glibc status update - Week ending Feb 21st

Carlos O'Donell <[email protected]> Wed, 26 Feb 2025 08:17:04 -0500
Newsgroups org.linuxfoundation.lists.cti-tac
Organization Red Hat
Message-ID <[email protected]>
Current status looks like this:

https://sourceware.org/glibc/wiki/CTI
https://sourceware.org/glibc/wiki/CTI/Policy/glibc

- Reviewed OWASP's SAMM
  - It is freely available and useful open standard.
  - The process pieces of this standard are too much for the GNU Toolchain.
  - The framework is really for a much larger organization starting a program.

- Reviewed Black Duck's BSIMM
  - Could not review data since BSIMM is a live standard.
  - You need an assesor to compare you to the industry baseline.
  - We naturally compare solutions across FOSS so this standard
    doesn't really apply to provide a checkbox certification.

- Updated main page justification for why we're using NIST SP 800-218.
  - Noted references for all the other standards.
  - Noted that we follow NISTS framework because it is a useful framework.

Next week
- Start writing glibc position.

-- 
Cheers,
Carlos.