Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Proposal] White Paper Compliance Use Cases #1436

Open
18 tasks
hubbertsmith opened this issue Dec 23, 2024 · 1 comment
Open
18 tasks

[Proposal] White Paper Compliance Use Cases #1436

hubbertsmith opened this issue Dec 23, 2024 · 1 comment
Labels
proposal common precursor to project, for discussion & scoping triage-required Requires triage

Comments

@hubbertsmith
Copy link

Description: Compliance Use Cases Whitepaper

Impact: This helps developers of compliance-related software understand how the code they develop will be used, by various personas.
This helps adopters of compliance-related software understand the roles and responsibilities of the various personas.

Scope:
https://docs.google.com/document/d/e/2PACX-1vRAYxHDwowAAT_Td55yEfA4NUN19KnkaTPGjlGYt0Ed3UD1Gd7nEvCNM0fbrfaI2Q/pub
to do --
[] add more authors
[] conduct reviews and edits required by Security TAG

Intent to lead:

  • Hubbert Smith, volunteers to be a project lead on this proposal.
    The Compliance GRC group has expressed interested in pursing this work.

Proposal to Project:

TO DO

  • Security TAG Leadership Representative:
  • Project leader(s):
  • Issue is assigned to project leaders and Security TAG Leadership
    Representative
  • Project Members:
  • Fill in addition TODO items here so the project team and community can
    see progress!
  • Scope
  • Deliverable(s)
  • Project Schedule
  • Slack Channel (as needed)
  • Meeting Time & Day:
  • Meeting Notes (link)
  • Meeting Details (zoom or hangouts link)
  • Retrospective
@hubbertsmith hubbertsmith added proposal common precursor to project, for discussion & scoping triage-required Requires triage labels Dec 23, 2024
@sunstonesecure-robert
Copy link
Contributor

sunstonesecure-robert commented Jan 15, 2025

I have reviewed and think it has important points. Since it notes that the top breach vectors are Credential related, I would suggest reviewing with relevant CNCF projects contribute examples of how these are mitigated would underline the CNCF contributions to solving these challenges. For example KeyCloak, OPA, Cloud custodian, certmanager, many others...and given that it has a lot of content on data breaches in particular, maybe some of the more data lifecycle projects are relevant and could chime in with examples/best practices, eg. etcd, tikv, rook, Kubeflow, many others...

The Compliance GRC group has expressed interested in pursing this work.

I believe several participants have reviewed the paper. I would definitely like to see some of the above examples presented at the GRC WG calls and can help coordinate!

overall huge +1 to moving foward!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
proposal common precursor to project, for discussion & scoping triage-required Requires triage
Projects
None yet
Development

No branches or pull requests

2 participants