glibc policy update - Week ending Feb 14th
Carlos O'Donell <[email protected]> Wed, 26 Feb 2025 08:16:58 -0500
| Newsgroups | org.linuxfoundation.lists.cti-tac |
|---|---|
| Organization | Red Hat |
| Message-ID | <[email protected]> |
Current status looks like this:
https://sourceware.org/glibc/wiki/CTI
https://sourceware.org/glibc/wiki/CTI/Policy/glibc
- In a discussion with David Edehlson I mused that we were using NIST's
SP 800-218 because it was what I *thought* was the best, but this got
me considering a review of the existing documents and what we would use
for comparative reference.
- Reviewed Common Criteria again for the second time.
- Some of the items in CC are applicable but because the
standard itself is high level and Government controlled it doesn't
apply to us.
- Lots of documents to review here, skipped a number that don't matter,
and while some do like the OSPP pieces, they are more for deployment
and not infra like CTI.
- Reviewed ISO 27001:2022 which is often quoted for infosec and cyber
security.
- This document is very much like NIST SP800-218, but less well
organized IMO and as a closed paid standard it makes it difficult
to hand out copies for review.
- As an ISO member I had access and went through the 26 pages.
- Reviewed TOGAF from the OpenGroup
- Closed standard.
- The standard itself is massive and very proscriptive as
to how enterprise software shoudl be developed.
- Not going to use this standard.
- Reviewed PCI DSS standard, 35 pages.
- No easily applicable to glibc or software standards.
- Skipping this. Took notes and decided we won't use this for
our own review process.
Next week
- Review OWASP SAMM, BSIMM, and update justifications.
--
Cheers,
Carlos.