Re: [PATCH] source/faq/index: Update FAQ.
"Frank Ch. Eigler" <[email protected]> Wed, 5 Jun 2024 14:33:06 -0400
| Newsgroups | org.linuxfoundation.lists.cti-tac |
|---|---|
| Message-ID | <[email protected]> |
Hi, Carlos - > [...] > > +In order to continue to support these communities we must start to adhere to > > +the modern cybersecurity principles including moving towards zero-trust > > +architectures with strong application sandboxing for all provided services > > +e.g. NIST SP.800-207, separate and protect each environment involved > > +in software development e.g. NIST SP.800-218A PO.5.1, and use multi-factor, > > +risk-based authentication and conditional access for each environment. > [...] Thank you for offering those extra book references. It would help even more if there were an itemized list of those particular suggestions or mandates from those books are of your interest, and how each is absent on sourceware vs. to be satisfied at lf. In other words, offer a way for someone to verify problem, incompliance and compliance. - FChE