DO-02, OSPS-DO-06, OSPS-DO-11 for inclusion, or it could be combined with the LE- line if desired. |
Co-authored-by: Evan Anderson <evan.k.anderson@gmail.com> Signed-off-by: CRob <69357996+SecurityCRob@users.noreply.github.com>
...yeah, I was thinking that today too. What does the rest of the group think? |
I'm in favor of creating a Governance category, as proposed. |
A general comment on this PR: there are a lot of capital letters in places I don't expect. Maybe that's something for Eddie to include in the style guide (#112) |
Signed-off-by: CRob <69357996+SecurityCRob@users.noreply.github.com>
added suggestion for criteria OSPS-DO-16 which covers project roles & responsibilities