glibc policy update - Week ending Feb 14th

Carlos O'Donell <[email protected]> Wed, 26 Feb 2025 08:16:58 -0500
Newsgroups org.linuxfoundation.lists.cti-tac
Organization Red Hat
Message-ID <[email protected]>
Current status looks like this:

https://sourceware.org/glibc/wiki/CTI
https://sourceware.org/glibc/wiki/CTI/Policy/glibc

- In a discussion with David Edehlson I mused that we were using NIST's
  SP 800-218 because it was what I *thought* was the best, but this got
  me considering a review of the existing documents and what we would use
  for comparative reference.

- Reviewed Common Criteria again for the second time.
  - Some of the items in CC are applicable but because the
    standard itself is high level and Government controlled it doesn't
    apply to us.
  - Lots of documents to review here, skipped a number that don't matter,
    and while some do like the OSPP pieces, they are more for deployment
    and not infra like CTI.

- Reviewed ISO 27001:2022 which is often quoted for infosec and cyber
  security.
  - This document is very much like NIST SP800-218, but less well
    organized IMO and as a closed paid standard it makes it difficult
    to hand out copies for review.
  - As an ISO member I had access and went through the 26 pages.

- Reviewed TOGAF from the OpenGroup
  - Closed standard.
  - The standard itself is massive and very proscriptive as
    to how enterprise software shoudl be developed.
  - Not going to use this standard.

- Reviewed PCI DSS standard, 35 pages.
  - No easily applicable to glibc or software standards.
  - Skipping this. Took notes and decided we won't use this for
    our own review process.

Next week
- Review OWASP SAMM, BSIMM, and update justifications.

-- 
Cheers,
Carlos.