Re: [PATCH] source/faq/index: Update FAQ.

Carlos O'Donell <[email protected]> Tue, 11 Jun 2024 08:18:46 -0400
Newsgroups org.linuxfoundation.lists.cti-tac
Organization Red Hat
Message-ID <[email protected]>
On 6/5/24 2:33 PM, Frank Ch. Eigler wrote:
> Hi, Carlos -
> 
>> [...]
>>> +In order to continue to support these communities we must start to adhere to
>>> +the modern cybersecurity principles including moving towards zero-trust
>>> +architectures with strong application sandboxing for all provided services
>>> +e.g. NIST SP.800-207, separate and protect each environment involved
>>> +in software development e.g. NIST SP.800-218A PO.5.1, and use multi-factor,
>>> +risk-based authentication and conditional access for each environment.
>> [...]
> 
> Thank you for offering those extra book references.  It would help
> even more if there were an itemized list of those particular
> suggestions or mandates from those books are of your interest, and how
> each is absent on sourceware vs. to be satisfied at lf.  In other
> words, offer a way for someone to verify problem, incompliance and
> compliance.

Such an answer goes beyond what I would normally put into an FAQ. The 
intent of the FAQ is to be smaller quick to read answers to specific
questions.

Such an answer could also be viewed as antagonistic towards Sourceware and
I don't want it to be seen that way. I would like to continue collaborating
now and into the future with you and the other overseers.

-- 
Cheers,
Carlos.